![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
win32.zafi.b
hi, every time i start up my computer a windows firewall dialog box comes up and says i have a zafi.b worm trojan. it then has 3 boxes to click on but 2 are grayed out. (keep blocking, and unblock). so i can only click on enable protection. but it never fixes it. any help would be appreciated :) thanks.
DDS (Ver_09-02-01.01) - NTFSx86 Run by joe at 10:55:13.60 on Mon 23/02/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.238 [GMT 10:00] AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Outdated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\igfxtray.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Documents and Settings\joe\Application Data\Google\yfijv17721328.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe "C:\WINDOWS\system32\drivers\svchost.exe" C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\joe\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: solution Class: {99c6d1bb-7555-474c-91da-d8fb62a9cc75} - c:\windows\system32\75FYe5c0.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 6\PCSuite.exe" -onlytray uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PCSync2.exe" /NoDialog uRun: [SVCHOST.EXE] c:\windows\system32\drivers\svchost.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [AASecuUFD] mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [wclock] "c:\documents and settings\joe\application data\google\yfijv17721328.exe" 2 mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1184375899280 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab TCP: {DBA60028-DA75-46CA-A3EB-D8BFBB242833} = 203.12.160.35,203.12.160.36 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Notification Packages = scecli ================= FIREFOX =================== FF - ProfilePath - ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2009-1-18 11840] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2009-1-18 68865] R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2009-1-18 151297] R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2009-1-18 52032] =============== Created Last 30 ================ ==================== Find3M ==================== 2009-01-13 08:08 49,152 a------- c:\windows\system32\drivers\svchost.exe ============= FINISH: 10:55:35.59 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Hello and welcome to TSF
You may wish to subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. ------------------------------------- I see you have P2P software (LimeWire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. References for the risk of these programs are here, here and here. I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. --------------------------- When was the last time you updated Avast? According to your log it is outdated. Update the definitions and then run a full system scan. --------------------------- We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool: http://www.bleepingcomputer.com/comb...o-use-combofix * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. See this link for instructions on how to do this: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs Please include the C:\ComboFix.txt in your next reply for further review.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#3 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
Re: win32.zafi.b
thank you clark76. sorry i havent replied i am away for a week and wont be able to access my computer until i get back. believe me i want to get this fixed as soon as possible lol! i will do as you suggested as soon as i get back and then post a reply asap. thanks for your help. :)
|
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Thanks for letting me know. I was just about to close this thread
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
Re: win32.zafi.b
thanks clark76, got it done :) here it is...
ComboFix 09-03-02.01 - joe 2009-03-03 20:25:01.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.254 [GMT 10:00] Running from: c:\documents and settings\joe\Desktop\ComboFix.exe AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\joe\Application Data\Google\mjkspc.dll c:\windows\system32\drivers\svchost.exe c:\windows\system32\fFXhv6uO.exe.a_a c:\windows\system32\UTSCSI.EXE c:\windows\system32\XRfy6B8B.exe.a_a . ((((((((((((((((((((((((( Files Created from 2009-02-03 to 2009-03-03 ))))))))))))))))))))))))))))))) . 2009-02-23 10:56 . 2009-02-23 10:56 250 --a------ c:\windows\gmer.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-18 00:40 --------- d-----w c:\program files\Avira 2009-01-18 00:40 --------- d-----w c:\documents and settings\All Users\Application Data\Avira . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-06 68856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "wclock"="c:\documents and settings\joe\Application Data\Google\yfijv17721328.exe" [2009-01-13 126976] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\system32\\drivers\\svchost.exe"= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acde1602-642e-11dc-91bf-00105a75b247}] \Shell\AutoRun\command - E:\USBNB.exe . Contents of the 'Scheduled Tasks' folder 2008-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] 2009-02-07 c:\windows\Tasks\At1.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At10.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At11.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-23 c:\windows\Tasks\At12.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At13.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At14.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At15.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At16.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At17.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At18.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At19.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At2.job - c:\windows\system32\fFXhv6uO.exe [] 2009-03-03 c:\windows\Tasks\At20.job - c:\windows\system32\fFXhv6uO.exe [] 2009-03-03 c:\windows\Tasks\At21.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At22.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At23.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At24.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At25.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At26.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At27.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At28.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At29.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At3.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At30.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At31.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At32.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At33.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At34.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At35.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-23 c:\windows\Tasks\At36.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At37.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At38.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At39.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At4.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-08 c:\windows\Tasks\At40.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At41.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-08 c:\windows\Tasks\At42.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At43.job - c:\windows\system32\XRfy6B8B.exe [] 2009-03-03 c:\windows\Tasks\At44.job - c:\windows\system32\XRfy6B8B.exe [] 2009-03-03 c:\windows\Tasks\At45.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At46.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At47.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At48.job - c:\windows\system32\XRfy6B8B.exe [] 2009-02-07 c:\windows\Tasks\At5.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At6.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At7.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At8.job - c:\windows\system32\fFXhv6uO.exe [] 2009-02-07 c:\windows\Tasks\At9.job - c:\windows\system32\fFXhv6uO.exe [] . - - - - ORPHANS REMOVED - - - - HKLM-Run-AASecuUFD - (no file) . ------- Supplementary Scan ------- . uStart Page = about:blank uInternet Settings,ProxyOverride = *.local TCP: {DBA60028-DA75-46CA-A3EB-D8BFBB242833} = 203.12.160.35,203.12.160.36 FF - ProfilePath - . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-03 20:28:43 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . c:\program files\Lavasoft\Ad-Aware\aawservice.exe c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\iPod\bin\iPodService.exe c:\program files\PC Connectivity Solution\ServiceLayer.exe c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe c:\program files\Common Files\Nokia\MPAPI\MPAPI3s.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-03-03 20:32:32 - machine was rebooted ComboFix-quarantined-files.txt 2009-03-03 10:32:24 Pre-Run: 13,597,732,864 bytes free Post-Run: 14,374,096,896 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn 210 --- E O F --- 2008-12-18 12:55:43 |
|
|
|
|
#7 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Hello
Please submit the following file to Jotti File Scan c:\documents and settings\joe\Application Data\Google\yfijv17721328.exe At the top of the window you should see "File to Upload & Scan" and a blank box. Copy and paste the red text from above into the box. Then click "submit". When it is finished, please copy and paste the information listed under "Service" and "Scanner Results" back in this thread. If the site is too busy, upload it here http://www.virustotal.com/en/indexf.html -------------------------- 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the codebox below into it: Code:
AtJob:: Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\drivers\\svchost.exe"=- ![]() Refering to the picture above, drag CFScript into ComboFix.exe Then post the resultant log Note: Do not mouseclick combofix's window while it's running. That may cause it to stall ------------------------------------- Establish an internet connection & perform an online scan with Firefox or Internet Explorer at Kaspersky Online Scanner **Note** To optimize scanning time and produce a more sensible report for review:
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. ---------------------------------- Please provide the following logs with your next post: Jotti results C:\ComboFix.txt Kaspersky Report Also include an update on how your system is running
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
Re: win32.zafi.b
hi again. sorry it has taken a while to reply.
i wasnt sure whether you wanted me to copy and paste or to attach results as a file so i have just copied and pasted the logs. hope thats alright. the online virus scan didnt work properly and i had to dash off to work before trying it again. so here are the other 2 logs.. Service load: 0% 100% File: yfijv17721328.exe Status: INFECTED/MALWARE MD5: 785a8bcb8f49fb12ee9e9a3fefbf10f4 Packers detected: - Scanner results Scan taken on 10 Mar 2009 08:18:39 (GMT) A-Squared Found Trojan-Downloader.Win32.FraudLoad!IK AntiVir Found TR/Fakealert.AQE.10 ArcaVir Found nothing Avast Found Win32:Trojan-gen {Other} AVG Antivirus Found nothing BitDefender Found Trojan.FakeAlert.AQE ClamAV Found Trojan.Delf-7615 CPsecure Found Troj.W32.Delf.va Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Downloader.Win32.FraudLoad.cyq Ikarus Found Trojan-Downloader.Win32.FraudLoad Kaspersky Anti-Virus Found Trojan-Downloader.Win32.FraudLoad.cyq NOD32 Found nothing Norman Virus Control Found W32/Renos.CKY Panda Antivirus Found Generic Quick Heal Found TrojanDownloader.FraudLoad.cy Sophos Antivirus Found Troj/FakeAle-LB VirusBuster Found Trojan.DL.FraudLoad.CIG VBA32 Found nothing ComboFix 09-03-02.01 - joe 2009-03-10 18:28:59.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.243 [GMT 10:00] Running from: c:\documents and settings\joe\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\joe\Desktop\CFScript.txt AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) * Created a new restore point . - REDUCED FUNCTIONALITY MODE - . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Tasks\At1.job c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At2.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At27.job c:\windows\Tasks\At28.job c:\windows\Tasks\At29.job c:\windows\Tasks\At3.job c:\windows\Tasks\At30.job c:\windows\Tasks\At31.job c:\windows\Tasks\At32.job c:\windows\Tasks\At33.job c:\windows\Tasks\At34.job c:\windows\Tasks\At35.job c:\windows\Tasks\At36.job c:\windows\Tasks\At37.job c:\windows\Tasks\At38.job c:\windows\Tasks\At39.job c:\windows\Tasks\At4.job c:\windows\Tasks\At40.job c:\windows\Tasks\At41.job c:\windows\Tasks\At42.job c:\windows\Tasks\At43.job c:\windows\Tasks\At44.job c:\windows\Tasks\At45.job c:\windows\Tasks\At46.job c:\windows\Tasks\At47.job c:\windows\Tasks\At48.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job . ((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 ))))))))))))))))))))))))))))))) . 2009-02-23 10:56 . 2009-02-23 10:56 250 --a------ c:\windows\gmer.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-18 00:40 --------- d-----w c:\program files\Avira 2009-01-18 00:40 --------- d-----w c:\documents and settings\All Users\Application Data\Avira . ((((((((((((((((((((((((((((( SnapShot@2009-03-03_20.31.37.60 ))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-06 68856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "wclock"="c:\documents and settings\joe\Application Data\Google\yfijv17721328.exe" [2009-01-13 126976] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acde1602-642e-11dc-91bf-00105a75b247}] \Shell\AutoRun\command - E:\USBNB.exe . Contents of the 'Scheduled Tasks' folder 2008-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] . . ------- Supplementary Scan ------- . uStart Page = about:blank uInternet Settings,ProxyOverride = *.local TCP: {DBA60028-DA75-46CA-A3EB-D8BFBB242833} = 203.12.160.35,203.12.160.36 FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\kjqabufk.default\ FF - prefs.js: browser.startup.homepage - www.gmail.com FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-10 18:29:49 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-03-10 18:31:46 ComboFix-quarantined-files.txt 2009-03-10 08:31:29 ComboFix2.txt 2009-03-03 10:32:34 Pre-Run: 14,320,349,184 bytes free Post-Run: 14,309,638,144 bytes free 140 --- E O F --- 2008-12-18 12:55:43 |
|
|
|
|
#9 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Hello again,
Avira is outdated. You need to keep your antivirus updated since the antivirus companies are constantly updated definitions. --------------- Delete your current copy of ComboFix.exe from the desktop. Then download a fresh copy from one of these locations: Link 1 Link 2 Link 3 Do not run it yet, we will use it in a bit. ----------------- 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the codebox below into it: Code:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/349067-win32-zafi-b.html#post2015391 Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "wclock"=- Collect:: c:\documents and settings\joe\Application Data\Google\yfijv17721328.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe Then post the resultant log Note: Do not mouseclick combofix's window while it's running. That may cause it to stall **Note** When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
--------------------- Go here to run an online scannner from ESET.
----------------------- Please provide the following logs with your next post: C:\ComboFix.txt C:\Program Files\EsetOnlineScanner\log.txt Also include an update on how your system is running
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#10 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Still with me, shorn?
I generally unsubscribe from threads after 7 days of inactivity. If I don't receive a reply from you within 3 days of this post, this topic will be closed.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
Re: win32.zafi.b
hi, yes im still with you, sorry for not replying sooner. thank you for all your help.
with avira i realise it is still outdated and will get onto that in a minute. in regards to the internet scan, i tried it about 10 times but was unable to start it. your instructions:- * Tick the box next to YES, I accept the Terms of Use. * Click Start * When asked, allow the activex control to install * Click Start i go to the 'allow activex to install' and then another box came up that said, " the publisher could not be verified. are you sure you want to install this software? name: onlinescanner.cab publisher: unknown publisher each time i pressed install, but nothing happened. i went to help on the sidebar of the website and noticed that in their example, the warning is supposed to have a publisher called ESET, spol. s r.o. so im not sure what the go is there. here is my combofix log as requested.: ComboFix 09-03-13.02 - joe 2009-03-15 16:05:20.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.278 [GMT 10:00] Running from: c:\documents and settings\joe\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\joe\Desktop\CFScript.txt AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\joe\Application Data\Google\mjkspc.dll . ((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 ))))))))))))))))))))))))))))))) . 2009-03-10 19:14 . 2009-03-10 19:14 118 --a------ c:\windows\system32\MRT.INI 2009-02-23 10:56 . 2009-02-23 10:56 250 --a------ c:\windows\gmer.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-18 00:40 --------- d-----w c:\program files\Avira 2009-01-18 00:40 --------- d-----w c:\documents and settings\All Users\Application Data\Avira 2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll . ((((((((((((((((((((((((((((( SnapShot@2009-03-03_20.31.37.60 ))))))))))))))))))))))))))))))))))))))))) . + 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll + 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll + 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll + 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll + 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll + 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe + 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll + 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll + 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll + 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll + 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll + 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll + 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll + 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll + 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe + 2008-10-15 07 26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll + 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll + 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll + 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll + 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll + 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll + 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll + 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll + 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll + 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe + 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll + 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll + 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll + 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll + 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll - 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll + 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll - 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll + 2008-12-20 23:15:11 124,928 -c----w c:\windows\system32\dllcache\advpack.dll - 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll + 2008-12-20 23:15:12 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll - 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll + 2008-12-20 23:15:13 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll - 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll + 2008-12-20 23:15:13 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll - 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll + 2008-12-20 23:15:13 63,488 -c----w c:\windows\system32\dllcache\icardie.dll - 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe + 2008-12-19 09:10:15 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe - 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll + 2008-12-20 23:15:14 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll - 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll + 2008-12-20 23:15:14 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll - 2008-10-15 07:04:53 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll + 2008-12-19 05:23:56 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll - 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll + 2008-12-20 23:15:15 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll - 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll + 2008-12-20 23:15:16 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll + 2008-12-20 23:15:21 6,066,688 -c----w c:\windows\system32\dllcache\ieframe.dll - 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll + 2008-12-20 23:15:21 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll - 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll + 2008-12-20 23:15:22 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll - 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe + 2008-12-19 09:10:15 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe - 2008-10-15 07 26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe+ 2008-12-19 05:25:25 634,024 -c----w c:\windows\system32\dllcache\iexplore.exe - 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll + 2008-12-20 23:15:23 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll - 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll + 2008-12-20 23:15:23 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll - 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll + 2009-01-16 11:35:14 3,594,752 -c----w c:\windows\system32\dllcache\mshtml.dll - 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll + 2008-12-20 23:15:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll - 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll + 2008-12-20 23:15:31 193,024 -c----w c:\windows\system32\dllcache\msrating.dll - 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll + 2008-12-20 23:15:32 671,232 -c----w c:\windows\system32\dllcache\mstime.dll - 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll + 2008-12-20 23:15:38 102,912 -c----w c:\windows\system32\dllcache\occache.dll - 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll + 2008-12-20 23:15:38 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll - 2008-08-28 10:04:17 333,056 -c--a-w c:\windows\system32\dllcache\srv.sys + 2008-12-11 11:57:21 333,184 -c--a-w c:\windows\system32\dllcache\srv.sys - 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll + 2008-12-20 23:15:39 105,984 -c----w c:\windows\system32\dllcache\url.dll - 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll + 2008-12-20 23:15:40 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll - 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll + 2008-12-20 23:15:40 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll - 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll + 2008-12-20 23:15:41 826,368 -c----w c:\windows\system32\dllcache\wininet.dll - 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\drivers\srv.sys + 2008-12-11 11:57:21 333,184 ----a-w c:\windows\system32\drivers\srv.sys - 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll + 2008-12-20 23:15:12 347,136 ----a-w c:\windows\system32\dxtmsft.dll - 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll + 2008-12-20 23:15:13 214,528 ----a-w c:\windows\system32\dxtrans.dll - 2008-10-16 20:38:35 133,120 ----a-w c:\windows\system32\extmgr.dll + 2008-12-20 23:15:13 133,120 ----a-w c:\windows\system32\extmgr.dll - 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll + 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll - 2008-10-16 13:11:09 70,656 ----a-w c:\windows\system32\ie4uinit.exe + 2008-12-19 09:10:15 70,656 ----a-w c:\windows\system32\ie4uinit.exe - 2008-10-16 20:38:35 153,088 ----a-w c:\windows\system32\ieakeng.dll + 2008-12-20 23:15:14 153,088 ----a-w c:\windows\system32\ieakeng.dll - 2008-10-16 20:38:35 230,400 ----a-w c:\windows\system32\ieaksie.dll + 2008-12-20 23:15:14 230,400 ----a-w c:\windows\system32\ieaksie.dll - 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll + 2008-12-19 05:23:56 161,792 ----a-w c:\windows\system32\ieakui.dll - 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll + 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll - 2008-10-16 20:38:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll + 2008-12-20 23:15:16 384,512 ----a-w c:\windows\system32\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll + 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll - 2008-10-16 20:38:37 44,544 ----a-w c:\windows\system32\iernonce.dll + 2008-12-20 23:15:21 44,544 ----a-w c:\windows\system32\iernonce.dll - 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll + 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll - 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe + 2008-12-19 09:10:15 13,824 ----a-w c:\windows\system32\ieudinit.exe - 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll + 2008-12-20 23:15:23 27,648 ----a-w c:\windows\system32\jsproxy.dll - 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\system32\MRT.exe + 2009-02-11 10:56:18 21,244,872 ----a-w c:\windows\system32\MRT.exe - 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll + 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll - 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll + 2009-01-16 11:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll - 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll + 2008-12-20 23:15:30 477,696 ----a-w c:\windows\system32\mshtmled.dll - 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll + 2008-12-20 23:15:31 193,024 ----a-w c:\windows\system32\msrating.dll - 2008-10-16 20:38:39 671,232 ----a-w c:\windows\system32\mstime.dll + 2008-12-20 23:15:32 671,232 ----a-w c:\windows\system32\mstime.dll - 2008-10-16 20:38:39 102,912 ----a-w c:\windows\system32\occache.dll + 2008-12-20 23:15:38 102,912 ----a-w c:\windows\system32\occache.dll - 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll + 2008-12-20 23:15:38 44,544 ----a-w c:\windows\system32\pngfilt.dll - 2007-07-26 23:41:40 16,760 ------w c:\windows\system32\spmsg.dll + 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll - 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll + 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll - 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll + 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll - 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll + 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-06 68856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 1232896] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acde1602-642e-11dc-91bf-00105a75b247}] \Shell\AutoRun\command - E:\USBNB.exe . Contents of the 'Scheduled Tasks' folder 2008-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] . . ------- Supplementary Scan ------- . uStart Page = about:blank uInternet Settings,ProxyOverride = *.local TCP: {DBA60028-DA75-46CA-A3EB-D8BFBB242833} = 203.12.160.35,203.12.160.36 FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\kjqabufk.default\ FF - prefs.js: browser.startup.homepage - www.gmail.com FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-15 16:07:24 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-03-15 16:09:25 ComboFix-quarantined-files.txt 2009-03-15 06:09:06 ComboFix2.txt 2009-03-10 08:31:48 ComboFix3.txt 2009-03-03 10:32:34 Pre-Run: 14,139,867,136 bytes free Post-Run: 14,172,909,568 bytes free 246 --- E O F --- 2009-03-10 09:14:55 |
|
|
|
|
#12 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Hmmm... Not sure why the online scans are not working for you. That seems to happen on occasion but not necessarily mean it is malware related. Lets try a different scanner to make sure there are not any last bits that need cleaning.
Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Please also let me know how your system is running.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Nov 2006
Posts: 30
OS: xp
|
Re: win32.zafi.b
thanks clark :)
system update: at the moment its looking good so far. the warnings dont come up anymore, so thats a good thing. things seem to be working well although i havent used the computer much while we have been working on this. below is the report- Malwarebytes' Anti-Malware 1.34 Database version: 1861 Windows 5.1.2600 Service Pack 3 18/03/2009 8:10:34 PM mbam-log-2009-03-18 (20-10-34).txt Scan type: Quick Scan Objects scanned: 58938 Time elapsed: 4 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\solution.solution (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\solution.solution.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{892b2785-b0d0-4aa2-ae6a-0ed60b00a979} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{00476c87-a276-49bf-86bc-ff005732430b} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{e81cf86b-f683-422a-b742-3f2427ea9d6a} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
|
#14 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Well done, your logs are clean!
Go to -> Run -> copy/paste in the following single line command & click OKcombofix /u This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points. ------------------------ Now that your system is clean, to help protect your computer in the future I recommend that you follow these steps and look into the following free programs:
Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer Here are some additional utilities that will further enhance your safety.
In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
|
|
#16 (permalink) |
|
Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: Cleveland, Ohio
Posts: 1,696
OS: XP Pro, Vista, Ubuntu 8.10
|
Re: win32.zafi.b
Glad I could help
![]() Happy and safe surfing.
__________________
![]() Proud Member of ASAP Proud Member of UNITE If you feel we've helped you, Please Donate to the Forum |
|
|
| Thread Tools | |
|
|