Jump to content

Recommended Posts

Posted

Hi, just wondered if anyone could help - yesterday I booted up my Toshiba equium m70 laptop to be met by a green desktop with a black box containing words to the effect of

'' your computer is infected by spyware......''. I realised this was probably a fake spyware program so ran norton antivirus & then aol spyware protection - neither scan detected anything. After looking for advice on a few other websites (on my netbook) I downloaded Malwarebytes and scanned it with that. Malwarebytes found 17 spyware/malware issues & quarantined them all & I then deleted them. Problem solved - or so I thought - now everytime I launch internet explorer 8 a dialogue box pops up saying '' cannot find 'http://ny........'' followed by a line of strange symbols and ''make sure the path or internet address is correct''. Whenever I close this or click ok, it immediately opens IE in another window and each time I close the window another box pops up again and so on. I'm assuming this is something to do with the spyware issue but not sure what to do about it.

Any advice would be greatly appreciated thanks.

Dave.

  • Replies 8
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Hi Dave,

 

A few things before we start....

1. Please Read All Instructions Carefully.

2. If you don't understand something, stop and ask! Don't keep going on.

3. Please do not run any other tools or scans whilst I am helping you.

4. If you have to go away for an extended period of time, let me know.

5. Please continue to respond until I give you the "All Clear".

(Just because you can't see a problem doesn't mean it isn't there)

 

 

Let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:

 

Go here ======> A guide and tutorial on using ComboFix <====== Go here

 

Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.

 

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

 

Once installed, you should get a prompt that says:

 

The Recovery Console was successfully installed.

 

Please continue as follows:

 

(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

(2) Click Yes to allow ComboFix to continue scanning for malware.

 

When the tool is finished, it will produce a report for you.

 

 

Please include C:\ComboFix.txt for further review, so that we may continue cleansing the system.

 

 

Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.

Posted

Hi Chiaz, thanks for your reply, sorry I've taken so long to get back to you - I followed your instructions, here is the report :

 

ComboFix 09-12-05.06 - Dave 06/12/2009 15:34.1.1 - x86

Running from: E:\ComboFix.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\system32\tmp.reg

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected

Restored copy from - Kitty ate it :p

.

((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))

.

2009-12-05 16:39 . 2009-12-05 16:39 -------- d-----w- c:\program files\Common Files\Apple

2009-12-05 16:38 . 2009-12-05 16:38 -------- d-----w- c:\program files\QuickTime

2009-12-05 16:38 . 2009-12-05 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer

2009-12-05 16:35 . 2009-12-05 16:35 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple

2009-12-05 12:33 . 2009-12-03 16:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-12-05 12:33 . 2009-12-03 16:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-05 12:33 . 2009-12-05 15:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-12-04 18:13 . 2009-12-04 18:13 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2009-12-04 18:04 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll

2009-12-04 18:02 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2009-12-04 18:02 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2009-12-04 17:28 . 2009-12-04 17:28 -------- d-----w- c:\windows\system32\wbem\Repository

2009-12-04 17:22 . 2009-12-04 17:22 -------- d-sh--w- c:\documents and settings\Dave\IECompatCache

2009-12-04 17:22 . 2009-12-04 17:22 -------- d-sh--w- c:\documents and settings\Dave\PrivacIE

2009-12-04 17:13 . 2009-12-04 17:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2009-12-04 17:09 . 2009-12-04 17:09 -------- d-sh--w- c:\documents and settings\Dave\IETldCache

2009-12-04 17:02 . 2009-12-05 17:07 -------- d-----w- c:\windows\ie8updates

2009-12-04 16:57 . 2009-12-05 15:09 -------- dc-h--w- c:\windows\ie8

2009-12-04 10:39 . 2009-12-04 10:39 -------- d-----w- c:\documents and settings\Dave\Application Data\Malwarebytes

2009-12-04 10:39 . 2009-12-04 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-12-02 19:22 . 2006-10-26 19:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll

2009-12-02 19:22 . 2008-11-10 11:41 32656 ----a-w- c:\windows\system32\msonpmon.dll

2009-12-02 19:17 . 2009-12-02 19:18 -------- d-----w- c:\windows\SHELLNEW

2009-12-02 19:17 . 2009-12-02 19:17 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\Microsoft Help

2009-12-02 19:15 . 2009-12-04 01:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-12-02 18:51 . 2009-12-02 19:25 -------- d-----w- c:\documents and settings\Dave\Application Data\GetRightToGo

2009-11-24 22:56 . 2009-11-24 22:56 -------- d-----w- c:\documents and settings\Dave\Application Data\Apple Computer

2009-11-10 22:35 . 2009-11-10 22:35 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\WMTools Downloaded Files

2009-11-10 20:00 . 2009-11-10 20:00 -------- d-----w- C:\divx

2009-11-08 14:14 . 2009-11-08 14:14 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\Sony

2009-11-08 14:11 . 2009-11-08 14:11 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\Apple

2009-11-08 14:11 . 2009-11-08 14:11 -------- d-----w- c:\program files\Apple Software Update

2009-11-08 14:11 . 2009-11-08 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple

2009-11-08 14:11 . 2009-11-08 14:11 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\Apple Computer

2009-11-08 14:08 . 2009-11-08 14:14 -------- d-----w- c:\documents and settings\Dave\Application Data\Sony

2009-11-08 14:07 . 2009-11-08 14:07 -------- d-----w- c:\documents and settings\Dave\Local Settings\Application Data\Sony Ericsson

2009-11-08 14:06 . 2008-11-04 08:52 108328 ----a-w- c:\windows\system32\drivers\s1018mgmt.sys

2009-11-08 14:06 . 2008-11-04 08:52 10792 ----a-w- c:\windows\system32\drivers\s1018cr.sys

2009-11-08 14:06 . 2008-11-04 08:52 109736 ----a-w- c:\windows\system32\drivers\s1018unic.sys

2009-11-08 14:06 . 2008-11-04 08:52 26024 ----a-w- c:\windows\system32\drivers\s1018nd5.sys

2009-11-08 14:06 . 2008-11-04 08:52 104616 ----a-w- c:\windows\system32\drivers\s1018obex.sys

2009-11-08 14:06 . 2008-11-04 08:52 15016 ----a-w- c:\windows\system32\drivers\s1018mdfl.sys

2009-11-08 14:06 . 2008-11-04 08:52 12200 ----a-w- c:\windows\system32\drivers\s1018cmnt.sys

2009-11-08 14:06 . 2008-11-04 08:52 12200 ----a-w- c:\windows\system32\drivers\s1018cm.sys

2009-11-08 14:06 . 2008-11-04 08:52 114472 ----a-w- c:\windows\system32\drivers\s1018mdm.sys

2009-11-08 14:06 . 2008-11-04 08:52 12200 ----a-w- c:\windows\system32\drivers\s1018whnt.sys

2009-11-08 14:06 . 2008-11-04 08:52 12200 ----a-w- c:\windows\system32\drivers\s1018wh.sys

2009-11-08 14:06 . 2008-11-04 08:52 86696 ----a-w- c:\windows\system32\drivers\s1018bus.sys

2009-11-08 14:05 . 2009-11-08 14:05 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpe9D.dll

2009-11-08 14:05 . 2009-11-08 14:05 -------- d-----w- c:\program files\Sony Ericsson

2009-11-08 14:05 . 2009-11-08 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-06 15:34 . 2005-09-16 06:26 -------- d-----w- c:\program files\Common Files\Symantec Shared

2009-12-06 14:27 . 2009-02-09 22:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2009-12-05 11:33 . 2007-09-02 17:14 -------- d-----w- c:\program files\Lx_cats

2009-12-04 01:34 . 2005-09-19 08:14 -------- d-----w- c:\program files\Microsoft Works

2009-12-03 17:17 . 2005-09-15 08:46 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-11-27 14:21 . 2005-09-16 06:27 -------- d-----w- c:\program files\Norton Internet Security

2009-11-08 14:14 . 2006-08-20 13:58 -------- d-----w- c:\program files\Common Files\Sony Shared

2009-11-08 14:13 . 2006-08-20 13:58 -------- d-----w- c:\program files\Sony

2009-11-08 14:07 . 2006-07-27 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software

2009-09-11 14:18 . 2005-09-15 06:09 136192 ----a-w- c:\windows\system32\msv1_0.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-02-16 405504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP" [X]

"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL" [X]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]

"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 88358]

"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]

"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]

"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 53248]

"Zooming"="ZoomingHook.exe" [2005-06-06 24576]

"TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 28672]

"TPSMain"="TPSMain.exe" [2005-08-11 266240]

"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 118784]

"TFncKy"="TFncKy.exe" [bU]

"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-08-30 1077329]

"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]

"NDSTray.exe"="NDSTray.exe" [bU]

"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-08 49512]

"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2005-05-06 22656]

"CFSServ.exe"="CFSServ.exe" [bU]

"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2007-12-07 71008]

"HostManager"="c:\program files\Common Files\AOL\1153425322\ee\AOLSoftware.exe" [2006-11-17 50736]

"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 222208]

"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-05-07 100056]

"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]

"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]

"lxdjamon"="c:\program files\Lexmark 1400 Series\lxdjamon.exe" [2007-03-06 20480]

"LXDJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDJtime.dll" [2007-02-09 102400]

"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Common Files\\AOL\\1153425322\\ee\\AOLServiceHost.exe"=

"c:\\WINDOWS\\system32\\lxdjcoms.exe"=

"c:\\Program Files\\Lexmark 1400 Series\\lxdjamon.exe"=

"c:\\Program Files\\Lexmark 1400 Series\\App4R.exe"=

"c:\\WINDOWS\\system32\\lxdjcfg.exe"=

"c:\\Program Files\\Common Files\\AOL\\1153425322\\ee\\aolsoftware.exe"=

"c:\\Program Files\\AOL 9.0 VR\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=

"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=

"c:\\Program Files\\Lexmark 1400 Series\\Wireless\\lxdjwpss.exe"=

"c:\\Program Files\\AOL 9.0\\waol.exe"=

"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjpswx.exe"=

"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjjswx.exe"=

"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjtime.exe"=

R2 gupdate1c98b06dc3ce414;Google Update Service (gupdate1c98b06dc3ce414);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104]

R3 PAC207;SoC PC-Camer@;c:\windows\system32\DRIVERS\pfc027.sys [2005-02-24 162176]

R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]

R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]

R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]

R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108328]

R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]

R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]

R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com

DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://homebase.2020.net/Core/Player/2020PlayerAX_Win32.cab

DPF: {3FDA5826-89EB-458C-BF30-93267F601014} - hxxp://www.flexwatch.com/app_link/download/FwSimCtl.cab

.

- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)

HKLM-Run-Loader - c:\windows\System\loader.exe

HKLM-Run-lxdjmon.exe - c:\program files\Lexmark 1400 Series\lxdjmon.exe

AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

AddRemove-{2FCE4FC5-6930-40E7-A4F1-F862207424EF} - c:\program files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe REMOVEALL

AddRemove-{91810AFC-A4F8-4EBA-A5AA-B198BBC81144} - c:\program files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe REMOVEALL

 

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2009-12-06 15:54

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXDJCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDJtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(760)

c:\windows\system32\msacm32.drv

.

Completion time: 2009-12-06 16:01

ComboFix-quarantined-files.txt 2009-12-06 16:01

Pre-Run: 7,446,138,880 bytes free

Post-Run: 7,989,743,616 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 4A2B438127155077E346055882685BA0

Posted

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

 

c:\documents and settings\All Users\Application Data\hpe9D.dll

 

Then click Submit. Allow the file to be scanned, and then please Copy/Paste the results here for me to see.

 

If Jotti is busy, please go to http://www.virustotal.com.

 

===============================================

 

Next, please go HERE to run Panda ActiveScan 2.0

  • Click the big green Scan now button.
  • If it wants to install an ActiveX component allow it.
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • The scan may take some time. Once it is completed, please hit the notepad icon next to the text Export to:
  • Save it to a convenient location such as your Desktop.
  • Post the contents of the ActiveScan.txt in your next reply, along with the VirusTotal/Jotti results.

Posted

Scan took about 4 hours !

Results :

 

;***********************************************************************************************************************************************************************************

ANALYSIS: 2009-12-07 16:53:39

PROTECTIONS: 1

MALWARE: 10

SUSPECTS: 0

;***********************************************************************************************************************************************************************************

PROTECTIONS

Description Version Active Updated

;===================================================================================================================================================================================

Norton Internet Security 2005 Yes Yes

;===================================================================================================================================================================================

MALWARE

Id Description Type Active Severity Disinfectable Disinfected Location

;===================================================================================================================================================================================

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@doubleclick[2].txt

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@atdmt[1].txt

00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@tradedoubler[1].txt

00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@tribalfusion[2].txt

00167753 Cookie/Statcounter TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@statcounter[2].txt

00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No c:\documents and settings\dave\cookies\dave@questionmarket[2].txt

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\57f86dcc.exe

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\34f65857.exe

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\6fa9394b.exe

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\2efd2c2b.exe

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\00594aa9.sys

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\04192665.htm

00447834 Adware/Lop Adware No 0 Yes No c:\program files\norton internet security\norton antivirus\quarantine\1d6005ec.exe

00484705 Application/IEDefender HackTools No 0 Yes No c:\documents and settings\dave\desktop\unused\smitfraudfix\smitfraudfix.zip[smitfraudfix/iedfix.c.exe]

00484705 Application/IEDefender HackTools No 0 Yes No c:\documents and settings\dave\desktop\unused\smitfraudfix\iedfix.c.exe

01270987 Generic Malware Virus/Trojan No 0 Yes No c:\documents and settings\dave\desktop\unused\smitfraudfix.exe

03541233 HackTool/Rebooter HackTools No 0 No No c:\documents and settings\dave\desktop\unused\smitfraudfix.exe[c:\documents and settings\dave\desktop\unused\smitfraudfix.exe][smitfraudfix\reboot.exe]

03541233 HackTool/Rebooter HackTools No 0 Yes No c:\system volume information\_restore{fa76aae1-0d6b-45e6-a0e5-2e9bb81be9ad}\rp270\a0012407.exe

;===================================================================================================================================================================================

SUSPECTS

Sent Location

;===================================================================================================================================================================================

;===================================================================================================================================================================================

VULNERABILITIES

Id Severity Description

;===================================================================================================================================================================================

;===================================================================================================================================================================================

Posted (edited)

I think our work is done here - your PC should be clean now.

 

 

First, navigate to and delete the following folder (SmitfraudFix is outdated already anyway):

c:\documents and settings\dave\desktop\unused\smitfraudfix

 

Then you may want to go to Norton Anti-Virus and clear your quarantine out.

 

=====================

 

Finally it's time to remove ComboFix.

 

Go to to Start > Run

Type in box

 

combofix /u

 

Note: the space between the X and the /u

 

Press Enter.

 

This command will:

 

Delete the following:

ComboFix and its associated files and folders.

VundoFix backups, if present

The C:\Deckard folder, if present

The C:_OtMoveIt folder, if present

 

Reset the clock settings.

Hide file extensions, if required.

Hide System/Hidden files, if required.

Reset System Restore.

Edited by chiaz

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...