rpg -- thanks for the response. Ran ComboFix script and log is attached.
ndis.sys is still infected -- surprise! surprise!
I run CCleaner to clean both files and registry as a matter of course, so that had already been done. Reran to be safe but nothing suspicious was deleted (only a few log files left to delete). I also delete files in \Documents and Settings\%username%\Local Settings\Temp folder(s). Learned years ago that was a favorite malware hiding place and neither CCleaner nor ATF Cleaner clean those folders.
It's Easter Sunday morning here so I won't be working on PC again until later in the day. Will upadte as I have more info.
Main Topics
Browse All Topics





by: rpggamergirlPosted on 2009-04-12 at 00:25:13ID: 24124804
Hi willcomp,
---------- ---------- ---------- ---------- ---------- --- :: \windows\s ystem32\dr ivers\e43e dea6.sys ts and settings\Owner\Application Data\iwyn.bin m files\Common Files\tavosep.sys m files\Common Files\ehexigetiw.exe uments and settings\Owner\Application Data\yhyn.vbs and settings\Owner\Application Data\ziqylalisa.dll ments and settings\Owner\Application Data\jydocatyja.exe ram files\Common Files\hozusur.inf nts and settings\Owner\Application Data\yzare.sys s\Pyihuriz e.dat ndows\Khot oho.bin windows\sy stem32\dri vers\OLD7. tmp ows\temp\B N1.tmp
---------- ---------- ---------- ---------- ------
ne.org/cco unt/click. php?id=1 's normal after running ATF cleaner that the PC will be slower to boot the first time. eaner.com/ download/
ndis.sys failed the sigcheck so that's probably patched or maybe sality or virut is present there... I would just replaced that just to be sure.
I did not check those files in the dllcache folder(asuming they're all legit)....but some nasties can also hide in dllcache and i386 folders... the most likely going on here is a file infector. Snapshot is also showing some filesize discrepancy.
If it's virut a reformat and reinstall would be the quickest and safest solution as depending on how long the system has been infected it takes time and patience to remove and replaced corrupted files. And even then we can not guarantee that the system is virus-free or error-free afterwards.
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------
KillAll
File::
c:
c:\program files\Common Files\omykon.vbs
c:\documen
c:\documents and settings\All Users\Application Data\ocisib.dll
c:\program files\Common Files\befydyz.scr
c:\progra
c:\progra
c:\doc
c:\documents and settings\All Users\Application Data\lipaf.bat
c:\documents
c:\docu
c:\prog
c:\docume
c:\program files\Common Files\emakutik.dl
c:\window
c:\wi
c:\
c:\wind
Folder::
c:\program files\temp01
Driver::
e43edea6
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
Also run ATF Cleaner or CCleaner:
Download and run ATF Cleaner by Atribune.
http://www.atribu
It
OR:
CCleaner:
http://www.ccl