Thanks for the post and info. Great catch! Let me take a look at those and I will post the results or close this.
bol
Please review the ComboFix log file below (see snippet). Does it look clean? Any other things I should do or know about for getting rid of this worm?
Thanks for your help!
bol
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
The files really do seem suspicious. The location makes me think they are valid at all so I went with the second option and ran the "FileLook." The resulting log is in the snippet below.
Do I have to manually delete or is there a way for ComboFix to do it? What is the "SnapShot" section and should I be concerned about the files listed there? It is a new section so I don't know if that means there are problems (and even new ones) or just it is a section that is part of the "FileLook" I ran.
What is the next step? Any extra info you would like to provide on how ComboFix works will be great since I am interested in it and this process. That is more just for my curiosity though so don't feel you have to for this answer. :)
Can you tell from the results if McAfee is working well?
Let me know if you need anything else. Thanks for the help so far.
bol
I'm really sorry, I didn't receive the alert that you posted. I came here while googling something else,(lucky I did)
Those files are very suspicious, let's delete them, combofix creates backup of all deleted files anyway.
I think these may be the new variants of Brontok, the old brontok use filenames the same those of system files csrss.exe, lsass.exe, smss.exe, svchost.exe but located in App. Data folder which is easily recognized, but this time it looks like it's using different tricks (no longer system filenames) but inside legit folder names instead.
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------
File::
c:\documents and settings\Joeblack\Applicat
c:\doc
c:\docume
c:\
c:\doc
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
About the snapshot, Combofix creates a snapshot of the files from C:\Windows during its first run.
The second time Cf runs, it compares the earlier snapshot with current file listing. Any discrepancies is listed.
But since those files did not fail the sigcheck, I won't worry about them just yet.
Was there something missing in the steps? The files were not deleted. I can manually delete them if that will be just as easy but I am curious why the program didn't using the new Script file. Let me know if it seems like I missed something or if you have a question.
I actually tried the file twice but neither run deleted the files. The second log file is below.
Thanks!
bol
Did you include the line "File::" in the script? including the double colons "::"
it must be included.
File::
I can't think of any reason why combofix did not delete those files. It should've said "failed to delete" if there was something protecting the files from deletion.
Yes, you can also delete them manually if you like.
The thing for using Combofix to delete them is that it will create a backup on those files.
I haven't compared both logs but I don't notice any new malicous entries showing in the second log, unless some of those legit files are patched. Do you see any files there that you don't recognize? I might've missed it.
If you like you can also try running DrWebCureIt to check for any file infectors in case you're worried about those system files in the snapshot section.
Scanners to scan for file infectors:
Virut:
http://www
Sality:
http://support.kasp
By the way, can you please tell us how did you disable McAfee? A lot of McAfee users seem to have problems disabling its realtime protection when running Combofix. And I don't have McAfee.
Thanks.
It was the colons. Sorry! Including those got the files deleted. The new log file is below. I don't see any files that are a problem but let me know if you have a concern. Thanks for the link to DrWebCureIt; I will pass on that info but won't insist on it being run unless you think it would be good.
The response I got for disabling McAfee is below:
"I open McAfee security center, go to the advanced menu, click on 'configure' and then run through "computer and files", "internet", and "email and IM" categories; in each on there is a manual option to turn off the protection (click the off bubble). When I'm done running ComboFix I just have McAfee "fix" everything that is disabled and it is all back to normal."
Let me know if those details aren't enough or some more info will help. I am glad I could help you some. Thanks for all your help so far. It seems like this is done but I will wait for your response before closing this.
bol
Hi bol,
Yes, the files have been deleted, that's great.
And if the pc is running fine he's good to go.
When you uninstall ComboFix, the backup will be deleted and System Restore will be reset.
You can uninstall ComboFix via;
Start > Run and 'copy and paste' next command in the field:
ComboFix /u
And thank you so much for the steps on how to disable McAfee. I'll take note on this so I can share it to McAfee users when it's needed.
Thanks! :)
Thanks. I will pass on the steps to uninstall. After posting the log I had the user run McAfee and it found some files which it quarantined. I don't know if it is this same issue so I will open a new question for them and close this. Please take a look and help there if you can (although they will not be at their computer for about 5 days so there may be a delay after your first reply).
Thanks again for the help! I am glad the McAfee steps were useful and I hope they will help others.
bol
Regarding your other thread, it would've been okay to continue on here, but anyway it seems resolved now.
Thanks again for the McAfee steps, as I've seen many CF users who have problems disabling it.
I even tried googling for instructions but I couldn't find one, so I'm really glad to have it now, thanks to you.
:) Your welcome! I am really glad to have made my *small* contribution to what is done by you Virus experts. I know enough about virus, etc removal to be VERY impressed by what you all do.
>> it would've been okay to continue on here, <<
I realize now the "new" trojans were more related to this than I had thought. I overlooked the folder name that showed it was in ComboFix's "folder." Since I spend most time as an expert when I couldn't say for sure it was related I thought it best to ask a new question. I have the points to use so no harm and it was nice to see other experts jump in, especially Vic, and get their contribution.
bol
Business Accounts
Answer for Membership
by: rpggamergirlPosted on 2009-06-24 at 06:36:01ID: 24700858
Hi bol,
/
ion Data\Apple Computer\socks32.exe uments and settings\Joeblack\Applicat ion Data\Corel Photo Album\megalon.exe nts and settings\Joeblack\Applicat ion Data\AdobeUM\reniga.dll documents and settings\Joeblack\Applicat ion Data\Corel\horsi.exe uments and settings\Joeblack\Applicat ion Data\Adobe\moha.exe
---------- ---------- ---------- ---------- ---------- --- k:: ments and settings\Joeblack\Applicat ion Data\Apple Computer\socks32.exe uments and settings\Joeblack\Applicat ion Data\Corel Photo Album\megalon.exe nts and settings\Joeblack\Applicat ion Data\AdobeUM\reniga.dll documents and settings\Joeblack\Applicat ion Data\Corel\horsi.exe uments and settings\Joeblack\Applicat ion Data\Adobe\moha.exe ---------- ---------- ---------- ---------- ------
If McAfee detected Brontok and did not remove it there are many removal tools for Brontok out there, Sophos, BitDefender also has removal tools.
I don't see Brontok files in the log, though these files below look suspicious.
You might like to check them, they're all created in the same date/time 2009-06-23 04:26, some nasties also hide inside legit folders.
Check their properties to make sure they are legit or submit them at http://virusscan.jotti.org
c:\documents and settings\Joeblack\Applicat
c:\doc
c:\docume
c:\
c:\doc
Or you can let combofix check their properties using a script.
Run Combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------
FileLoo
c:\docu
c:\doc
c:\docume
c:\
c:\doc
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.