Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
LinkBack Thread Tools
Old 04-20-2009, 07:22 PM   #1 (permalink)
Registered User
 
Join Date: Apr 2009
Posts: 4
OS: vista home basic


trojan infection

I started getting the 'An Unauthorized change was made to your license' error message some time ago but I ran a System Restore and it worked fine. Couple of days ago I had a trojan alert from windows defender. It was 'antivirus pro 2009' virus and I read some forums, downloaded Malwarebutes' Anti-Malware and it seemed to have fixed it. However, after I rebooted the system I got the 'An unauthorized...' message again which seemed really strange to me. When I run Malwarebytes it shows me Trojan.Zlob.H, Trojan.Agent, Trojan.Downloader, Hijack.Regedit, Hijack.FolderOptions. Also I was getting errors for the automatic windows update which I was just about to search how to fix before all this happened. I have little knowledge on how to fix this, I pre-installed vista about 2 months ago after having some issues and I have know idea how to fix it now.

Any help will be appreciated.



DDS (Ver_09-03-16.01) - NTFSx86 NETWORK
Run by Krum Dukin at 20:47:23.75 on Mon 04/20/2009
Internet Explorer: 7.0.6000.16809
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.1022.527 [GMT -4:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\KRUMDU~1\AppData\Local\Temp\417347228.exe
C:\Users\Krum Dukin\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: c:\windows\system32\zfgh83jg3.dll: {d5bf49a0-94f3-42bd-f434-3604812c8955} - c:\windows\system32\zfgh83jg3.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Diagnostic Manager] c:\users\krumdu~1\appdata\local\temp\417347228.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [Radio-TV adverts] c:\windows\temp\rtv_winupd.exe
mRun: [svchost.exe] "c:\windows\system32\3361\SVCHOST.exe"
mRunOnce: [svchost.exe] "c:\windows\system32\3361\SVCHOST.exe"
dRun: [<NO NAME>] c:\windows\temp\f49egg.exe
dRun: [Windows Resurections] c:\windows\temp\f49egg.exe
dRun: [Diagnostic Manager] c:\windows\temp\2918519072.exe
StartupFolder: c:\users\krumdu~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\users\krumdu~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
STS: c:\windows\system32\zfgh83jg3.dll: {d5bf49a0-94f3-42bd-f434-3604812c8955} - c:\windows\system32\zfgh83jg3.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

============= SERVICES / DRIVERS ===============

R0 amacpi;Microsoft Away Mode System;c:\windows\system32\drivers\null.sys [2006-11-2 4608]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
S2 DhcpSrv;Dhcp server;c:\windows\dhcp\svchost.exe [2009-4-16 235008]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-4-16 38496]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S4 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-2-6 727720]

=============== Created Last 30 ================

2009-04-19 23:00 15,000 a------- c:\windows\system32\zfgh83jg3.dll
2009-04-16 22:26 <DIR> --d----- c:\users\krumdu~1\appdata\roaming\Malwarebytes
2009-04-16 22:26 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-16 22:26 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-16 22:26 <DIR> --d----- c:\programdata\Malwarebytes
2009-04-16 22:26 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-16 22:26 <DIR> --d----- c:\progra~2\Malwarebytes
2009-04-16 22:13 154,624 a------- c:\windows\onajegoz.dll
2009-04-16 22:07 874,496 a------- c:\windows\system32\kernel32_check.dll
2009-04-16 22:07 61,440 a------- c:\windows\system32\tcpd.exe
2009-04-16 22:07 18,944 a------- c:\windows\system32\AUTMGR.EXE
2009-04-16 22:07 172,032 a------- c:\windows\system32\tcpcon.dll
2009-04-16 22:07 10,240 a------- c:\windows\system32\Packer.dll
2009-04-16 22:07 9 a------- c:\windows\system32\riphy.dll
2009-04-16 22:07 9 a------- c:\windows\system32\iphy.dll
2009-04-16 22:07 3 a------- c:\windows\system32\fhpatch.dll
2009-04-16 22:06 1 a------- c:\windows\system32\uniq.tll
2009-04-16 22:06 <DIR> --d----- c:\windows\system32\3361
2009-04-16 22:06 108,336 a------- c:\windows\system32\MSWINSCK.OCX
2009-04-16 22:06 <DIR> --d----- c:\windows\dhcp
2009-04-06 16:22 <DIR> --d----- c:\programdata\Office Genuine Advantage
2009-04-06 16:18 <DIR> --d----- c:\programdata\Windows Genuine Advantage
2009-04-04 05:25 <DIR> --d----- c:\users\krumdu~1\appdata\roaming\ppstream
2009-04-01 10:35 <DIR> --d----- c:\program files\TVAnts
2009-04-01 10:32 <DIR> --d----- c:\program files\SopCast
2009-03-26 00:57 <DIR> --d----- c:\programdata\Adobe Systems
2009-03-26 00:47 <DIR> --d----- c:\program files\common files\Adobe Systems Shared
2009-03-26 00:42 <DIR> --d----- c:\program files\Technical Information
2009-03-26 00:42 <DIR> --d----- c:\program files\Help
2009-03-26 00:42 <DIR> --d----- c:\program files\Goodies
2009-03-26 00:42 <DIR> --d----- c:\program files\CRACK
2009-03-26 00:42 <DIR> --d----- c:\program files\AutoPlay
2009-03-26 00:41 245,408 a------- c:\program files\unicows.dll
2009-03-26 00:41 126,976 a------- c:\program files\epic_eula.dll
2009-03-26 00:41 <DIR> --d----- c:\program files\Adobe(R) Photoshop(R) CS2
2009-03-25 22:12 410,984 a------- c:\windows\system32\deploytk.dll

==================== Find3M ====================

2009-03-15 03:15 665,600 a------- c:\windows\inf\drvindex.dat
2009-03-15 03:15 51,200 a------- c:\windows\inf\infpub.dat
2009-03-15 03:15 86,016 a------- c:\windows\inf\infstrng.dat
2009-03-15 03:15 86,016 a------- c:\windows\inf\infstor.dat
2009-03-15 03:09 268,800 a------- c:\windows\system32\es.dll
2009-03-15 03:08 223,232 a------- c:\windows\system32\WMASF.DLL
2009-03-15 03:08 9,728 a------- c:\windows\system32\LAPRXY.DLL
2009-03-15 03:08 2,048 a------- c:\windows\system32\asferror.dll
2009-03-15 03:07 712,192 a------- c:\windows\system32\WindowsCodecs.dll
2009-03-15 03:07 425,472 a------- c:\windows\system32\PhotoMetadataHandler.dll
2009-03-15 03:07 347,136 a------- c:\windows\system32\WindowsCodecsExt.dll
2009-03-15 03:07 37,376 a------- c:\windows\system32\printcom.dll
2009-03-15 03:07 441,856 a------- c:\windows\system32\win32spl.dll
2009-03-15 03:06 113,664 a------- c:\windows\system32\drivers\rmcast.sys
2009-03-15 03:06 14,848 a------- c:\windows\system32\wshrm.dll
2009-03-15 03:05 290,304 a------- c:\windows\system32\drivers\srv.sys
2009-03-15 03:04 53,760 a------- c:\windows\system32\drivers\hdaudbus.sys
2009-03-15 03:04 269,824 a------- c:\windows\system32\schannel.dll
2009-03-14 04:14 174 a--sh--- c:\program files\desktop.ini
2009-03-14 04:02 61,440 a------- c:\windows\system32\winipsec.dll
2009-03-14 04:02 28,672 a------- c:\windows\system32\FwRemoteSvr.dll
2009-03-14 04:02 361,984 a------- c:\windows\system32\IPSECSVC.DLL
2009-03-14 04:02 272,896 a------- c:\windows\system32\polstore.dll
2009-03-14 04:00 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2009-03-14 04:00 160,768 a------- c:\windows\system32\PortableDeviceTypes.dll
2009-03-14 04:00 95,232 a------- c:\windows\system32\PortableDeviceClassExtension.dll
2009-03-14 03:59 205,824 a------- c:\windows\system32\msoeacct.dll
2009-03-14 03:59 87,040 a------- c:\windows\system32\msoert2.dll
2009-03-14 03:59 39,424 a------- c:\windows\system32\ACCTRES.dll
2009-03-14 03:58 721,408 a------- c:\windows\system32\PhotoScreensaver.scr
2009-03-14 03:58 24,064 a------- c:\windows\system32\wtsapi32.dll
2009-03-14 03:58 258,232 a------- c:\windows\system32\drivers\acpi.sys
2009-03-14 03:58 542,720 a------- c:\windows\system32\sysmain.dll
2009-03-14 03:58 290,816 a------- c:\windows\system32\wlanmsm.dll
2009-03-14 03:58 67,584 a------- c:\windows\system32\wlanhlp.dll
2009-03-14 03:58 47,104 a------- c:\windows\system32\wlanapi.dll
2009-03-14 03:58 502,784 a------- c:\windows\system32\wlansvc.dll
2009-03-14 03:58 297,984 a------- c:\windows\system32\wlansec.dll
2009-03-14 03:57 194,560 a------- c:\windows\system32\WebClnt.dll
2009-03-14 03:57 110,080 a------- c:\windows\system32\drivers\mrxdav.sys
2009-03-14 03:56 826,368 a------- c:\windows\system32\wininet.dll
2009-03-14 03:56 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-03-14 03:56 44,032 a------- c:\windows\system32\ieUnatt.exe
2009-03-14 03:56 56,320 a------- c:\windows\system32\iesetup.dll
2009-03-14 03:55 376,320 a------- c:\windows\system32\winsrv.dll
2009-03-14 03:55 49,664 a------- c:\windows\system32\csrsrv.dll
2009-03-14 03:51 297,472 a------- c:\windows\system32\gdi32.dll
2009-03-14 03:50 1,060,920 a------- c:\windows\system32\drivers\ntfs.sys
2009-03-14 03:50 41,984 a------- c:\windows\system32\drivers\monitor.sys
2009-03-14 03:50 211,456 a------- c:\windows\system32\drivers\mrxsmb10.sys
2009-03-14 03:49 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-03-14 03:49 2,560 a------- c:\windows\apppatch\AcRes.dll
2009-03-14 03:49 2,144,256 a------- c:\windows\apppatch\AcGenral.dll
2009-03-14 03:49 537,600 a------- c:\windows\apppatch\AcLayers.dll
2009-03-14 03:49 449,536 a------- c:\windows\apppatch\AcSpecfc.dll
2009-03-14 03:49 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-03-14 03:49 4,247,552 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-03-14 03:49 1,687,040 a------- c:\windows\system32\gameux.dll
2009-03-14 03:48 303,616 a------- c:\windows\system32\wmpeffects.dll
2009-03-14 03:47 1,194,496 a------- c:\windows\system32\msxml3.dll
2009-03-14 03:47 2,048 a------- c:\windows\system32\msxml3r.dll
2009-03-14 03:46 414,208 a------- c:\windows\system32\msscp.dll
2009-03-14 03:46 356,864 a------- c:\windows\system32\MediaMetadataHandler.dll
2009-03-14 03:45 392,192 a------- c:\windows\system32\FirewallAPI.dll
2009-03-14 03:45 396,800 a------- c:\windows\system32\MPSSVC.dll
2009-03-14 03:45 86,016 a------- c:\windows\system32\icfupgd.dll
2009-03-14 03:45 63,488 a------- c:\windows\system32\drivers\mpsdrv.sys
2009-03-14 03:45 61,952 a------- c:\windows\system32\cmifw.dll
2009-03-14 03:45 16,896 a------- c:\windows\system32\wfapigp.dll
2009-03-14 03:45 178,688 a------- c:\windows\system32\iphlpsvc.dll
2009-03-14 03:45 23,040 a------- c:\windows\system32\drivers\tunnel.sys
2009-03-14 03:45 15,360 a------- c:\windows\system32\drivers\TUNMP.SYS
2009-03-14 03:44 2,048 a------- c:\windows\system32\tzres.dll
2009-03-14 03:42 8,147,968 a------- c:\windows\system32\wmploc.DLL
2009-03-14 03:42 7,680 a------- c:\windows\system32\spwmp.dll
2009-03-14 03:42 4,096 a------- c:\windows\system32\dxmasf.dll
2009-03-14 03:38 45,112 a------- c:\windows\system32\drivers\pciidex.sys
2009-03-14 03:38 21,560 a------- c:\windows\system32\drivers\atapi.sys
2009-03-14 03:38 211,000 a------- c:\windows\system32\drivers\volsnap.sys
2009-03-14 03:38 109,624 a------- c:\windows\system32\drivers\ataport.sys
2009-03-14 03:38 15,928 a------- c:\windows\system32\drivers\pciide.sys
2009-03-14 03:38 154,624 a------- c:\windows\system32\drivers\nwifi.sys
2009-03-14 03:38 121,856 a------- c:\windows\system32\DWWIN.EXE
2009-03-14 03:37 2,923,520 a------- c:\windows\explorer.exe
2009-03-14 03:35 216,632 a------- c:\windows\system32\drivers\netio.sys
2009-03-14 03:35 167,424 a------- c:\windows\system32\tcpipcfg.dll
2009-03-14 03:35 41,472 a------- c:\windows\system32\netcfg.exe
2009-03-14 03:35 803,328 a------- c:\windows\system32\drivers\tcpip.sys
2009-03-14 03:35 39,424 a------- c:\windows\system32\netiougc.exe
2009-03-14 03:33 3,419,136 a------- c:\windows\system32\NlsLexicons004a.dll
2009-03-14 03:30 1,585,664 a------- c:\windows\system32\setupapi.dll
2009-03-14 03:17 96,760 a------- c:\windows\system32\dfshim.dll
2009-03-14 03:17 41,984 a------- c:\windows\system32\netfxperf.dll
2009-03-14 03:17 282,112 a------- c:\windows\system32\mscoree.dll
2009-03-14 03:17 158,720 a------- c:\windows\system32\mscorier.dll
2009-03-14 03:17 83,968 a------- c:\windows\system32\mscories.dll
2009-03-14 03:04 2,855,424 a------- c:\windows\system32\mf.dll
2009-03-14 03:04 98,816 a------- c:\windows\system32\mfps.dll
2009-03-14 03:04 70,144 a------- c:\windows\system32\rrinstaller.exe
2009-03-14 03:04:07 A------- 41,472 c:\windows\system32\mfpmp.exe
2007-02-21 15:49 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:48:26.67 ===============
Attached Files
File Type: zip attach.zip (16.5 KB, 3 views)
breakenter is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 04-22-2009, 07:41 PM   #2 (permalink)
Registered User
 
Join Date: Apr 2009
Posts: 4
OS: vista home basic


Re: trojan infection

bump
breakenter is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 04-22-2009, 11:47 PM   #3 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,928
OS: WinXP and Vista


Re: trojan infection

Hello breakenter,

Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/comb...o-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure how to do this, please see this link http://www.bleepingcomputer.com/forums/topic114351.html

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 04-23-2009, 09:32 AM   #4 (permalink)
Registered User
 
Join Date: Apr 2009
Posts: 4
OS: vista home basic


Re: trojan infection

Thank you for getting back Reid.

However, I downloaded ComboFix, closed the browser and all other programs but I get the same Error message every time:

==================================================
!!Alert!! It is NOT SAFE to continue!
The contents of the ComboFix package has been compromised.
Please download a fresh copy from:
h**p://w.w.w.bleepingcomputer.com/combofix/how-to-use-combofix

Note: You may be infected with a file patching virus (Virut)
==================================================

Then it automatically deletes combofix from my desktop. I downloaded it from all the sources but I get the same message. What do I do now?

Last edited by breakenter; 04-23-2009 at 09:34 AM.
breakenter is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 04-23-2009, 01:31 PM   #5 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,928
OS: WinXP and Vista


Re: trojan infection

Sadly, it means just what it says. Virut is a polymorphic file infector which infects the executable files (.exe) including critical Windows files, and screensaver files (.scr) corrupting them beyond repair in most cases. I'm sorry to have to inform you that the only trustworthy solution for Virut is to format.

Do not back up anything other than Documents or other non-executable files (no .scr files or zip/cab/rar files which contain executables), and burn those to CD/DVD, not to USB drive or another machine, as those then become suspect or infected.

There is also a recent variant of Virut which also infects htm and html files.

See our colleague miekiemoes' blog for similar comments here
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 04-23-2009, 02:18 PM   #6 (permalink)
Registered User
 
Join Date: Apr 2009
Posts: 4
OS: vista home basic


Re: trojan infection

Thank you Ried, I will format everything and hope it is gone afterwards. I appreciate your help.
breakenter is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 04-23-2009, 02:53 PM   #7 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,928
OS: WinXP and Vista


Re: trojan infection

As long as you reformat and reinstall, you'll be fine. Do not do a repair install--that will still leave the infection onboard.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:49 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85