![]() |
| |||||||
|
![]() |
| | Thread Tools |
|
#11
| |||
| |||
| You've got a lot going on here. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: KillAll:: File:: c:\windows\system32\15570szambot9d7.exe c:\windows\system32\23901zot-a-5irus731.dll c:\windows\system32\z45n9t-a-viru524.dll c:\windows\7e6evi5z292.bin c:\windows\system32\1093b9ckdo5rz51.bin c:\windows\system32\24473spa9bot5z5.exe c:\windows\system32\2f01viz9570.bin c:\windows\system32\5d6zhre9t24991.exe c:\windows\system32\3d29do9n5zader101.bin c:\windows\system32\3z71hac59ool14e.exe c:\windows\system32\23474v9r5s42z.dll c:\windows\system32\6ae5stzal18559.dll c:\windows\3f59addwaze593.bin c:\windows\system32\5edownz9ader102.dll c:\windows\system32\331fth59at1109z.exe c:\windows\z4546w9rm885.bin c:\windows\system32\18c2thz5at19699.bin c:\windows\5965t9oj2z15.exe c:\windows\system32\59edownloader95z.bin c:\windows\system32\9a5fthrzat205005.bin c:\windows\system32\6d96threat2457z.dll 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ![]() ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze |
|
#12
| |||
| |||
| OK, I've run ComboFix with your instructions again and here's the most recent log: ComboFix 09-10-15.02 - Thomas 16/10/2009 1:04.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.479.169 [GMT 1:00] Running from: c:\documents and settings\Thomas\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Thomas\Desktop\CFScript.txt AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FILE :: "c:\windows\3f59addwaze593.bin" "c:\windows\5965t9oj2z15.exe" "c:\windows\7e6evi5z292.bin" "c:\windows\system32\1093b9ckdo5rz51.bin" "c:\windows\system32\15570szambot9d7.exe" "c:\windows\system32\18c2thz5at19699.bin" "c:\windows\system32\23474v9r5s42z.dll" "c:\windows\system32\23901zot-a-5irus731.dll" "c:\windows\system32\24473spa9bot5z5.exe" "c:\windows\system32\2f01viz9570.bin" "c:\windows\system32\331fth59at1109z.exe" "c:\windows\system32\3d29do9n5zader101.bin" "c:\windows\system32\3z71hac59ool14e.exe" "c:\windows\system32\59edownloader95z.bin" "c:\windows\system32\5d6zhre9t24991.exe" "c:\windows\system32\5edownz9ader102.dll" "c:\windows\system32\6ae5stzal18559.dll" "c:\windows\system32\6d96threat2457z.dll" "c:\windows\system32\9a5fthrzat205005.bin" "c:\windows\system32\z45n9t-a-viru524.dll" "c:\windows\z4546w9rm885.bin" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\21898ziru55c0.bin c:\windows\2195zspambot71f.ocx c:\windows\21e9spywa5e2z759.cpl c:\windows\22396sz52cd.ocx c:\windows\23386haczto9l6ee5.dll c:\windows\23z78tr5963d.ocx c:\windows\240055ot-a9vzrus54f.bin c:\windows\24010hzcktoo5927.ocx c:\windows\24707zro9195.dll c:\windows\253849ot-a-virzs7e5.ocx c:\windows\25486vir9sz5a.ocx c:\windows\25698nz9-a-5irus65f.ocx c:\windows\2591zorm5589.cpl c:\windows\25d2zackdoor9021.ocx c:\windows\26257not5a-vzrus493.bin c:\windows\264wor596fz.ocx c:\windows\26991hzckto5l51f.exe c:\windows\277075ot-9zvirus6dd.dll c:\windows\27d5zh5ef6819.ocx c:\windows\27easpyw9rez195.bin c:\windows\28345tz9j490.ocx c:\windows\284z55roj6199.bin c:\windows\284z9t5oj487.dll c:\windows\28798t5oz302.dll c:\windows\29142spz59c9.bin c:\windows\29255tro954z.ocx c:\windows\29265tzo5169.exe c:\windows\29599spy60az.ocx c:\windows\2993steaz5900.exe c:\windows\2997s5z58a.exe c:\windows\29z3backd9or2855.exe c:\windows\2bb5adzwar91914.exe c:\windows\2c36zackdoo9583.cpl c:\windows\2e77spyzar510379.dll c:\windows\2z550troj595.cpl c:\windows\30555s9yz53.dll c:\windows\30785o9-a-zirus56f.cpl c:\windows\30a4dow9loaderz175.ocx c:\windows\31063zir5s529.ocx c:\windows\3195hackt9olaz.ocx c:\windows\323aad5w9rez386.bin c:\windows\359czir1821.cpl c:\windows\35dcvi92z31.bin c:\windows\35dethiz95345.dll c:\windows\36fdow9loader55z5.ocx c:\windows\384download5rz059.dll c:\windows\38f1addwa5e1z90.ocx c:\windows\39755zo5m92.bin c:\windows\3b6ez9d5are913.ocx c:\windows\3c98thizf5460.ocx c:\windows\3f59addwaze593.bin c:\windows\3z158worm2fa9.ocx c:\windows\3z550not-a-v59us112.bin c:\windows\4056s9azse2994.ocx c:\windows\4128spyw5r91z94.dll c:\windows\4545ha9kto5z501.ocx c:\windows\4555virz7959.cpl c:\windows\4570hack5oolzc39.cpl c:\windows\458e9zreat525.ocx c:\windows\46fzthreat9515.dll c:\windows\490hacztool5c45.bin c:\windows\4a3cspar5e259z.dll c:\windows\4a91d9znl5ader3136.bin c:\windows\4f3spz5ar92939.bin c:\windows\4zaadownloader495.dll c:\windows\505z39orm158.ocx c:\windows\51005wo9m447z.exe c:\windows\5226thief63z9.exe c:\windows\523bdo9nlo5zer1918.cpl c:\windows\52941zpy335.dll c:\windows\53675py109z.cpl c:\windows\54036spz597.dll c:\windows\540z5tr9jaf.ocx c:\windows\5560addz5re9730.dll c:\windows\556addwaz91591.cpl c:\windows\55es9zrse355.bin c:\windows\5620addwzre905.ocx c:\windows\5669dow5lozde91477.exe c:\windows\5709zack95or2789.cpl c:\windows\577zbackdo5r2429.dll c:\windows\57e8threatz9339.bin c:\windows\5936sparse183z.dll c:\windows\59500zorm5a9.dll c:\windows\5965t9oj2z15.exe c:\windows\5986addware1443z.exe c:\windows\598bstzal1157.exe c:\windows\5995thzef1448.cpl c:\windows\599szeal1706.cpl c:\windows\59d9stealz125.exe c:\windows\59z6spyw9re4175.cpl c:\windows\5fz5threat235469.dll c:\windows\5z599pambo537b.dll c:\windows\5z6dbackdo5r2394.ocx c:\windows\6109threatz4395.exe c:\windows\6211zack9oor3815.ocx c:\windows\62d9vir2554z.exe c:\windows\6388w5rm9z8.bin c:\windows\64675pars93z72.dll c:\windows\649zspambo549.cpl c:\windows\650caddw9rz1726.bin c:\windows\6539ste9l2000z.exe c:\windows\65989zreat21557.exe c:\windows\65a8dow5loazer1889.dll c:\windows\65e2zhreat531129.ocx c:\windows\65f5z9eal157.ocx c:\windows\6659sparse123z.bin c:\windows\6665threat2z292.bin c:\windows\6795spyw9rz2045.ocx c:\windows\6799dzw5loader784.ocx c:\windows\6958threa9z0335.exe c:\windows\6bdzvir1579.ocx c:\windows\6be0addw5z91966.cpl c:\windows\6d55sparze19805.bin c:\windows\6fczt9r5at2321.exe c:\windows\7152spa9bot5ffz.exe c:\windows\729zspy5are856.exe c:\windows\755sp9rsez1735.bin c:\windows\758fback9oor638z.cpl c:\windows\75z6spye9.exe c:\windows\765cth9zat53072.ocx c:\windows\779ddow9loaze5584.bin c:\windows\785zsp53069.dll c:\windows\7895spa5ze257.ocx c:\windows\78b5spywzre950.cpl c:\windows\78c6d5wnloaderz901.ocx c:\windows\7b54sp9zse661.exe c:\windows\7d569ownlozder2519.bin c:\windows\7e6evi5z292.bin c:\windows\8029hrzat113525.exe c:\windows\805thr9az25829.ocx c:\windows\81caddwz9e6555.ocx c:\windows\9002zspam5ot435.bin c:\windows\903b5hiez2204.exe c:\windows\91997not-a-5zrus279.ocx c:\windows\91c5thiez1945.dll c:\windows\91z5spyware2737.ocx c:\windows\94a9ddzare351.dll c:\windows\95z3wormb3.bin c:\windows\96336noz-a-5irus724.dll c:\windows\965aaddwarz434.exe c:\windows\9679spazs5192.dll c:\windows\97504virzs306.bin c:\windows\978bbz5kdoor258.bin c:\windows\9866nz5-a-virus6c1.cpl c:\windows\9870hazktoo5434.bin c:\windows\99600zot5a-virus5ae.bin c:\windows\9975zdware1958.bin c:\windows\999295yz53.bin c:\windows\99cathief1599z.dll c:\windows\9a1zste5l2955.exe c:\windows\system32\1093b9ckdo5rz51.bin c:\windows\system32\15570szambot9d7.exe c:\windows\system32\18c2thz5at19699.bin c:\windows\system32\23474v9r5s42z.dll c:\windows\system32\23901zot-a-5irus731.dll c:\windows\system32\24473spa9bot5z5.exe c:\windows\system32\2f01viz9570.bin c:\windows\system32\331fth59at1109z.exe c:\windows\system32\3d29do9n5zader101.bin c:\windows\system32\3z71hac59ool14e.exe c:\windows\system32\59edownloader95z.bin c:\windows\system32\5d6zhre9t24991.exe c:\windows\system32\5edownz9ader102.dll c:\windows\system32\6ae5stzal18559.dll c:\windows\system32\6d96threat2457z.dll c:\windows\system32\9a5fthrzat205005.bin c:\windows\system32\z45n9t-a-viru524.dll c:\windows\z4546w9rm885.bin . ((((((((((((((((((((((((( Files Created from 2009-09-16 to 2009-10-16 ))))))))))))))))))))))))))))))) . 2009-10-08 13:26 . 2009-10-08 13:29 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2009-10-07 15:35 . 2009-10-07 15:35 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-10-07 15:32 . 2009-10-07 18:14 -------- d-----w- c:\documents and settings\Thomas\Local Settings\Application Data\Adobe 2009-10-07 15:31 . 2009-10-07 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-10-07 15:24 . 2009-10-07 15:24 -------- d-----w- c:\windows\Sun 2009-10-04 18:57 . 2009-10-04 18:57 0 ----a-w- c:\windows\nsreg.dat 2009-10-04 18:57 . 2009-10-04 18:57 -------- d-----w- c:\documents and settings\Thomas\Local Settings\Application Data\Mozilla 2009-10-04 13:09 . 2009-10-04 13:09 -------- d-----w- c:\documents and settings\Thomas\Application Data\Trusteer 2009-10-04 13:09 . 2009-10-04 13:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Trusteer 2009-10-04 13:09 . 2009-10-04 13:09 -------- d-----w- c:\program files\Trusteer 2009-10-01 17:00 . 2009-10-06 16:25 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore 2009-10-01 16:59 . 2009-10-01 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\SiteAdvisor 2009-10-01 16:59 . 2009-10-01 16:59 -------- d-----w- c:\program files\Common Files\McAfee 2009-10-01 16:58 . 2009-10-02 00:09 -------- d-----w- c:\program files\McAfee 2009-10-01 09:56 . 2004-08-04 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll 2009-10-01 09:56 . 2009-10-01 09:56 -------- d-----w- c:\program files\Windows Media Connect 2 2009-10-01 09:52 . 2009-10-01 09:54 -------- d-----w- c:\windows\system32\drivers\UMDF 2009-10-01 09:52 . 2009-10-01 09:52 -------- d-----w- c:\windows\system32\LogFiles 2009-09-30 17:32 . 2009-09-30 17:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-09-30 17:31 . 2009-10-15 18:28 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-09-30 17:31 . 2009-09-30 17:31 -------- d-----w- c:\documents and settings\Thomas\Application Data\SUPERAntiSpyware.com 2009-09-30 17:31 . 2009-09-30 17:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-09-30 17:16 . 2009-09-30 17:16 -------- d-----w- c:\program files\CCleaner 2009-09-30 17:08 . 2009-09-30 17:07 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-09-30 17:07 . 2009-09-30 17:07 -------- d-----w- c:\program files\Java 2009-09-30 12:47 . 2008-12-11 07:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-09-30 12:46 . 2009-08-24 13:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-09-30 12:46 . 2009-08-19 10:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-09-30 12:46 . 2009-09-30 12:50 -------- d-----w- c:\program files\Common Files\PC Tools 2009-09-30 12:46 . 2008-12-10 10:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2009-09-30 12:46 . 2009-10-15 23:42 -------- d-----w- c:\program files\Spyware Doctor 2009-09-30 12:46 . 2009-09-30 12:46 -------- d-----w- c:\documents and settings\Thomas\Application Data\PC Tools 2009-09-30 12:46 . 2009-09-30 12:46 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-09-30 12:45 . 2009-10-16 00:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-09-30 12:39 . 2009-09-30 12:39 -------- d-----w- c:\documents and settings\Thomas\Application Data\Malwarebytes 2009-09-30 12:39 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-30 12:39 . 2009-09-30 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-09-30 12:39 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-30 12:39 . 2009-09-30 12:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-30 10:07 . 2009-10-01 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-09-29 07:25 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll 2009-09-29 07:25 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-09-28 17:20 . 2009-09-28 17:20 -------- d-sh--w- c:\documents and settings\Thomas\IECompatCache 2009-09-28 13:27 . 2009-10-15 22:31 -------- d-----w- c:\documents and settings\Thomas\Tracing 2009-09-28 13:25 . 2009-09-28 13:25 -------- d-----w- c:\program files\Microsoft 2009-09-28 13:25 . 2009-09-28 13:25 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-09-28 13:24 . 2009-09-28 13:25 -------- d-----w- c:\program files\Windows Live 2009-09-28 13:22 . 2009-09-28 13:22 -------- d-----w- c:\program files\Common Files\Windows Live 2009-09-28 12:55 . 2009-09-28 12:55 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-09-28 10:06 . 2009-09-28 10:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan 2009-09-28 10:06 . 2009-09-28 10:06 -------- d-----w- c:\program files\McAfee Security Scan 2009-09-28 01:27 . 2009-09-28 01:27 -------- d-sh--w- c:\documents and settings\Thomas\PrivacIE 2009-09-28 01:24 . 2009-09-28 01:24 -------- d-sh--w- c:\documents and settings\Thomas\IETldCache 2009-09-28 01:16 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-09-28 01:15 . 2009-09-28 01:15 -------- d-----w- c:\windows\ie8updates 2009-09-28 01:14 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-09-28 01:14 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-09-28 01:07 . 2009-09-28 01:13 -------- dc-h--w- c:\windows\ie8 2009-09-28 00:42 . 2009-09-28 00:42 -------- d-----w- C:\Google 2009-09-27 20:39 . 2009-09-27 20:39 -------- d-----w- c:\windows\system32\scripting 2009-09-27 20:39 . 2009-09-27 20:39 -------- d-----w- c:\windows\l2schemas 2009-09-27 20:39 . 2009-09-27 20:39 -------- d-----w- c:\windows\system32\en 2009-09-27 20:39 . 2009-09-27 20:39 -------- d-----w- c:\windows\system32\bits 2009-09-27 20:29 . 2009-09-27 20:41 -------- d-----w- c:\windows\ServicePackFiles 2009-09-27 20:04 . 2009-09-27 20:04 -------- d-----w- c:\windows\EHome 2009-09-27 19:47 . 2004-08-03 21:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys 2009-09-27 19:47 . 2004-08-03 21:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys 2009-09-27 19:47 . 2004-08-03 21:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys 2009-09-27 19:47 . 2004-08-03 21:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys 2009-09-27 19:47 . 2004-08-03 21:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys 2009-09-27 19:47 . 2004-08-03 21:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys 2009-09-27 19:46 . 2004-08-03 21:41 129535 ------w- c:\windows\system32\drivers\slnt7554.sys 2009-09-27 19:46 . 2004-08-03 21:29 166912 ------w- c:\windows\system32\drivers\s3gnbm.sys 2009-09-27 19:46 . 2004-08-03 21:29 1897408 ------w- c:\windows\system32\drivers\nv4_mini.sys 2009-09-27 19:46 . 2004-08-03 21:29 452736 ------w- c:\windows\system32\drivers\mtxparhm.sys 2009-09-27 19:46 . 2004-08-03 21:41 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys 2009-09-27 19:46 . 2004-08-03 21:41 1041536 ------w- c:\windows\system32\drivers\hsfdpsp2.sys 2009-09-27 19:46 . 2004-08-03 21:41 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys 2009-09-27 19:46 . 2004-08-03 21:41 220032 ------w- c:\windows\system32\drivers\hsfbs2s2.sys 2009-09-27 18:34 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll 2009-09-27 18:33 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll 2009-09-27 18:04 . 2009-09-27 18:04 -------- d-----w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec 2009-09-27 18:00 . 2009-09-27 18:01 60800 ----a-w- c:\windows\system32\S32EVNT1.DLL 2009-09-27 18:00 . 2009-09-27 18:01 123952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2009-09-27 17:59 . 2009-06-22 06:44 726528 -c--a-w- c:\windows\system32\dllcache\jscript.dll 2009-09-27 17:55 . 2009-09-27 18:01 -------- d-----w- c:\program files\Symantec 2009-09-27 17:50 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys 2009-09-27 17:50 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys 2009-09-27 17:50 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys 2009-09-27 17:50 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll 2009-09-27 17:50 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll 2009-09-27 17:48 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll 2009-09-23 23:26 . 2009-09-23 23:26 8793 ----a-w- c:\windows\system32\24957wormzbb.exe 2009-09-23 20:05 . 2009-09-23 20:08 -------- d-----w- C:\Train Store 2009-09-23 18:57 . 2009-09-23 18:57 -------- d-----w- c:\program files\J A Formoso . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-10-15 15:59 . 2009-10-15 15:59 -------- d-----w- c:\documents and settings\Thomas\Application Data\Apple Computer 2009-10-15 15:56 . 2009-10-15 15:53 -------- d-----w- c:\program files\iTunes 2009-10-15 15:56 . 2009-10-15 15:53 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-15 15:54 . 2009-10-15 15:54 -------- d-----w- c:\program files\iPod 2009-10-15 15:54 . 2009-10-15 15:46 -------- d-----w- c:\program files\Common Files\Apple 2009-10-15 15:53 . 2009-10-15 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2009-10-15 15:52 . 2009-10-15 15:52 -------- d-----w- c:\program files\Bonjour 2009-10-15 15:51 . 2006-02-13 11:55 -------- d-----w- c:\program files\QuickTime 2009-10-15 15:47 . 2009-10-15 15:47 -------- d-----w- c:\program files\Apple Software Update 2009-10-15 15:46 . 2009-10-15 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2009-10-07 18:07 . 2006-01-27 16:43 -------- d-----w- c:\program files\Common Files\Adobe 2009-09-30 20:23 . 2006-01-27 15:53 98176 ----a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-28 00:42 . 2006-04-04 11:14 -------- d-----w- c:\program files\Google 2009-09-27 18:05 . 2006-02-01 16:08 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-09-27 18:04 . 2006-02-01 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2009-09-27 18:01 . 2009-09-27 18:00 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF 2009-09-27 18:01 . 2009-09-27 18:00 10563 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2009-09-10 05:34 . 2009-09-10 05:34 9031 ----a-w- c:\windows\system32\445cvir9844z.bin 2009-09-05 19:01 . 2009-09-05 19:01 -------- d-----w- c:\program files\Western Digital 2009-09-04 02:56 . 2009-09-04 02:56 11152 ----a-w- c:\windows\system32\6192zroj359.dll 2009-09-02 13:25 . 2009-09-02 13:25 11150 ----a-w- c:\windows\system32\64dthre5t66z49.exe 2009-09-01 13:33 . 2009-09-01 13:33 15758 ----a-w- c:\windows\z5d15ownloader2909.bin 2009-08-25 21:35 . 2009-08-25 21:35 9674 ----a-w- c:\windows\system32\5224virzs9ab.dll 2009-08-24 16:37 . 2009-08-24 16:37 4390 ----a-w- c:\windows\system32\6904nzt-a-5ir9s82.exe 2009-08-21 13:16 . 2009-08-21 13:16 5290 ----a-w- c:\windows\system32\44e8st5al299z.bin 2009-08-16 11:22 . 2009-08-16 11:22 16433 ----a-w- c:\windows\system32\d9cadzwa9e520.exe 2009-08-12 12:15 . 2009-08-12 12:15 17018 ----a-w- c:\windows\system32\9437download5r2408z.exe 2009-08-08 05:06 . 2009-08-08 05:06 15492 ----a-w- c:\windows\system32\29zaspyware185.bin 2009-08-08 04:48 . 2009-08-08 04:48 12761 ----a-w- c:\windows\system32\956ha5k9ozla6.dll 2009-08-06 18:24 . 2006-01-11 11:56 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-06 18:24 . 2006-01-11 11:56 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-06 18:24 . 2006-01-11 11:56 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-06 18:24 . 2005-05-26 03:16 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-06 18:24 . 2006-01-11 11:56 53472 ------w- c:\windows\system32\wuauclt.exe 2009-08-06 18:24 . 2006-01-11 18:34 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-06 18:23 . 2006-01-11 11:56 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-06 18:23 . 2006-01-11 11:56 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2006-01-11 18:34 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-29 04:37 . 2006-01-11 18:34 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-07-29 04:37 . 2006-01-11 18:34 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-07-26 15:44 . 2009-07-26 15:44 48448 ----a-w- c:\windows\system32\sirenacm.dll 2009-07-26 15:12 . 2009-07-26 15:12 6239 ----a-w- c:\windows\system32\90651szam5ot723.exe 2009-07-23 02:22 . 2009-07-23 02:22 15918 ----a-w- c:\windows\system32\35c4thre9t22z15.exe 2009-07-22 22:50 . 2009-07-22 22:50 10947 ----a-w- c:\windows\system32\9c37backdzor2539.dll 2009-07-19 13:12 . 2009-07-19 13:12 8723 ----a-w- c:\windows\z2432troj995.exe 2006-04-03 20:24 . 2006-04-04 11:14 11817800 ----a-w- c:\program files\GoogleEarth.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "IW_Drop_Icon"="c:\program files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.ex e" [2003-11-19 1134080] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2009-09-28 39408] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-28 110592] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-28 634880] "PinnacleDriverCheck"="c:\windows\system32\PSDrvCh eck.exe" [2003-11-10 406016] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.E XE" [2004-08-04 208952] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScI nst.exe" [2004-08-04 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT \TINTSETP.EXE" [2004-08-04 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TIN TSETP.EXE" [2004-08-04 455168] "Net-It Launcher"="c:\windows\system32\NILaunch.exe" [1998-02-05 24576] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-22 115560] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-30 149280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] c:\documents and settings\All Users\Start Menu\Programs\Startup\ McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184] Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864] [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ccEvtMgr] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ccSetMgr] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Symantec Antivirus] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kazga.exe.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kazga.exe.lnk backup=c:\windows\pss\Kazga.exe.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk backup=c:\windows\pss\Lotus Organizer EasyClip.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus QuickStart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus QuickStart.lnk backup=c:\windows\pss\Lotus QuickStart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SmartCenter.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus SmartCenter.lnk backup=c:\windows\pss\Lotus SmartCenter.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SuiteStart.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus SuiteStart.lnk backup=c:\windows\pss\Lotus SuiteStart.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Thomas^Start Menu^Programs^Startup^Encarta Dictionary Quickshelf.lnk] path=c:\documents and settings\Thomas\Start Menu\Programs\Startup\Encarta Dictionary Quickshelf.lnk backup=c:\windows\pss\Encarta Dictionary Quickshelf.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Thomas^Start Menu^Programs^Startup^Lotus SmartSuite Release 9 Registration.lnk] path=c:\documents and settings\Thomas\Start Menu\Programs\Startup\Lotus SmartSuite Release 9 Registration.lnk backup=c:\windows\pss\Lotus SmartSuite Release 9 Registration.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "CCALib8"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"= "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [30/09/2009 13:46 206256] R0 VOBID;VOBID;c:\windows\system32\drivers\vobid.sys [01/08/2003 15:47 29239] R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [27/09/2009 12:53 58856] R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [27/09/2009 12:53 333928] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15/09/2009 11:42 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/09/2009 11:42 74480] R1 vobcom;vobcom;c:\windows\system32\drivers\vobcom.s ys [04/10/2001 12:53 9728] R1 vobiw;vobiw;c:\windows\system32\drivers\vobIW.sys [27/08/2003 18:48 187392] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [01/10/2009 17:59 210216] R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [27/09/2009 12:53 967912] R3 cdrdrv;Cdrdrv;c:\windows\system32\drivers\Cdrdrv.s ys [13/12/2002 19:33 64000] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [11/01/2006 19:36 191092] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [14/10/2009 10:26 102448] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mo n.sys [22/07/2009 16:40 23888] S3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStb y.sys [11/01/2006 19:36 6100] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/09/2009 11:42 7408] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [30/09/2009 13:46 348824] --- Other Services/Drivers In Memory --- *Deregistered* - mchInjDrv [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: QuickDefine - c:\program files\Common Files\Microsoft Shared\Reference Titles\eddefine.htm IE: QuickTranslate - c:\program files\Common Files\Microsoft Shared\Reference Titles\edtrans.htm Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\1f7j90nn.default\ FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll . ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-16 01:27 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(608) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(2992) c:\windows\system32\WININET.dll c:\program files\Spyware Doctor\pctgmhk.dll c:\program files\McAfee\SiteAdvisor\saHook.dll c:\program files\Trusteer\Rapport\bin\rooksbas.dll c:\program files\Trusteer\Rapport\bin\MSVCR80.dll c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\ieframe.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLL c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLL c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\ConnAPI.DLL c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Trusteer\Rapport\bin\RapportService.exe . ************************************************** ************************ . Completion time: 2009-10-16 1:47 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-16 00:47 ComboFix2.txt 2009-10-15 22:39 Pre-Run: 36,609,404,928 bytes free Post-Run: 36,576,153,600 bytes free 528 --- E O F --- 2009-10-02 12:22 |
|
#13
| |||
| |||
| Were getting there. Start Malwarebytes and go to the More Tools tab. There you'll find a button named Run Tool to run FileASSISSIN. Then browse to this file: c:\windows\system32\24957wormzbb.exe Double click 24957wormzbb.exe and click OK, then Yes to remove it. ---------- * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log |
|
#14
| |||
| |||
| I've managed to run File Assassin but cannot run Combofix /u, probably because I've already deleted it. Whenever I try to run it Windows says it can't find it. Shall I still carry on? |
|
#15
| |||
| |||
| Yes just continue on. |
![]() |
|
| Bookmarks |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Harddrive Error on Bootup - "Disk Error" "Press any key to restart" | ashaiba | General Hardware Chat | 6 | 13th Mar 2009 15:56 |
| Will "Office 95" work with "Windows XP"? | Raynhawk | Office Suites & Applications | 4 | 23rd Feb 2009 17:01 |
| Problems with "Check your hard disk for errors" feature | pest79456 | Linux & Alternative OS | 3 | 16th Oct 2008 04:16 |
| Can not put "ENABLE" function "on" in Bios ref CD/DVD. | ashmehta | Laptops, Mobiles & PDAs | 8 | 17th Jun 2008 02:56 |
| Laptop not starting up, "syntax" or "disk error". | aechain | Windows Operating Systems | 5 | 24th Jan 2008 15:45 |
| Thread Tools | |
| |