Keep getting a message from Windows firewall saying I'm suffering from Trojan.Zlob.G and then it gives me a link to download some fake malware removal. Also when I try to open a web page i see "Insecure internet security. Threat of Virus Attack" I've read the posts and see that others are suffering from similar problems. I've noticed the virus name changes for some people though. Please help me
Here is my combofix log:
ComboFix 08-12-09.03 - stepahnie 2008-12-10 21:00:27.1 - NTFSx86
Microsoft Windows Vista Home Premium 6.0.6001.0.1252.1.1033.18.361 [GMT -5:00]
Running from: c:\users\stepahnie\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\stepahnie\AppData\Roaming\inst.exe
c:\windows\system32\MabryObj.dll
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-10 02:52 . 2008-06-22 20:59 2,868,736 --a--c--- c:\windows\System32\mf.dll
2008-12-10 02:52 . 2008-06-22 20:59 996,352 --a--c--- c:\windows\System32\WMNetMgr.dll
2008-12-10 02:52 . 2008-06-22 20:58 94,720 --a--c--- c:\windows\System32\logagent.exe
2008-12-10 02:37 . 2008-10-21 00:25 296,960 --a--c--- c:\windows\System32\gdi32.dll
2008-12-10 02:35 . 2008-10-29 01:29 2,927,104 --a--c--- c:\windows\explorer.exe
2008-12-10 01:39 . 2008-12-10 20:41 d----c--- c:\program files\Panda Security
2008-12-09 03:58 . 2008-12-09 03:58 d----c--- c:\program files\Common Files\Wise Installation Wizard
2008-12-08 20:05 . 2008-12-08 20:05 d----c--- c:\users\All Users\WindowsSearch
2008-12-08 20:05 . 2008-12-08 20:05 d----c--- c:\programdata\WindowsSearch
2008-12-08 19:29 . 2008-12-08 19:29 d--h-c--- c:\windows\PIF
2008-12-08 19:19 . 2008-12-08 19:19 109,744 --a--c--- c:\windows\System32\drivers\SYMEVENT.SYS
2008-12-08 19:19 . 2008-12-08 19:19 8,014 --a--c--- c:\windows\System32\drivers\SYMEVENT.CAT
2008-12-08 19:19 . 2008-12-08 19:19 805 --a--c--- c:\windows\System32\drivers\SYMEVENT.INF
2008-12-08 19:18 . 2008-12-08 19:18 d----c--- c:\program files\Symantec AntiVirus
2008-12-08 04:01 . 2008-12-08 04:01 d----c--- c:\users\stepahnie\AppData\Roaming\Malwarebytes
2008-12-08 04:01 . 2008-12-08 04:01 d----c--- c:\users\All Users\Malwarebytes
2008-12-08 04:01 . 2008-12-08 04:01 d----c--- c:\programdata\Malwarebytes
2008-12-08 04:01 . 2008-12-08 04:01 d----c--- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 04:01 . 2008-12-03 19:53 38,496 --a--c--- c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-08 04:01 . 2008-12-03 19:53 15,504 --a--c--- c:\windows\System32\drivers\mbam.sys
2008-12-08 02:43 . 2008-02-22 23:38 170,496 --a--c--- c:\windows\System32\tcpipcfg.dll
2008-12-08 02:43 . 2008-02-22 21:41 22,528 --a--c--- c:\windows\System32\netiougc.exe
2008-12-08 02:42 . 2008-12-08 02:42 d----c--- c:\program files\Zone Labs
2008-12-08 02:42 . 2008-08-21 20:41 1,221,008 --a--c--- c:\windows\System32\zpeng25.dll
2008-12-08 02:40 . 2008-12-08 02:42 d----c--- c:\windows\System32\ZoneLabs
2008-12-08 02:40 . 2008-12-10 19:05 348,371 --ah-c--- c:\windows\System32\drivers\vsconfig.xml
2008-12-08 02:40 . 2008-08-21 20:42 294,288 --a--c--- c:\windows\System32\drivers\vsdatant.sys
2008-12-07 16:19 . 2008-12-07 16:19 d----c--- c:\users\stepahnie\AppData\Roaming\Grisoft
2008-12-07 16:18 . 2008-12-07 16:18 d----c--- c:\users\All Users\Grisoft
2008-12-07 16:18 . 2008-12-07 16:18 d----c--- c:\programdata\Grisoft
2008-12-07 16:18 . 2007-05-30 07:10 10,872 --a--c--- c:\windows\System32\drivers\AvgAsCln.sys
2008-12-07 13:07 . 2008-05-27 00:18 350,208 --a--c--- c:\windows\System32\mssph.dll
2008-12-07 13:07 . 2008-05-27 00:18 203,776 --a--c--- c:\windows\System32\mssphtb.dll
2008-12-06 19:03 . 2008-12-06 19:03 d----c--- C:\PerfLogs
2008-12-06 17:49 . 2008-12-06 18:05 d----c--- c:\program files\Eusing Free Registry Cleaner
2008-12-04 19:16 . 2008-12-04 19:16 d----c--- c:\program files\CCleaner
2008-12-04 17:43 . 2008-12-08 17:57 d----c--- c:\program files\Alwil Software
2008-11-29 00:51 . 2008-11-29 00:51 d----c--- c:\program files\Common Files\Apple
2008-11-29 00:48 . 2008-11-29 00:48 d----c--- c:\users\All Users\Apple
2008-11-29 00:48 . 2008-11-29 00:48 d----c--- c:\programdata\Apple
2008-11-29 00:48 . 2008-11-29 00:48 d----c--- c:\program files\Apple Software Update
2008-11-28 14:50 . 2008-11-28 14:50 dr---c--- c:\windows\System32\config\systemprofile\Music
2008-11-26 19:23 . 2008-10-21 00:25 1,645,568 --a--c--- c:\windows\System32\connect.dll
2008-11-26 19:23 . 2008-08-27 22:40 712,704 --a--c--- c:\windows\System32\WindowsCodecs.dll
2008-11-26 19:23 . 2008-08-27 22:40 425,472 --a--c--- c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 19:23 . 2008-08-27 22:40 347,136 --a--c--- c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 19:23 . 2008-10-21 22:57 241,152 --a--c--- c:\windows\System32\PortableDeviceApi.dll
2008-11-26 19:23 . 2008-01-19 02:36 160,768 --a--c--- c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 19:23 . 2008-01-19 02:36 94,720 --a--c--- c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-13 22:08 . 2008-12-08 23:41 d----c--- c:\program files\TVAnts
2008-11-13 20:14 . 2008-11-13 20:14 d----c--- c:\windows\Sun
2008-11-13 20:07 . 2008-10-16 16:13 1,809,944 --a--c--- c:\windows\System32\wuaueng.dll
2008-11-13 20:07 . 2008-10-16 15:56 1,524,736 --a--c--- c:\windows\System32\wucltux.dll
2008-11-13 20:07 . 2008-10-16 16:12 561,688 --a--c--- c:\windows\System32\wuapi.dll
2008-11-13 20:07 . 2008-10-16 15:55 83,456 --a--c--- c:\windows\System32\wudriver.dll
2008-11-13 20:07 . 2008-10-16 16:09 51,224 --a--c--- c:\windows\System32\wuauclt.exe
2008-11-13 20:07 . 2008-10-16 16:09 43,544 --a--c--- c:\windows\System32\wups2.dll
2008-11-13 20:07 . 2008-10-16 16:08 34,328 --a--c--- c:\windows\System32\wups.dll
2008-11-13 20:06 . 2008-10-16 14:08 162,064 --a--c--- c:\windows\System32\wuwebv.dll
2008-11-13 20:06 . 2008-10-16 13:56 31,232 --a--c--- c:\windows\System32\wuapp.exe
2008-11-12 17:35 . 2008-08-26 20:05 212,480 --a--c--- c:\windows\System32\drivers\mrxsmb10.sys
2008-11-11 15:27 . 2008-09-05 00:14 1,191,936 --a--c--- c:\windows\System32\msxml3.dll
2008-11-11 15:26 . 2008-09-09 22:40 1,334,272 --a--c--- c:\windows\System32\msxml6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 02:00 --------- dc--a-w c:\programdata\TEMP
2008-12-09 09:36 --------- dc----w c:\programdata\Spybot - Search & Destroy
2008-12-09 00:20 --------- dc----w c:\programdata\Symantec
2008-12-09 00:19 --------- dc----w c:\program files\Symantec
2008-12-09 00:19 --------- dc----w c:\program files\Common Files\Symantec Shared
2008-12-07 00:15 174 --sha-w c:\program files\desktop.ini
2008-12-07 00:05 --------- dc----w c:\program files\Windows Sidebar
2008-12-07 00:05 --------- dc----w c:\program files\Windows Photo Gallery
2008-12-07 00:05 --------- dc----w c:\program files\Windows Mail
2008-12-07 00:05 --------- dc----w c:\program files\Windows Journal
2008-12-07 00:05 --------- dc----w c:\program files\Windows Defender
2008-12-07 00:05 --------- dc----w c:\program files\Windows Calendar
2008-12-07 00:05 --------- d-----w c:\program files\Windows Collaboration
2008-12-06 23:47 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-06 23:47 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\FileMaker
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\Download Manager
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\CyberLink
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\Amazon
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\acccore
2008-12-05 06:55 --------- dc----w c:\programdata\WholeSecurity
2008-12-04 17:52 --------- dc----w c:\program files\Spybot - Search & Destroy
2008-12-02 10:07 --------- dc----w c:\program files\StudySmart
2008-11-29 05:51 --------- dc----w c:\program files\QuickTime
2008-11-29 05:50 --------- dc----w c:\programdata\Apple Computer
2008-11-27 17:01 --------- dc----w c:\programdata\Microsoft Help
2008-11-14 02:48 --------- dc----w c:\users\stepahnie\AppData\Roaming\SopCast
2008-11-03 20:38 32,132,615 -c--a-w c:\users\stepahnie\Symantec AV - Ver. 10.2 - Vista (32 bit) - unmanaged - 01MAR.exe
2008-10-30 21:01 --------- dc----w c:\program files\Amazon
2008-10-30 16:42 --------- dc----w c:\program files\Microsoft Works
2008-10-02 03:49 827,392 -c--a-w c:\windows\System32\wininet.dll
2008-09-30 21:43 1,286,152 -c--a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 -c--a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 -c--a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 -c--a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 -c--a-w c:\windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 -c--a-w c:\windows\System32\win32k.sys
2007-11-28 04:00 8 -c--a-w c:\users\stepahnie\AppData\Roaming\usb.dat.bin
2007-11-26 16:56 47,360 -c--a-w c:\users\stepahnie\AppData\Roaming\pcouffin.sys
2007-07-01 23:48 0 -c--a-w c:\users\stepahnie\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Here is my combofix log:
ComboFix 08-12-09.03 - stepahnie 2008-12-10 21:00:27.1 - NTFSx86
Microsoft Windows Vista Home Premium 6.0.6001.0.1252.1.1033.18.361 [GMT -5:00]
Running from: c:\users\stepahnie\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\stepahnie\AppData\Roaming\inst.exe
c:\windows\system32\MabryObj.dll
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-10 02:52 . 2008-06-22 20:59 2,868,736 --a--c--- c:\windows\System32\mf.dll
2008-12-10 02:52 . 2008-06-22 20:59 996,352 --a--c--- c:\windows\System32\WMNetMgr.dll
2008-12-10 02:52 . 2008-06-22 20:58 94,720 --a--c--- c:\windows\System32\logagent.exe
2008-12-10 02:37 . 2008-10-21 00:25 296,960 --a--c--- c:\windows\System32\gdi32.dll
2008-12-10 02:35 . 2008-10-29 01:29 2,927,104 --a--c--- c:\windows\explorer.exe
2008-12-10 01:39 . 2008-12-10 20:41
2008-12-09 03:58 . 2008-12-09 03:58
2008-12-08 20:05 . 2008-12-08 20:05
2008-12-08 20:05 . 2008-12-08 20:05
2008-12-08 19:29 . 2008-12-08 19:29
2008-12-08 19:19 . 2008-12-08 19:19 109,744 --a--c--- c:\windows\System32\drivers\SYMEVENT.SYS
2008-12-08 19:19 . 2008-12-08 19:19 8,014 --a--c--- c:\windows\System32\drivers\SYMEVENT.CAT
2008-12-08 19:19 . 2008-12-08 19:19 805 --a--c--- c:\windows\System32\drivers\SYMEVENT.INF
2008-12-08 19:18 . 2008-12-08 19:18
2008-12-08 04:01 . 2008-12-08 04:01
2008-12-08 04:01 . 2008-12-08 04:01
2008-12-08 04:01 . 2008-12-08 04:01
2008-12-08 04:01 . 2008-12-08 04:01
2008-12-08 04:01 . 2008-12-03 19:53 38,496 --a--c--- c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-08 04:01 . 2008-12-03 19:53 15,504 --a--c--- c:\windows\System32\drivers\mbam.sys
2008-12-08 02:43 . 2008-02-22 23:38 170,496 --a--c--- c:\windows\System32\tcpipcfg.dll
2008-12-08 02:43 . 2008-02-22 21:41 22,528 --a--c--- c:\windows\System32\netiougc.exe
2008-12-08 02:42 . 2008-12-08 02:42
2008-12-08 02:42 . 2008-08-21 20:41 1,221,008 --a--c--- c:\windows\System32\zpeng25.dll
2008-12-08 02:40 . 2008-12-08 02:42
2008-12-08 02:40 . 2008-12-10 19:05 348,371 --ah-c--- c:\windows\System32\drivers\vsconfig.xml
2008-12-08 02:40 . 2008-08-21 20:42 294,288 --a--c--- c:\windows\System32\drivers\vsdatant.sys
2008-12-07 16:19 . 2008-12-07 16:19
2008-12-07 16:18 . 2008-12-07 16:18
2008-12-07 16:18 . 2008-12-07 16:18
2008-12-07 16:18 . 2007-05-30 07:10 10,872 --a--c--- c:\windows\System32\drivers\AvgAsCln.sys
2008-12-07 13:07 . 2008-05-27 00:18 350,208 --a--c--- c:\windows\System32\mssph.dll
2008-12-07 13:07 . 2008-05-27 00:18 203,776 --a--c--- c:\windows\System32\mssphtb.dll
2008-12-06 19:03 . 2008-12-06 19:03
2008-12-06 17:49 . 2008-12-06 18:05
2008-12-04 19:16 . 2008-12-04 19:16
2008-12-04 17:43 . 2008-12-08 17:57
2008-11-29 00:51 . 2008-11-29 00:51
2008-11-29 00:48 . 2008-11-29 00:48
2008-11-29 00:48 . 2008-11-29 00:48
2008-11-29 00:48 . 2008-11-29 00:48
2008-11-28 14:50 . 2008-11-28 14:50
2008-11-26 19:23 . 2008-10-21 00:25 1,645,568 --a--c--- c:\windows\System32\connect.dll
2008-11-26 19:23 . 2008-08-27 22:40 712,704 --a--c--- c:\windows\System32\WindowsCodecs.dll
2008-11-26 19:23 . 2008-08-27 22:40 425,472 --a--c--- c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 19:23 . 2008-08-27 22:40 347,136 --a--c--- c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 19:23 . 2008-10-21 22:57 241,152 --a--c--- c:\windows\System32\PortableDeviceApi.dll
2008-11-26 19:23 . 2008-01-19 02:36 160,768 --a--c--- c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 19:23 . 2008-01-19 02:36 94,720 --a--c--- c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-13 22:08 . 2008-12-08 23:41
2008-11-13 20:14 . 2008-11-13 20:14
2008-11-13 20:07 . 2008-10-16 16:13 1,809,944 --a--c--- c:\windows\System32\wuaueng.dll
2008-11-13 20:07 . 2008-10-16 15:56 1,524,736 --a--c--- c:\windows\System32\wucltux.dll
2008-11-13 20:07 . 2008-10-16 16:12 561,688 --a--c--- c:\windows\System32\wuapi.dll
2008-11-13 20:07 . 2008-10-16 15:55 83,456 --a--c--- c:\windows\System32\wudriver.dll
2008-11-13 20:07 . 2008-10-16 16:09 51,224 --a--c--- c:\windows\System32\wuauclt.exe
2008-11-13 20:07 . 2008-10-16 16:09 43,544 --a--c--- c:\windows\System32\wups2.dll
2008-11-13 20:07 . 2008-10-16 16:08 34,328 --a--c--- c:\windows\System32\wups.dll
2008-11-13 20:06 . 2008-10-16 14:08 162,064 --a--c--- c:\windows\System32\wuwebv.dll
2008-11-13 20:06 . 2008-10-16 13:56 31,232 --a--c--- c:\windows\System32\wuapp.exe
2008-11-12 17:35 . 2008-08-26 20:05 212,480 --a--c--- c:\windows\System32\drivers\mrxsmb10.sys
2008-11-11 15:27 . 2008-09-05 00:14 1,191,936 --a--c--- c:\windows\System32\msxml3.dll
2008-11-11 15:26 . 2008-09-09 22:40 1,334,272 --a--c--- c:\windows\System32\msxml6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 02:00 --------- dc--a-w c:\programdata\TEMP
2008-12-09 09:36 --------- dc----w c:\programdata\Spybot - Search & Destroy
2008-12-09 00:20 --------- dc----w c:\programdata\Symantec
2008-12-09 00:19 --------- dc----w c:\program files\Symantec
2008-12-09 00:19 --------- dc----w c:\program files\Common Files\Symantec Shared
2008-12-07 00:15 174 --sha-w c:\program files\desktop.ini
2008-12-07 00:05 --------- dc----w c:\program files\Windows Sidebar
2008-12-07 00:05 --------- dc----w c:\program files\Windows Photo Gallery
2008-12-07 00:05 --------- dc----w c:\program files\Windows Mail
2008-12-07 00:05 --------- dc----w c:\program files\Windows Journal
2008-12-07 00:05 --------- dc----w c:\program files\Windows Defender
2008-12-07 00:05 --------- dc----w c:\program files\Windows Calendar
2008-12-07 00:05 --------- d-----w c:\program files\Windows Collaboration
2008-12-06 23:47 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-06 23:47 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\FileMaker
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\Download Manager
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\CyberLink
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\Amazon
2008-12-06 07:34 --------- dc----w c:\users\stepahnie\AppData\Roaming\acccore
2008-12-05 06:55 --------- dc----w c:\programdata\WholeSecurity
2008-12-04 17:52 --------- dc----w c:\program files\Spybot - Search & Destroy
2008-12-02 10:07 --------- dc----w c:\program files\StudySmart
2008-11-29 05:51 --------- dc----w c:\program files\QuickTime
2008-11-29 05:50 --------- dc----w c:\programdata\Apple Computer
2008-11-27 17:01 --------- dc----w c:\programdata\Microsoft Help
2008-11-14 02:48 --------- dc----w c:\users\stepahnie\AppData\Roaming\SopCast
2008-11-03 20:38 32,132,615 -c--a-w c:\users\stepahnie\Symantec AV - Ver. 10.2 - Vista (32 bit) - unmanaged - 01MAR.exe
2008-10-30 21:01 --------- dc----w c:\program files\Amazon
2008-10-30 16:42 --------- dc----w c:\program files\Microsoft Works
2008-10-02 03:49 827,392 -c--a-w c:\windows\System32\wininet.dll
2008-09-30 21:43 1,286,152 -c--a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 -c--a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 -c--a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 -c--a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 -c--a-w c:\windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 -c--a-w c:\windows\System32\win32k.sys
2007-11-28 04:00 8 -c--a-w c:\users\stepahnie\AppData\Roaming\usb.dat.bin
2007-11-26 16:56 47,360 -c--a-w c:\users\stepahnie\AppData\Roaming\pcouffin.sys
2007-07-01 23:48 0 -c--a-w c:\users\stepahnie\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.