Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with TTSS Rootkit


  • This topic is locked This topic is locked
13 replies to this topic

#1 Sam Bamford

Sam Bamford

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 30 March 2010 - 03:52 PM

Hi all at Bleep

A few weeks ago I downloaded a piece of free PLR software and from that time have noticed strange things happening whilst browsing google or yahoo. Also my Zone labs firewall was throwing up a whole host of unknown programs looking to act as a server. When trying to update Zonelabs and Spybot S&D I was getting error messages and could not connect to these site through either IE or firefox. I tried the HJT software and it was through their site that led me to Bleeping Computer. Having read through the forum on this site for anything similar to my experiences I found information on the TDSS Rootkit and a download link for rootkit removal software which found the infection last week. On removing the infection and almost at the same time emails where sent (judging by the times on an undeliverable notification from mailer demon) from an old backup file saved in My Documents. Later that day I received approx 30 emails to my default email address with the subject line Rootkit Rootkit Rootkit etc. Since that time I have switched off my wireless connection as I'm not 100% certain that my laptop is secure. Luckily I have access to another computer but the situation is not ideal. Hope someone here can advise. I have followed the steps in forum/topic 34773.

My computer is a Dell Inspiron 6400 running on XP, please find the DDS report below and GMER file attached.


DDS (Ver_10-03-17.01) - NTFSx86
Run by MSB at 23:31:58.21 on 26/03/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.515 [GMT 0:00]

AV: ZoneAlarm Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\AOL\1166157621\ee\AOLSoftware.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Spamihilator\spamihilator.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AOL 9.0a\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\MSB\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = hxxp://www.google.ie/hws/sb/dell-row/en/side.html?channel=ie
uSearch Bar = hxxp://www.google.ie/hws/sb/dell-row/en/side.html?channel=ie
uDefault_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=3061113
mSearchAssistant = hxxp://www.google.ie/hws/sb/dell-row/en/side.html?channel=ie
uURLSearchHooks: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: WebCGMHlprObj Class: {56b38f40-4e70-11d4-a076-0080ad86ba2f} - c:\windows\cgmopenbho.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus CX6400] c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX6400" /M "Stylus CX6400" /EF "HKCU"
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe -NoStart
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HostManager] c:\program files\common files\aol\1166157621\ee\AOLSoftware.exe
mRun: [EPSON Stylus CX6400] c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [Spamihilator] "c:\program files\spamihilator\spamihilator.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"
StartupFolder: c:\docume~1\msb\startm~1\programs\startup\deskto~1.lnk - c:\documents and settings\msb\start menu\programs\startup\desktop.ini
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\aol90t~1.lnk - c:\program files\aol 9.0a\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} - hxxp://support.microsoft.com/mats/DiagWebControl.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://ebanking.northernbank.co.uk/html/activex/e-Safekey/NB/e-Safekey.cab
Handler: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - c:\program files\common files\intuit\intu-res.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - No File

============= SERVICES / DRIVERS ===============

R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2010-3-21 128016]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-21 64288]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-3-21 317072]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-3-21 486280]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2009-10-14 25208]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2009-10-14 476528]
R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifay.sys [2007-12-7 12160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 Gonzales;Gonzales;c:\windows\system32\drivers\Gonzales.sys [2007-12-7 7040]

=============== Created Last 30 ================

2010-03-26 23:20:45 0 ----a-w- c:\documents and settings\msb\defogger_reenable
2010-03-25 13:24:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-22 01:12:49 0 d-sh--w- c:\documents and settings\msb\IECompatCache
2010-03-22 01:07:56 0 d-sh--w- c:\documents and settings\msb\PrivacIE
2010-03-22 00:15:33 0 d-sh--w- c:\documents and settings\msb\IETldCache
2010-03-22 00:09:46 0 d-----w- c:\windows\ie8updates
2010-03-22 00:03:55 0 dc-h--w- c:\windows\ie8
2010-03-21 23:59:20 69120 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-03-21 23:59:12 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-21 23:59:12 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-03-21 17:04:33 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-03-21 17:04:24 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-21 14:34:22 0 d-----w- c:\program files\CheckPoint
2010-03-21 14:34:19 72584 ----a-w- c:\windows\zllsputility.exe
2010-03-21 14:34:17 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2010-03-21 14:33:42 1238408 ----a-w- c:\windows\system32\zpeng25.dll
2010-03-21 14:33:39 422256 ----a-w- c:\windows\system32\vsconfig.xml
2010-03-21 12:36:09 0 d-----w- c:\windows\system32\wbem\Repository
2010-03-20 16:47:22 55436 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-03-20 16:47:22 4058912 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-03-20 16:47:22 2444 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-03-20 16:47:22 14624 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-03-20 16:42:03 0 d-----w- c:\windows\system32\ZoneLabs
2010-03-20 16:42:03 0 d-----w- c:\program files\Zone Labs
2010-03-20 16:40:54 0 d-----w- c:\windows\Internet Logs
2010-03-20 16:38:10 4043 ----a-w- C:\WirelessDiagLog.csv
2010-03-20 08:32:41 1312 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-03-20 01:08:57 0 d-----w- c:\docume~1\alluse~1\applic~1\SITEguard
2010-03-20 01:07:47 0 d-----w- c:\program files\common files\iS3
2010-03-20 00:26:32 0 d-----w- c:\program files\Trend Micro
2010-03-10 15:53:22 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-06 16:24:01 0 d-----w- c:\program files\Poll Creator Pro
2010-02-26 18:11:50 293376 ------w- c:\windows\system32\browserchoice.exe

==================== Find3M ====================

2010-03-25 23:22:23 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-25 00:53:35 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-03-22 23:46:52 7680 ----a-w- c:\windows\system32\dllcache\rasadhlp.dll
2010-03-21 13:31:34 512 ----a-w- C:\ScanSectorLog.dat
2010-02-17 11:00:28 203781 ----a-w- c:\windows\XHeader Uninstaller.exe
2010-02-17 02:18:36 1537626 ----a-w- c:\windows\XCommentPro Uninstaller.exe
2010-02-15 02:35:48 134118 ----a-w- c:\windows\ColorPic Uninstaller.exe
2010-01-05 10:00:21 133120 ----a-w- c:\windows\system32\dllcache\extmgr.dll
2009-12-31 16:50:03 353792 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2006-12-15 16:36:27 8192 --sha-w- c:\windows\o2cLicStore.bin
2008-07-22 07:13:09 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008072220080723\index.dat

============= FINISH: 23:33:02.25 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 02 April 2010 - 01:34 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

Could you please post/Attach the GMER log as well. I think you forgot to attach it.

Thanks.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 02 April 2010 - 04:22 PM

Hi Extremeboy

Many thanks in advance for your help and assistance. Please find the GMER file attached.

Regards

Sam

PS Tried to add this post a few moments ago but seems to have disappeared into cyberspace.

#4 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 02 April 2010 - 04:24 PM

Sorry

Forgot to hit the upload button

Attached Files

  • Attached File  ark.txt   11.63KB   2 downloads


#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 03 April 2010 - 10:40 AM

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 03 April 2010 - 04:21 PM

Hello again Extremeboy

Here are the results from combofix.

ComboFix 10-03-28.03 - MSB 03/04/2010 21:34:25.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.547 [GMT 1:00]
Running from: c:\documents and settings\MSB\Desktop\ComboFix.exe
AV: ZoneAlarm Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\winhelp.ini

.
((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.

2010-03-25 13:24 . 2010-03-25 23:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-22 01:12 . 2010-03-22 01:12 -------- d-sh--w- c:\documents and settings\MSB\IECompatCache
2010-03-22 01:07 . 2010-03-22 01:07 -------- d-sh--w- c:\documents and settings\MSB\PrivacIE
2010-03-22 00:18 . 2010-03-22 00:18 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-03-22 00:15 . 2010-03-22 00:15 -------- d-sh--w- c:\documents and settings\MSB\IETldCache
2010-03-22 00:09 . 2010-03-22 17:23 -------- d-----w- c:\windows\ie8updates
2010-03-22 00:03 . 2010-03-22 00:07 -------- dc-h--w- c:\windows\ie8
2010-03-21 23:59 . 2009-12-11 08:38 69120 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-03-21 23:59 . 2009-12-21 19:14 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-03-21 23:59 . 2009-12-21 19:14 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-21 17:04 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-03-21 17:04 . 2010-03-21 17:04 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-21 14:34 . 2010-03-21 14:34 -------- d-----w- c:\program files\CheckPoint
2010-03-21 14:34 . 2009-10-17 01:39 72584 ----a-w- c:\windows\zllsputility.exe
2010-03-21 14:34 . 2009-10-12 18:15 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2010-03-21 14:33 . 2009-10-17 01:39 69000 ----a-w- c:\windows\system32\zlcomm.dll
2010-03-21 14:33 . 2009-10-17 01:39 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2010-03-21 14:33 . 2009-10-17 01:39 1238408 ----a-w- c:\windows\system32\zpeng25.dll
2010-03-21 12:36 . 2010-03-21 12:36 -------- d-----w- c:\windows\system32\wbem\Repository
2010-03-20 16:47 . 2010-03-21 14:27 4058912 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-03-20 16:47 . 2010-03-21 14:27 14624 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-03-20 16:42 . 2010-03-21 14:59 -------- d-----w- c:\windows\system32\ZoneLabs
2010-03-20 16:42 . 2010-03-20 16:42 -------- d-----w- c:\program files\Zone Labs
2010-03-20 16:40 . 2010-04-03 20:19 -------- d-----w- c:\windows\Internet Logs
2010-03-20 12:50 . 2009-12-17 00:09 49241 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\sb_BunkerHill.dll
2010-03-20 12:50 . 2009-12-16 07:07 136528 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\Vercopy.exe
2010-03-20 12:50 . 2009-12-15 06:33 120144 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\SBFix.exe
2010-03-20 12:50 . 2009-12-15 06:14 95568 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\RunOnce.exe
2010-03-20 12:50 . 2009-12-15 04:35 106496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\sb_Raga_Refresh.dll
2010-03-20 12:50 . 2009-12-14 16:00 106496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\sb_Almaak.dll
2010-03-20 12:50 . 2009-12-14 14:06 106496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\sb_Thailand.dll
2010-03-20 12:50 . 2009-12-14 14:03 106496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4482\sb_Strauss.dll
2010-03-20 01:08 . 2010-03-20 01:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2010-03-20 01:07 . 2010-03-20 01:07 -------- d-----w- c:\program files\Common Files\iS3
2010-03-20 00:26 . 2010-03-20 00:26 -------- d-----w- c:\program files\Trend Micro
2010-03-19 22:19 . 2010-03-21 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-03-10 15:53 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-06 16:24 . 2010-03-08 19:49 -------- d-----w- c:\program files\Poll Creator Pro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-03 19:45 . 2007-09-12 21:23 -------- d-----w- c:\documents and settings\MSB\Application Data\Spamihilator
2010-03-26 13:36 . 2010-03-26 13:36 159245 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_crt_term_2010_03_26_13_29_47_small.dmp.zip
2010-03-26 10:09 . 2010-03-26 13:29 2502656 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2010-03-25 23:22 . 2007-12-07 18:13 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-25 15:03 . 2008-02-29 23:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-25 00:53 . 2004-08-03 22:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-03-23 19:18 . 2010-03-23 20:51 208384 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2010-03-23 01:15 . 2010-03-23 11:27 98816 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2010-03-22 18:26 . 2010-03-22 18:27 102400 ----a-w- c:\windows\Internet Logs\xDB3.tmp
2010-03-22 17:59 . 2006-12-15 22:01 -------- d-----w- c:\program files\CCleaner
2010-03-22 02:10 . 2010-03-22 13:22 54272 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2010-03-22 00:13 . 2010-03-22 00:14 158720 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2010-03-21 14:27 . 2010-03-20 16:47 55436 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-03-21 14:27 . 2010-03-20 16:47 2444 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-03-21 13:31 . 2007-05-20 00:12 512 ----a-w- C:\ScanSectorLog.dat
2010-03-21 13:02 . 2006-12-15 16:55 147160 ----a-w- c:\documents and settings\MSB\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 15:43 . 2008-02-29 18:37 -------- d-----w- c:\program files\Real Link Finder
2010-03-20 12:50 . 2007-02-09 05:03 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-03-20 08:33 . 2010-03-20 08:32 1312 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-03-06 15:03 . 2006-12-15 18:51 -------- d-----w- c:\program files\XSite Pro
2010-03-02 21:14 . 2010-03-02 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-02 21:10 . 2010-03-02 21:10 -------- d-----w- c:\program files\NOS
2010-02-20 11:55 . 2010-02-20 11:55 -------- d-----w- c:\program files\Xara
2010-02-20 11:55 . 2006-11-13 14:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-19 19:31 . 2010-03-02 21:10 31936 ----a-w- c:\documents and settings\MSB\Application Data\Mozilla\Firefox\Profiles\9zltz2o1.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2010-02-19 19:31 . 2010-03-02 21:10 29344 ----a-w- c:\documents and settings\MSB\Application Data\Mozilla\Firefox\Profiles\9zltz2o1.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-02-17 13:55 . 2007-01-29 18:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 11:00 . 2009-05-24 22:09 203781 ----a-w- c:\windows\XHeader Uninstaller.exe
2010-02-17 11:00 . 2009-05-24 22:09 -------- d-----w- c:\program files\XHeader
2010-02-17 02:18 . 2010-02-17 02:18 1537626 ----a-w- c:\windows\XCommentPro Uninstaller.exe
2010-02-17 02:18 . 2010-02-17 02:18 -------- d-----w- c:\program files\XCommentPro
2010-02-15 02:35 . 2010-02-15 02:35 134118 ----a-w- c:\windows\ColorPic Uninstaller.exe
2010-02-15 02:35 . 2010-02-15 02:35 -------- d-----w- c:\program files\ColorPic 4.1
2010-02-12 10:03 . 2010-02-26 18:11 293376 ------w- c:\windows\system32\browserchoice.exe
2006-12-15 16:36 . 2006-12-15 16:36 8192 --sha-w- c:\windows\o2cLicStore.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX6400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"HostManager"="c:\program files\Common Files\AOL\1166157621\ee\AOLSoftware.exe" [2006-11-17 50736]
"EPSON Stylus CX6400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"Spamihilator"="c:\program files\Spamihilator\spamihilator.exe" [2008-12-23 1321984]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2009-02-27 1368064]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-02-27 1202448]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-09-21 127036]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-10-17 1037192]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2009-10-14 730480]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-10 113664]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0a\aoltray.exe [2007-5-20 156784]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-13 24576]
EPSON Status Monitor 3 Environment Check.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [1999-10-22 217600]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"AOLDialer"=c:\program files\Common Files\AOL\ACS\AOLDial.exe
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" -s
"Easy-PrintToolBox"=c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AOL 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1166157621\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Spamihilator\\cdcc.exe"=
"c:\\Program Files\\Spamihilator\\dccproc.exe"=
"c:\\Program Files\\Spamihilator\\spamihilator.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [21/03/2010 18:04 64288]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [14/10/2009 14:30 25208]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [14/10/2009 14:30 476528]
R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifay.sys [07/12/2007 21:41 12160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 Gonzales;Gonzales;c:\windows\system32\drivers\Gonzales.sys [07/12/2007 21:41 7040]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://ebanking.northernbank.co.uk/html/activex/e-Safekey/NB/e-Safekey.cab
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - (no file)
SafeBoot-klmdb.sys



**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus CX6400 = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX6400" /M "Stylus CX6400" /EF "HKCU"????????5???????3???S????????????IB~?????????????????????????????????????JB~????????????3???8?????????????C~??????????????C~???????????????|???????

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(680)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(736)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-04-03 21:45:05
ComboFix-quarantined-files.txt 2010-04-03 20:45

Pre-Run: 57,590,968,320 bytes free
Post-Run: 57,573,720,064 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 3632EA2FC6B38FE3ACF085AA3FB020FD


Seconds after combofix completed, spybot search & destroy popped up showing a series of registry changes to which I allowed. Hope this was the right decission?

many thanks

Sam

#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 04 April 2010 - 10:04 AM

Hello,

Let's get a new Malwarebytes scan.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 04 April 2010 - 01:43 PM

Hi Extremeboy

Have the MBAM report for you and the new DDS reports are attached.

Computer seems to be getting back to normal with no signs of browser redirects or hijacked email... can't thank you enough!


Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3953

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

04/04/2010 18:20:09
mbam-log-2010-04-04 (18-20-09).txt

Scan type: Quick scan
Objects scanned: 108200
Time elapsed: 10 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56b38f40-4e70-11d4-a076-0080ad86ba2f} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{56b38f40-4e70-11d4-a076-0080ad86ba2f} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\cgmopenbho.dll (Trojan.BHO) -> Quarantined and deleted successfully.

Attached Files


Edited by Sam Bamford, 04 April 2010 - 01:50 PM.


#9 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 04 April 2010 - 01:49 PM

Hello.

Sounds good.

Please update your java: http://www.java.com/en/

Then uninstall all older versions of java. You only need the latest version which you will install with that website (Java 6 update 19).

Next, let's get an online scan.
Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#10 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 04 April 2010 - 05:26 PM

Hello again Extremeboy

Have uninstalled old versions of Java and run the ESET online scan. The result was no infections found so did not give me a file to export.

Is that me in the clear or is there anything else that I need to do?

Many thanks


Sam

#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 04 April 2010 - 09:27 PM

Yup, sounds good. Let's cleanup then.

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#12 Sam Bamford

Sam Bamford
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 05 April 2010 - 05:26 AM

Hi Extremeboy

Have completed your last instructions and will continue to take preventative measures as suggested.

I'm so happy that my computer is up and running again without infection or fear of someone stealing my personal data - all thanks to you personally, and this wonderful forum. I will indeed be recommending friends etc. to pay a visit here, if only to get advice on keeping their PC clean and safe.

Once again, many many thanks for your help and assistance - much appreciated.

Kind regards

Sam Bamford

#13 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 05 April 2010 - 10:37 AM

No problem. You're welcome. smile.gif

A pleasure to help out. Stay clean.

----

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy

Edited by extremeboy, 05 April 2010 - 10:37 AM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:00 AM

Posted 09 April 2010 - 09:05 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users