Question

PC infected with Multiple viruses and possible rootkits

Asked by: CluelessNI

A friend has a pc which I believe has had a serious virus issue for some time. Having failed to cure it, and with the most recent symtpoms being no icons, start menus etc on the desktop they have given it to me. The first thing I did was run up-to-date versions of AVG and superantivirus which identified numerous forms of virus, malware et al. Of main concern was two possible rootkits (Rootkit.Agent.gen and Rootkit TDSServ), Virus Rostock G and Vundo MSWorker fake) plus Trojans such as Csrssc, smitfraud (which I believe is responsible for the missing icons), sheur amongst others. I have cleared out all of temp files, cookies etc and tried to remove as much as I can using AVG & Superantivirus but as you would expect I have not been able to remove the serious infections and restore the icons. I have checked the registry settings for explorere.exe and it seems Ok. I can get task manager to run and can see explorer.exe in C:\windows. However I cannot run it as a new task. In addition it is not showing as running in the processes tab. I have also downloaded and  run smitrem but the icons have not been restored. Before I go any further and download root detecting utilities and wonder if someone could take a look at a HiJackThis log. This is as at the current state of play. I have one taken before I ran smitrem if it is of any use. Any advice and guiidance as to my next course of action would be appreciated.  With thanks.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-02-10 at 13:14:13ID24131250
Topics

HijackThis Software

,

Anti-Virus

Participating Experts
6
Points
500
Comments
30

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Explorer.exe is virus infected
    Hello XP people. I'm running XP (home version). I just installed the AVG virus checker and it found and 'cleansed' several viruses for me. But it also told me that explorer.exe is infected, and it was unable to cleanse it. It invited me to get rid of it, but I declined bec...
  2. Trojan Virus infection
    Infected with Radim Hook. I cant seem to get rid of it. I have tried Hijack this and Webroot spysweeper. It keeps coming back. My gut tells me its in registry. Can anyone advise on how to get rid of this particular virus. Thanks in advance.
  3. VIrus Infection Trojan and Worm
    My computer is infected with virus. I had Kaspersky and it was disabled. I installed Microsoft OnCare ahd they have tried to help. Installed Super Anti Spyware and ran in safe mode Ditto with Malware Malbites (sp). Trojan and other viruses reappear after cleaning or quarant...
  4. Virus infected windows files.
    I am working on removing a virus infection from a windows XP home computer. It started with spyware and the typical popups. I have removed everything I can find, but Trend Micro keeps finding a virus it calls PE_PATCHEP.A It is infecting lsass.exe, services.exe, spoolsv.ex...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: rbarnhardtPosted on 2009-02-10 at 13:17:28ID: 23605488

Why not just reload the computer? If it is that infected, my opinion is that is the best solution.

 

by: CluelessNIPosted on 2009-02-10 at 13:21:23ID: 23605532

This remains a possibility although I'll have to check that they have all the relevant disks. However I'll hang on a bit to see if anything comes of the HJT log. Thanks anyway.

 

by: lamaslanyPosted on 2009-02-10 at 13:22:59ID: 23605547

I agree with rbarnhardt: back up the data, nuke it and install a clean OS.  Once fully patched install and update antivirus then scan the data prior to moving it back.

 

by: Mike_CarrollPosted on 2009-02-10 at 13:23:32ID: 23605556

Download MBAM here http://www.malwarebytes.org/mbam.php
Install, update and run it.

Then think about the HiJackThis log.

Also, I would not rule out a reload

 

by: TK-77Posted on 2009-02-10 at 13:27:34ID: 23605605

I agree with Mike Carroll, Run Malwarebytes and then post another Hijackthislog.

Here is what I found so far. Safe to remove:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.search.yahoo.com/search?fr=mcafee&p=%s
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (file missing)
O4 - HKLM\..\Run: [dmxxk.exe] C:\WINDOWS\system32\dmxxk.exe
O4 - HKLM\..\Run: [dmvkk.exe] C:\WINDOWS\system32\dmvkk.exe
O4 - HKLM\..\Run: [mozilla-text] newbreed.exe
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\system32\lssas.exe
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKCU\..\Run: [My-disgo] C:\Documents and Settings\Mark\Application Data\My-disgo\MyKey disgo.exe
O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\Mark\LOCALS~1\Temp\~tmpa.exe
O4 - HKCU\..\Run: [13CFG914-K641-26SF-N31P] C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0950\vsse33.exe
O4 - HKCU\..\RunOnce: [DelayShred] "C:\Program Files\McAfee.com\Shredder\SHRED32.EXE" /q C:\DOCUME~1\Mark\LOCALS~1\History\History.SH! C:\WINDOWS\SYSTEM32\stdole3.SH! C:\WINDOWS\SYSTEM32\atmclk.SH! C:\WINDOWS\SYSTEM32\regperf.SH! C:\WINDOWS\SYSTEM32\hp100.SH! C:\WINDOWS\SYSTEM32\ld104.SH! C:\WINDOWS\SYSTEM32\dcomcfg.SH!
O4 - HKUS\S-1-5-18\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O20 - Winlogon Notify: cbXnkHXq - cbXnkHXq.dll (file missing)
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)

TK

 

by: rpggamergirlPosted on 2009-02-10 at 14:30:30ID: 23606290


F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\system32\ndetect.exe,

The above is also a bad entry (SDBot/IRCBot entry).
The system is heavily infected wareout and all, you may need other tools in case MalwareBytes won't get it all.
Either SDFix or Combofix you can also run if problem persists.


If problem persists,
Please download ComboFix by sUBs: If the tool you use won't run, redownload and rename them first before saving to your desktop)
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

 

by: CluelessNIPosted on 2009-02-10 at 14:38:20ID: 23606353

OK - I have removed the entries that TK-77 said was safe. I have downloaded malwarebytes product and am running it as we speak. Once that is complete I will post a HJT log as requested. This is 150GB HDD so previous scans have taken some time. I will  come back to you as soon as it is done. The only issue is that this PC cannot connect to internet so the malwarebytes program was installed but not updated prior to running the scan. However I am sure its better than nothing! Just a quick thought - how much of this (HTJ or malwarebytes) should be done in safe mode - or does it not make much difference?  With thanks...

 

by: Mike_CarrollPosted on 2009-02-10 at 14:43:15ID: 23606391

MBAM is updated pretty regularly. Not the end of the world if it's not updated.

 

by: rpggamergirlPosted on 2009-02-10 at 15:31:15ID: 23606761

>>>OK - I have removed the entries that TK-77 said was safe
Did you also removed the F2 entry below that TK-77 missed in his list?
Believe it or not that is a bad entry. MBAM might removed it itself too anyway.

F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\system32\ndetect.exe,


>>>how much of this (HTJ or malwarebytes) should be done in safe mode
Hijackthis should NOT be run in safe mode(if pc boots in normal mode), while MBAM can be run in safe mode if you wish though It shouldn't make any difference, some tools works well in both mode.

 

by: CluelessNIPosted on 2009-02-11 at 08:12:19ID: 23612843

Hi All - just a quick update. I removed the F2 entry as identified by rpggamergirl and I ran the malwarebytes program and it has improved things considerably as it removed 300+ items(at the second time of asking). I now have desktop icons etc plus I also have connectivity back. I have attached a current HJT log plus the malwarebytes log. What I intend to do now that I have connectivity is run an updated malwarebytes plus combofix as per rpggamergirls' recommendation. I'll come back to you this evening once these programs have run. With thanks, C

 

by: CluelessNIPosted on 2009-02-11 at 08:13:33ID: 23612863

Sorry - finger trouble. Heres the HJT log.

 

by: rpggamergirlPosted on 2009-02-11 at 16:14:00ID: 23618082

The MBAM log attached is before it removed those items(which I assume, as you said has now been removed)

The Hijackthis log(besides some unnecessary entries) looks clean!
Bear in mind also that a clean Hijackthis log is not a guarantee that the system is clean because some nasties can still hide from the hijackthis scan.
But if the pc is behaving well and hijackthis log is clean then it sounds great.

 

by: rbarnhardtPosted on 2009-02-11 at 20:30:18ID: 23619156

Personally, if it was that infected, I would backup the data, nuke it, and reload it. I never trust a badly infected system.

 

by: CluelessNIPosted on 2009-02-16 at 04:43:31ID: 23649186

Hi All, Sorry about the delay in replying which was due to both being away on a work trip and also due to sever problems with my own PC. I thought I had infected it with the same viruses as the PC I am trying to fix as the symptoms were similar (slow boot and no internet connection/icons on desktop although ctr+alt+del gave me the task manager). However this turned out to be due to a windows patch (KB960715) which clashed with my firewall (Zone Labs) which it would not allow to initialise. It took me a while to figure this out hence the delay. I have uninstalled the patch and zone labs (which was corrupted) and all is well. However I have taken the liberty of attached a HJT log and malwarebytes log for my personal PC which I hope someone would be kind enough to take a look at. I would also be interested to know if this is a known issue with this patch as this would not be the first time this has happened.
With regard to teh original infected PC I think it is a case of one step forward and two back. Having restoreed the icons and intenet connectivity through malwarebytes I then ran combofix as suggested by rpggamergirl. After this I lost my interet connection although desktop icons etc were still there. It booted OK but with the occsional BSOD.I ran malwarebytes again and it identified vundo so also ran vundofix. I still had no internet connection and windos diagnositcs showed a problem with winsock.dll. Therefore I ran winsock fix but it did not work. I then let windows diagnostics fix the problem. Big mistake!. Now the pc boots OK but as soon as it tries to load a profile it gives a BSOD. I can boot into safe mode and the icons etc are still there (but no connectivity). I checked the lsass.exe files as I thought combofix may have removed them. There was a copy in System32 folder but not System32\dllcache so I copied form one to the other. However It still gives me a BSOD at the user login stage. I have attached a current HJT log adn malwarebytes log but I beleive the system is now clean. However if someone could take a look and confirm this I would be grateful. Likewise if anyone has any thoughts on teh BSOD issue then these would also be welcome. I realise that this probably a different issue and that I may need to log a seperate question. With thanks....

 

by: CluelessNIPosted on 2009-02-16 at 04:45:29ID: 23649196

Apologise for previous typos !! - just wanted to get a comment on quickly!!

 

by: rpggamergirlPosted on 2009-02-17 at 03:52:34ID: 23658415

Original pc, just fix this entry below:
O4 - HKUS\S-1-5-18\..\Run: [hdleqqqz.exe] C:\WINDOWS\hdleqqqz.exe (User 'SYSTEM')
C:\WINDOWS\hdleqqqz.exe <-- and delete this file if still present.
 

Personal pc: the 023 entry can go and delete its file. I assume you let MBAM took care of the threats found?
C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe


Or just try running combofix on both pcs and see if it finds anything else, show us the combofix log after.

 

by: CluelessNIPosted on 2009-02-17 at 14:07:18ID: 23664816

Hi rpggamergirl: I have removed the entries as per your last post. I have also run combofix on the original PC (in safe mode as I still cannot load a profile in normal mode). I have attahced a log accordingly.
With regard to my personal PC I cannot run combofix as it keeps detecting my antivirus (AVG). This is despite the fact that I have uninstalled AVG and used the avg removal tool. I cannot see any trace of it on my system but combofix  still seems to think it is running. I will keep working at it.  With thanks...

 

by: DooflegnaPosted on 2009-02-17 at 14:34:42ID: 23665090

It's probably detecting registry traces left over.  You'll need to run regedit and get rid of these keys manually.

http://www.mydigitallife.info/2008/07/11/fix-remove-avg-incompatible-software-error-when-installing-kaspersky-kis-and-kav/

 

by: CluelessNIPosted on 2009-02-17 at 15:06:47ID: 23665309

Hi Dooflegna - thanks for this. I had a look for traces of avg and could not find any. In particular I cold not see the entries as detailed in your link or using he find command. The path that is showing as problematic is HKLM\Software\Microsoft\WindowsNT\currentversion\windows\create registry key. However when I navigate to as far as the windows folder I get the error " cannot open windows: error opening key".
I hope this helps

 

by: DooflegnaPosted on 2009-02-17 at 15:19:32ID: 23665386

Does AVG Install/Uninstall from Safe Mode?  If it does, I would boot to Safe mode w/ Command Prompt (F8), reinstall AVG, reboot, Safe Mode w/ Command Prompt and then uninstall AVG.

 

by: rpggamergirlPosted on 2009-02-18 at 04:52:07ID: 23669681


[COLOR=RED] c:\windows\system32\userinit.exe . . . is infected!![/COLOR]
[COLOR=RED] c:\windows\system32\svchost.exe . . . is infected!![/COLOR]
[COLOR=RED] c:\windows\system32\spoolsv.exe . . . is infected!![/COLOR]
[COLOR=RED] c:\windows\explorer.exe . . . is infected!![/COLOR]


Looks like Virut or sality file patcher and looks like CF couldn't find a clean replacement of those files.
If it's virut it can't be cleaned and a reformat is needed.

 

by: rpggamergirlPosted on 2009-02-18 at 04:56:16ID: 23669714

>>>I had a look for traces of avg and could not find any<<<
AVG is still installed in the personal pc(entries are showing there.

How to disable AVG's Resident Shield.
Right click the AVG icon and click Open.
In the Overview panel click on Resident Sheild > Uncheck the Resident Sheild Active box > Save Changes

 

by: CluelessNIPosted on 2009-02-18 at 08:45:49ID: 23672070

Thanks for all the advice above - gives me a few things to do. I will 1. See what disks the infected PC owners have and go for a restore. I have their data and have swept it with malwarebytes and it appears clean. With regard to my own PC and AVG I will try Dooflegna's command line suggestion tonight when I have more time adn come back to you soonest. With thanks....

 

by: DooflegnaPosted on 2009-02-18 at 08:53:36ID: 23672187

There's a new nasty variant strain of virut that has just hit.  A lot of commercially available scanners opt to just delete the infected files if they are unable to successfully clean them.  However, since this particular infection targets .exes, it can render your OS entirely unusable.  AVG offers a free Virut remover (here: http://www.softpedia.com/get/Antivirus/Win32-Virut-Remover.shtml ), but it's outdated, so it's chances of cleaning in your situation are probably very small.  I agree with rpggamergirl's that a reload may be necessary in this case.  No fun.

 

by: CluelessNIPosted on 2009-02-18 at 12:20:30ID: 23674468

Hi All.
Firstly I downloaded the avg virut remover by as predicted it did not have much affect. It did not detect anythign on teh infected PC but it did on my pen drive that I have been using to transfer logs. Don't worry - this is about to undergo a full format. However I ran combofix again and it detected the entries as shown in rpggamergirls last post. Did not seem much point in posting the log as I don't think anything has changed from the last one. I am in the process of getting the original disks and will reformat it.

Secondly I tried Dooflegna's suggestion of trying an AVG install/uninstall in safe mode from the command prompt. Again it stalled with the same error message. Is it possible that AVG is not so much the problem but more so a corrupt registry folder (the windows folder as stated in the path). I take it the entry that rpggamergirl is referring to in the HJT log is this one:

O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing).

Can I use HJT to try and fix this entry?
Thanks....

 

by: DooflegnaPosted on 2009-02-18 at 15:18:03ID: 23676259

It could be a permissions issue, which spyruses have been known to bork.  For fun before you restore the OS, you could always try a permissions reset.

Here are some better commands than what's listed in the link.

subinacl /subkeyreg hkey_local_machine /grant=administrators=f /grant=system=f
subinacl /subkeyreg hkey_users /grant=administrators=f /grant=system=f
subinacl /subdirectories %systemdrive%\ /setowner=administrators /grant=administrators=f /grant=system=f

http://www.winhelponline.com/blog/reset-the-registry-and-the-file-permissions-in-windows-xp/

 

by: CluelessNIPosted on 2009-02-19 at 13:51:02ID: 23686629

Hi All. Cuurent situation is:

Original infected PC: No change. Still waiitng for disks to do a complete restore.

Personal PC: I tried dooflegna's subinacl solution. Whilst it ran OK the first line produced 3 failures. I only noted 2 of them: Hkey_local_machine\Security\Policy\Secrets\sai and
HKey_Local_Machine\Software\Microsoft\windowsNT\currentversion\perflib\009

Notwithstanding this I tried agian to open the widows folder in regedit but got the same message. However I right-clicked it and ws told I could not view permissions but could change them. I then added in Administrators and gave full permissions in the ACL but it would not let me apply them. HOWEVER: I was able to take ownership OK. I then re-installed AVG successfully, disabled it (using reggamersgirls instructions) and finally ran combofix on my own PC. I have attached the log and if someone could take a look I would be grateful.
We are probably approaching the close of this (depending on the log). One worry I have is rootkits. Should I download a program that looks for this or is there no point?
Is there anything else I should run and attach a log? Do you need another malwarebytes or HJT log? If so please let me know.

With thanks...........

 

by: DooflegnaPosted on 2009-02-21 at 00:42:50ID: 23698988

For what it's worth, the subinacl reset will almost always generate errors.  It'd be very strange if it didn't.  Your combofix log looks pretty good.  We shouldn't need Hijack This, but it can always be reviewed if it'll make you feel more comfortable.

If you're worried about rootkits, check out Trend Micro's Rootkit Buster: http://www.trendmicro.com/download/rbuster.asp

Can we access internet at this point?  If so, I suggest running a couple free online scanners.  They won't remove anything, but they'll tell us if anything's there.

http://www.kaspersky.com/virusscanner

 

by: CluelessNIPosted on 2009-02-21 at 14:26:57ID: 31545304

As per my last post - many thanks for your time and help. It was very clear, concise and accurate. With best wishes.......

 

by: CluelessNIPosted on 2009-02-21 at 14:30:54ID: 23702258

I have downloaded and run rottkitbuster on my personal PC adn it found nothing. i was more concerned about the original infected PC but this is now irrelavant as it has now been formatted, reinstalled and is back with its rightful owners. I have run AVG adn Superantispyware and they have found nothing so, whilst I may do Kaspersky for completeness I am confident all is well.
I guess it is time to close the call. Many thanks to you all, but especailly rpggamergirl, Dooflegna and TK-77 for all your time and help. With best wishes, CluelessNI

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...