WiredWX Hobby Weather ToolsLog in

 


Spyware.ISpyNow Virus

3 posters

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Yeah.. I found it. How should I proceed?

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
You may want to open this on your Husbands laptop to read from while doing it, it will be easier than me posting here and easier for you to understand.

http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/doug92.mspx

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Ok, my computer mysteriously decided to boot up. I ran ComboFix and here are my results.

ComboFix 08-11-18.03 - Crystal Jones 2008-12-02 21:04:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1692 [GMT -5:00]
Running from: c:\documents and settings\Crystal Jones\Desktop\-Combo-Fix-.exe
Command switches used :: c:\documents and settings\Crystal Jones\Desktop\CFscript.txt
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
c:\windows\system32\drivers\TDSSxxou.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\TDSSacun.dll
c:\windows\system32\TDSSirxy.dll
c:\windows\system32\TDSSktpa.dll
c:\windows\system32\TDSSqqcn.dll
c:\windows\system32\TDSSwghd.log
c:\windows\system32\TDSSwupe.dat
c:\windows\system32\TDSSyavu.dll

.
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.

2008-12-09 21:47 . 2008-09-07 13:13 1,100 --a------ c:\windows\system32\d3d8caps.dat
2008-12-09 20:49 . 2002-03-05 09:24 36,864 -ra------ c:\windows\system32\deluidrv.exe
2008-12-09 20:49 . 2002-03-05 09:24 32,768 -ra------ c:\windows\system32\usbmonit.exe
2008-12-09 20:49 . 2002-03-05 09:24 32,768 -ra------ c:\windows\system32\delentry.exe
2008-12-09 20:49 . 2002-03-05 09:24 21,064 -ra------ c:\windows\system32\drivers\geneuide.sys
2008-12-05 14:39 . 2008-12-05 14:39 d-------- c:\documents and settings\Crystal Jones\Application Data\Skunk Studios
2008-12-05 12:55 . 2008-12-05 13:25 d-------- c:\documents and settings\Crystal Jones\Application Data\BFG_JanesRealty
2008-12-02 21:03 . 2008-12-02 21:04 d-------- C:\-Combo-Fix-
2008-12-02 18:33 . 2008-12-02 18:33 d-------- c:\documents and settings\Crystal Jones\Application Data\Go-Go Gourmet Chef of the Year
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\scripting
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\en
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\bits
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\l2schemas
2008-11-29 19:27 . 2008-11-29 19:27 d-------- c:\windows\ServicePackFiles
2008-11-29 19:21 . 2008-11-29 19:21 d-------- c:\windows\EHome
2008-11-29 19:14 . 2008-04-13 19:11 1,888,992 --------- c:\windows\system32\ati3duag.dll
2008-11-29 14:24 . 2008-11-29 14:24 d-------- c:\documents and settings\Crystal Jones\Application Data\SaveThePuppy
2008-11-25 18:37 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-23 20:34 . 2008-11-23 20:34 d-------- c:\program files\Sun
2008-11-18 19:46 . 2008-11-18 19:46 d-------- c:\documents and settings\Crystal Jones\Application Data\PetShowCraze
2008-11-17 21:12 . 2008-11-17 21:12 d-------- c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-16 20:51 . 2008-11-16 20:51 d-------- c:\documents and settings\Crystal Jones\Application Data\Pogo Games
2008-11-14 19:27 . 2008-11-14 19:27 d-------- c:\documents and settings\All Users\Application Data\Fugazo
2008-11-13 19:29 . 2008-11-13 19:29 d-------- c:\documents and settings\Crystal Jones\Application Data\FirstColony
2008-11-12 07:24 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 07:24 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 01:40 90,112 ----a-w c:\windows\DUMP3a88.tmp
2008-12-03 01:37 90,112 ----a-w c:\windows\DUMP3a98.tmp
2008-12-03 01:31 90,112 ----a-w c:\windows\DUMP3ac6.tmp
2008-12-03 01:26 90,112 ----a-w c:\windows\DUMP39ad.tmp
2008-12-03 01:04 --------- d-----w c:\program files\Lavasoft
2008-12-01 02:48 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-12-01 02:21 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 02:20 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\Wildfire
2008-11-30 23:24 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-11-30 02:21 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\PlayFirst
2008-11-24 02:04 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\JewelMatch2
2008-11-24 01:33 --------- d-----w c:\program files\Java
2008-11-23 00:35 --------- d-----w c:\program files\Sudoku - Latin Squares
2008-11-16 16:27 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\Apple Computer
2008-11-14 00:23 --------- d-----w c:\program files\bfgclient
2008-11-10 02:28 --------- d-----w c:\program files\Megaplex Madness - Now Playing
2008-11-10 02:26 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\funkitron
2008-10-31 02:14 --------- d-----w c:\program files\Carrie the Caregiver
2008-10-28 01:20 --------- d-----w c:\program files\Camp Funshine - Carrie the Caregiver 3
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 23:46 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\SecretIslandEng
2008-10-23 23:20 --------- d-----w c:\program files\The Treasures of Mystery Island
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-07 02:06 --------- d-----w c:\program files\Cooking Dash
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-09 02:05 17,144 ----a-w c:\documents and settings\Crystal Jones\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-12-02_19.44.28.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-03 00:42:42 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-03 01:02:32 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-03 00:42:42 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-03 01:02:32 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-03 00:05:51 41,144 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-03 02:03:11 41,144 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-03 00:05:51 313,664 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-03 02:03:11 313,664 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-17 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-17 8495104]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"nwiz"="nwiz.exe" [2007-11-17 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-11-17 c:\windows\system32\nvhotkey.dll]

c:\documents and settings\Crystal Jones\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-27 19:49 10792 c:\program files\Citrix\GoToAssist\480\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

S3 GoToAssist;GoToAssist;"c:\program files\Citrix\GoToAssist\480\g2aservice.exe" Start=service [2008-05-27 16936]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd5f9c0-b2ac-11dd-bc93-001d09c52f34}]
\Shell\AutoRun\command - E:\WDSetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d7ea2a-5c17-11dd-bc27-001d09c52f34}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-08-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 21:04:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSxxou.sys"
.
Completion time: 2008-12-02 21:09:04
ComboFix-quarantined-files.txt 2008-12-03 02:09:01
ComboFix2.txt 2008-12-03 00:46:21

Pre-Run: 125,767,335,936 bytes free
Post-Run: 125,758,599,168 bytes free

160 --- E O F --- 2008-11-12 12:36:52

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Hello.
Can you connect to the top links of CF now?

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
What are the top links of CF?

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Should of been more specific.
Here:
http://www.geekpolice.net/Combofix-h7.htm

The BC and geekstogo mirrors.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
I am able to get to the links now.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Hooray! Hooray! Hooray!
Please download from one of those and re-scan, the old version was running in reduced mode.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Done. Here's the log.

ComboFix 08-12-01.03 - Crystal Jones 2008-12-02 21:23:53.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1678 [GMT -5:00]
Running from: c:\documents and settings\Crystal Jones\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Crystal Jones\Application Data\google\runhh6110411.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.

2008-12-09 21:47 . 2008-09-07 13:13 1,100 --a------ c:\windows\system32\d3d8caps.dat
2008-12-09 20:49 . 2002-03-05 09:24 36,864 -ra------ c:\windows\system32\deluidrv.exe
2008-12-09 20:49 . 2002-03-05 09:24 32,768 -ra------ c:\windows\system32\usbmonit.exe
2008-12-09 20:49 . 2002-03-05 09:24 32,768 -ra------ c:\windows\system32\delentry.exe
2008-12-09 20:49 . 2002-03-05 09:24 21,064 -ra------ c:\windows\system32\drivers\geneuide.sys
2008-12-05 14:39 . 2008-12-05 14:39 d-------- c:\documents and settings\Crystal Jones\Application Data\Skunk Studios
2008-12-05 12:55 . 2008-12-05 13:25 d-------- c:\documents and settings\Crystal Jones\Application Data\BFG_JanesRealty
2008-12-02 21:03 . 2008-12-02 21:09 d-------- C:\-Combo-Fix-
2008-12-02 18:33 . 2008-12-02 18:33 d-------- c:\documents and settings\Crystal Jones\Application Data\Go-Go Gourmet Chef of the Year
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\scripting
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\en
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\system32\bits
2008-11-29 19:28 . 2008-11-29 19:28 d-------- c:\windows\l2schemas
2008-11-29 19:27 . 2008-11-29 19:27 d-------- c:\windows\ServicePackFiles
2008-11-29 19:21 . 2008-11-29 19:21 d-------- c:\windows\EHome
2008-11-29 19:14 . 2008-04-13 19:11 1,888,992 --------- c:\windows\system32\ati3duag.dll
2008-11-29 14:24 . 2008-11-29 14:24 d-------- c:\documents and settings\Crystal Jones\Application Data\SaveThePuppy
2008-11-25 18:37 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-23 20:34 . 2008-11-23 20:34 d-------- c:\program files\Sun
2008-11-18 19:46 . 2008-11-18 19:46 d-------- c:\documents and settings\Crystal Jones\Application Data\PetShowCraze
2008-11-17 21:12 . 2008-11-17 21:12 d-------- c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-16 20:51 . 2008-11-16 20:51 d-------- c:\documents and settings\Crystal Jones\Application Data\Pogo Games
2008-11-14 19:27 . 2008-11-14 19:27 d-------- c:\documents and settings\All Users\Application Data\Fugazo
2008-11-13 19:29 . 2008-11-13 19:29 d-------- c:\documents and settings\Crystal Jones\Application Data\FirstColony
2008-11-12 07:24 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 07:24 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 01:40 90,112 ----a-w c:\windows\DUMP3a88.tmp
2008-12-03 01:37 90,112 ----a-w c:\windows\DUMP3a98.tmp
2008-12-03 01:31 90,112 ----a-w c:\windows\DUMP3ac6.tmp
2008-12-03 01:26 90,112 ----a-w c:\windows\DUMP39ad.tmp
2008-12-03 01:04 --------- d-----w c:\program files\Lavasoft
2008-12-01 02:21 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 02:20 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\Wildfire
2008-11-30 23:24 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-11-30 02:21 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\PlayFirst
2008-11-24 02:04 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\JewelMatch2
2008-11-24 01:33 --------- d-----w c:\program files\Java
2008-11-23 00:35 --------- d-----w c:\program files\Sudoku - Latin Squares
2008-11-16 16:27 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\Apple Computer
2008-11-14 00:23 --------- d-----w c:\program files\bfgclient
2008-11-10 02:28 --------- d-----w c:\program files\Megaplex Madness - Now Playing
2008-11-10 02:26 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\funkitron
2008-10-31 02:14 --------- d-----w c:\program files\Carrie the Caregiver
2008-10-28 01:20 --------- d-----w c:\program files\Camp Funshine - Carrie the Caregiver 3
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 23:46 --------- d-----w c:\documents and settings\Crystal Jones\Application Data\SecretIslandEng
2008-10-23 23:20 --------- d-----w c:\program files\The Treasures of Mystery Island
2008-10-07 02:06 --------- d-----w c:\program files\Cooking Dash
2008-08-09 02:05 17,144 ----a-w c:\documents and settings\Crystal Jones\Application Data\GDIPFONTCACHEV1.DAT
.

------- Sigcheck -------

2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtServicePackUninstall$\termsrv.dll
2008-04-13 19:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\ServicePackFiles\i386\termsrv.dll
2008-11-30 21:48 295424 63999d0abd8dabfd76a9c07f6e104868 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-02_19.44.28.62 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-12-03 00:42:42 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-03 01:02:32 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-03 00:42:42 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-03 01:02:32 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-03 00:05:51 41,144 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-03 02:03:11 41,144 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-03 00:05:51 313,664 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-03 02:03:11 313,664 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-17 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-17 8495104]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"nwiz"="nwiz.exe" [2007-11-17 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-11-17 c:\windows\system32\nvhotkey.dll]

c:\documents and settings\Crystal Jones\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-27 19:49 10792 c:\program files\Citrix\GoToAssist\480\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

S3 GoToAssist;GoToAssist;"c:\program files\Citrix\GoToAssist\480\g2aservice.exe" Start=service [2008-05-27 16936]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd5f9c0-b2ac-11dd-bc93-001d09c52f34}]
\Shell\AutoRun\command - E:\WDSetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d7ea2a-5c17-11dd-bc27-001d09c52f34}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-08-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 21:26:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(848)
c:\program files\Citrix\GoToAssist\480\G2AWinLogon.dll
c:\windows\System32\BCMLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-12-02 21:28:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-03 02:28:04
ComboFix2.txt 2008-12-03 02:09:05
ComboFix3.txt 2008-12-03 00:46:21

Pre-Run: 125,742,039,040 bytes free
Post-Run: 125,676,736,512 bytes free

163 --- E O F --- 2008-11-12 12:36:52

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Hello.
CF cleaned up what was left.
Log looks clean.

I'm sorry for the trouble the malware caused, you have had first taste of the horrible stuff this rootkit is capable of. Sad tearing

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Thank you very much for all of your help!! I greatly appreciate it! I don't know what I would have done without your help. Thank You!

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Hello.
Glad I could help. Smile...

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:

  • Download the latest version of Java SE Runtime Environment (JRE) 6 Update 11.
  • Select the first option where it says "Java SE Runtime Environment (JRE) 6 Update 11".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add or Remove Programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    - Java 2 Runtime Environment, SE v1.4.2
    - J2SE Runtime Environment 5.0
    - J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe that you downloaded to install the newest version.
Please make sure the new version of Java is installed before you run JavaRa.

Please download JavaRa from here

  • First, unzip it.
  • Then run JavaRa.
  • Select English from the drop down menu and press Select.
  • This will open JavaRa.
  • Press Remove older versions
  • Press yes to the prompt.
  • It will make a log file of what it's removed.
  • Copy and paste the log back here.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Tue Dec 02 22:14:41 2008

Found and removed: C:\Program Files\Java\jre1.6.0_06

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_06\

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. Big Grin

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

descriptionSolvedRe: Spyware.ISpyNow Virus

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum