Problem sorted - please check!
Hi,
I took the advice of johnb35 and downloaded Combofix. It ran itself and after restarting the system all 'blocks' to the internet were gone. As I said in my last post the Trojan Horse on the system was blocking communication to the internet for all programs except Firefox.
I went to the second stage (install HiJackThis) but there was a problem on installation. How important is it to install that program? I mean, the problem seems to be fixed, should I still bother?
Anyway many thanks for your help and here is the log file for Combofix and below it the one from Malwarebytes.
Regards, D.
ComboFix 10-06-15.04 - Alan 16/06/2010 16:53:16.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2302.1155 [GMT 1:00]
Running from: c:\users\Alan\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-05-16 to 2010-06-16 )))))))))))))))))))))))))))))))
.
2010-06-16 15:58 . 2010-06-16 15:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-02 20:08 . 2010-06-02 20:08 -------- d-----w- c:\users\Alan\AppData\Roaming\Malwarebytes
2010-06-02 20:08 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-02 20:08 . 2010-06-02 20:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-02 20:08 . 2010-06-02 20:08 -------- d-----w- c:\programdata\Malwarebytes
2010-06-02 20:08 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-02 18:56 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-06-01 22:53 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-06-01 22:53 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-05-27 19:40 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-27 19:40 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-16 15:45 . 2010-01-31 22:04 -------- d-----w- c:\users\Alan\AppData\Roaming\LimeWire
2010-06-16 15:45 . 2008-03-31 19:54 -------- d-----w- c:\program files\Steam
2010-06-16 15:44 . 2008-03-31 19:43 -------- d-----w- c:\programdata\NVIDIA
2010-06-10 18:50 . 2008-03-31 19:54 -------- d-----w- c:\program files\Common Files\Steam
2010-06-10 18:50 . 2009-12-31 15:13 34800 ----a-w- c:\programdata\nvModes.dat
2010-06-05 13:20 . 2009-12-11 19:05 -------- d-----w- c:\program files\Electronic Arts
2010-06-05 13:19 . 2008-03-31 19:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-02 20:08 . 2010-03-12 10:20 -------- d-----w- c:\users\Alan\AppData\Roaming\Azureus
2010-06-01 21:22 . 2010-03-12 10:19 -------- d-----w- c:\program files\Vuze
2010-06-01 20:20 . 2010-04-23 16:35 -------- d-----w- c:\programdata\Norton
2010-05-27 20:10 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-27 19:38 . 2010-03-18 19:10 -------- d-----w- c:\program files\Google
2010-05-21 13:14 . 2009-12-11 18:51 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-04-23 16:35 . 2010-04-23 16:35 -------- d-----w- c:\programdata\Symantec
2010-04-23 16:35 . 2010-04-23 16:35 -------- d-----w- c:\programdata\NortonInstaller
2010-03-24 23:48 . 2010-03-24 23:48 10686001 ----a-w- c:\users\Alan\AppData\Roaming\Azureus\plugins\azump\mplayer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Steam"="c:\program files\steam\steam.exe" [2010-05-11 1238352]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="c:\users\Alan\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-18 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-08-17 184864]
"Zboard"="c:\program files\Ideazon\ZEngine\Zboard.exe" [2009-06-04 57344]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"CTHelper"="CTHELPER.EXE" [2007-03-05 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-03-05 19968]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
c:\users\Alan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-11 13:57 1238352 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d9,2a,12,5c,35,8a,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3635180043-1872571312-1943345751-1000]
"EnableNotificationsRef"=dword:00000002
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
R3 cpuz130;cpuz130;c:\users\Alan\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-18 19:10]
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-18 19:10]
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3635180043-1872571312-1943345751-1000Core.job
- c:\users\Alan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-02 19:10]
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3635180043-1872571312-1943345751-1000UA.job
- c:\users\Alan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-02 19:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=14959&l=dis
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5555
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath - c:\users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\qu3x7cuf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q=
FF - component: c:\users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\qu3x7cuf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\qu3x7cuf.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\users\Alan\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-Launch LCDMon - c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
MSConfigStartUp-Launch LGDCore - c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
MSConfigStartUp-trlmhhbl - c:\users\Alan\AppData\Local\hxcgtpeue\sfiygbatssd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-16 16:58
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3635180043-1872571312-1943345751-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f9,87,be,f0,04,ae,fa,6e,da,1e,b3,e6,c4,6b,5c,92,f6,88,6f,f1,d0,d9,13,
40,4f,21,de,cb,3f,97,8f,6c,4b,d7,93,73,1e,86,f8,d4,b4,a9,c9,f8,c8,f1,dd,85,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
[HKEY_USERS\S-1-5-21-3635180043-1872571312-1943345751-1000\Software\SecuROM\License information*]
"datasecu"=hex:04,09,29,44,0b,13,c2,bb,09,10,63,ea,24,75,bf,00,a0,08,5f,ef,81,
9f,d0,0d,da,5c,04,09,9d,e5,94,81,44,8f,9f,fc,0e,2f,c4,7f,47,88,fc,97,ea,6d,\
"rkeysecu"=hex:da,f5,9f,db,eb,23,38,f3,43,80,31,14,f5,63,d7,6c
.
Completion time: 2010-06-16 16:59:56
ComboFix-quarantined-files.txt 2010-06-16 15:59
Pre-Run: 32,244,572,160 bytes free
Post-Run: 32,307,822,592 bytes free
- - End Of File - - B3AB23B7CD5712797F26B5348BCBCB2A
----------------------------------------------------------------
Malwarebytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4165
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
02/06/2010 21:47:21
mbam-log-2010-06-02 (21-47-21).txt
Scan type: Quick scan
Objects scanned: 119798
Time elapsed: 3 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)