Unsolved

This post is more than 5 years old

59 Posts

8209

September 5th, 2007 19:00

Possible Malware-related problems, need help with diagnosing and fixing

I'm running Windows XP Home Edition (SP1) on a DELL Inspiron laptop.  I thought I had the computer well-protected from malware but recently, I began noticing suspicious symptoms coinciding with changing my anti-virus software from AVG to McAfee Enterprise provided by my company and upgrading Ad-Aware SE Personal to AdAware 2007.
 
The symptoms include numerous ads popping up while using Internet Explorer, frequently causing IE to hang and become unresponsive to the End Task command; many strange .exe processes showing in Task Manager, sometimes multiple processes with the same name; sometimes I run AdAware scans, delete the problems, run the scan again, and the same problems are identified again; general slowness and frequently the Desktop Explorer itself becomes unresponsive.
 
I tried following the steps outlined by DELL (Journal ID: 07248GSKWM, Article ID: 277075).  In particular, I downloaded Spybot Search & Destroy and immunized.  I also tried searching for Windows and IE updates, especially SP2.  The updater found 63 updates!  I downloaded these successfully, but during the installation phase, IE froze on 8 of 63 (Windows Messenger update) and I had to force a restart.  After restarting, I tried again to update and a dialog box appeared saying I didn't have privileges to update and that I should contact my system administrator (ME!---albeit not a very good one apparently).  Moreover, I can't even find or access my Control Panels anymore!  (What happened?)  As a last resort, I tried reinstalling Windows from the disk that came with the computer.  Although this was successful, I still can't see the Control Panels in the Start menu and all of the aformentioned problems persist.
 
I'd be most appreciative if you could help me:
(i) diagnose and fix the problem and, just as important
(ii) help me with a strategy (software and software settings) that will provide me comprehensive protection (assuming I keep everything current going forward---virus defs., immunizations, Windows security patches, etc.)
 
Appended below is my Hijack this log.  Thanks in advance for your help.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:25 AM, on 9/3/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Win32 NT Adv Services] taskmngr.exe
O4 - HKLM\..\Run: [Camra Updates] serviceswu.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\RunServices: [Camra Updates] serviceswu.exe
O4 - HKLM\..\RunServices: [Win32 NT Adv Services] taskmngr.exe
O4 - HKCU\..\Run: [Camra Updates] serviceswu.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sfl] "C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe"
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\Annie Fowler\svchost.exe
O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\CROSOF~1\ati2evxx.exe" -vt ndrv
O4 - HKCU\..\Run: [Brave-Sentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [Apeo] "C:\WINDOWS\SCURIT~1\winlogon.exe" -vt ndrv
O4 - HKUS\S-1-5-18\..\Run: [USB Driver4] UpdateXP2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Camra Updates] serviceswu.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [USBDrives] msfirewalI.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [LSASS32] ISASS32.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [USB Driver4] UpdateXP2.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [LSASS32] ISASS32.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantispyware.com/download/2007/download.php?file=2&aid=rrdef1_11_asr&lid=1034&affid=3
O17 - HKLM\System\CCS\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F50266D-7178-4E23-9E55-E4F2BBE8B86A}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{B68AACF7-76E8-41B1-A977-7A28EAC38788}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O20 - AppInit_DLLs: c:\windows\system32\pmkjifc.dll
O20 - Winlogon Notify: 0 ¸ À - 0 ¸ À (file missing)
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: DPCDFR - C:\WINDOWS\SYSTEM32\DPCDFR.dll
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O21 - SSODL: CDVfQUB - {E4DC5B2C-4E76-F186-6D41-2218BC043068} - C:\WINDOWS\System32\nzmal.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: Windows Management Service - Unknown owner - C:\WINDOWS\System32\.exe (file missing)
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 9050 bytes

59 Posts

October 9th, 2007 20:00

The ComboFix log is appended below. You mentioned something about removing these files the "old way"?

ComboFix log:

ComboFix 07-10-09.3 - Annie Fowler 2007-10-09 16:48:42.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.56 [GMT -4:00]
Running from: C:\Documents and Settings\Annie Fowler\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-09-09 to 2007-10-09 )))))))))))))))))))))))))))))))
.

2007-10-09 15:56 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-09 15:55 d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-10-09 15:55 d-------- C:\WINDOWS\LastGood
2007-10-09 13:06 24,576 --a------ C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-10-09 07:37 d-------- C:\VundoFix Backups
2007-10-04 00:02 d-------- C:\fsaua.data
2007-10-03 20:54 d-------- C:\Documents and Settings\Annie Fowler\Application Data\OpenOffice.org2
2007-10-03 20:45 d-------- C:\Program Files\OpenOffice.org 2.3
2007-10-03 17:59 d-------- C:\Program Files\SpywareBlaster
2007-10-03 17:51 d-------- C:\Program Files\CCleaner
2007-09-30 15:04 d-------- C:\Program Files\iTunes
2007-09-30 14:58 d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE
2007-09-30 14:57 d-------- C:\Program Files\Common Files\Apple
2007-09-26 09:48 d--h----- C:\WINDOWS\PIF
2007-09-23 23:12 d-------- C:\Program Files\MSXML 4.0
2007-09-23 22:53 33,792 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-09-23 22:41 128,896 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\fltmgr.sys
2007-09-23 22:41 23,040 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\fltmc.exe
2007-09-23 22:41 16,896 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\fltlib.dll
2007-09-23 21:45 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
2007-09-23 19:57 d-------- C:\WINDOWS\provisioning
2007-09-23 19:57 d-------- C:\WINDOWS\peernet
2007-09-23 19:51 d-------- C:\WINDOWS\ServicePackFiles
2007-09-23 19:36 d-------- C:\WINDOWS\EHome
2007-09-23 19:25 11,776 --------- C:\WINDOWS\SYSTEM32\spnpinst.exe
2007-09-23 19:25 4,569 --------- C:\WINDOWS\SYSTEM32\secupd.dat
2007-09-23 17:21 614,912 --a------ C:\WINDOWS\SYSTEM32\h323msp.dll
2007-09-23 17:21 331,264 --a------ C:\WINDOWS\SYSTEM32\ipnathlp.dll
2007-09-23 17:21 40,960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-09-23 17:21 40,960 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\evtgprov.dll
2007-09-23 16:52 351,232 --a------ C:\WINDOWS\SYSTEM32\winhttp.dll
2007-09-23 16:52 18,944 --a------ C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2007-09-20 19:35 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-09-09 16:11 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-09-09 16:10 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-09-09 16:10 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-09-09 16:10 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-09-09 16:08 d-------- C:\WINDOWS\Internet Logs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-07 22:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-03 21:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-30 19:04 --------- d-----w C:\Program Files\iPod
2007-09-30 18:59 --------- d-----w C:\Program Files\Apple Software Update
2007-09-26 12:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-09-26 11:42 44,288 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-09-06 20:14 1,086,952 ----a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2007-09-02 21:11 --------- d-----w C:\Documents and Settings\Annie Fowler\Application Data\Roxio
2007-09-01 14:11 --------- d-----w C:\Program Files\Trend Micro
2007-09-01 02:39 --------- d-----w C:\Program Files\Spybot
2007-09-01 01:50 --------- d-----w C:\Program Files\Lavasoft
2007-09-01 01:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-01 01:45 --------- d-----w C:\Documents and Settings\Annie Fowler\Application Data\Lavasoft
2007-09-01 01:41 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-08-22 12:10 --------- d-----w C:\Program Files\Opera
2007-08-17 02:35 --------- d-----w C:\Program Files\QuickTime
2007-08-17 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-08-12 20:28 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2007-08-12 20:17 --------- d-----w C:\Program Files\Common Files\Cisco Systems
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2007-07-30 23:19 43,352 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2007-07-30 23:18 207,736 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-09-25 19:53]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"PCTVOICE"="pctspk.exe" [2001-08-17 22:36 C:\WINDOWS\SYSTEM32\pctspk.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-02 18:21]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-02 18:15]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-28 18:17 C:\WINDOWS\SYSTEM32\Ati2mdxx.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-26 07:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

C:\Documents and Settings\Annie Fowler\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 8.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E6TaskPanel]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
C:\Program Files\McAfee.com\Agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLTRYSVC"=2 (0x2)
"WANMiniportService"=2 (0x2)
"MCVSRte"=2 (0x2)
"McShield"=3 (0x3)
"iPodService"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)

R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 F-Secure BlackLight Sensor;F-Secure BlackLight Sensor;C:\DOCUME~1\ANNIEF~1\LOCALS~1\Temp\F-Secure\Anti-Virus\fsblsrv.exe

.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-09 16:55:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-09 16:57:45
.
--- E O F ---

3.3K Posts

October 10th, 2007 03:00

Your combofix log looks fine except that it is still showing an empty folder for Viewpoint:
C:\Documents and Settings\All Users\Application Data\Viewpoint
...and I thought sure we removed that once already. You can navigate to that folder and delete it safely.

Let's try to remove the two vundo installation files still remaining on the system.
  • Print out these instructions as we will be shuting down
  • every open window later in the fix.
  • Please download Process Explorer by Systernals and extract it to your desktop. Do nothing else with it now.
  • If you deleted killbox earlier, please download a Fresh Copy and extract it to your desktop. Do nothing else with it now.
  • Download FixVundo.reg and save it to your desktop. Do nothing else with it now.
  • Reboot the computer into Safe mode.
  • Double-click on procexp.exe (the Process Explorer that we downloaded earlier).
  • Scroll down and double-click on winlogon.exe to bring up the winlogon.exe properties screen, then click on the Threads tab at the top.
  • Once you see this screen click on each instance of ehiilm.ini found
  • and click on the kill button. If you see any files listed that are
    the same name but end with .bak or .dll or are the same name in reverse,
    you can kill those as well. (it would look like this: mliihe.ini,.dll. or .bak)
  • After you have killed all of the instances of the DLL (or other files mentioned above) under winlogon click on the OK button.
  • Now double-click on explorer.exe, select the Threads tab, and again click once on each instance of ehiilm.ini. Once they are highlighted click on the Kill button like you did previously. Since you have deleteded the BHO (O2) relating to this infection previously, you will not find this dll listed in this step and can move on.
  • When this is done, click on the OK button again.
  • Now double-click on the FixVundo.reg file that you downloaded earlier and allow it to merge the information.
  • Double-click on Killbox.exe that you downloaded and extracted earlier. Select
  • the delete on reboot option. Then enter the full path to the DLL into the file to delete field by copying and pasting the following:

    C:\WINDOWS\ehiilm.ini
    C:\WINDOWS\stuwvw.ini


  • Click the red circle with the white X and select Yes to the delete prompt and then Yes to reboot now. When your computer comes back up, scan at F-Secure again and post that new scan log.

Good Luck!

59 Posts

October 10th, 2007 13:00

I deleted ViewPoint previously, based on some cautionary information I read in another thread, using the Add/Remove Programs Control Panel. What remained behind must have been remnants. I deleted the entire folder.

I ran procexp.exe in Safe Mode. I didn't find any instances of ehiilm.ini, .dll, .bak or stuwvw.ini, .dll, .bak or the reverse spellng of these in either winlogon.exe ---> Properties ---> Threads or explorer.exe ---> Properties ---> Threads. But I continued working through the instructions anyway. I ran fixvundo.reg and then KillBox (see log appended below) followed by a reboot back into Normal Mode.

I then ran an F-Secure scan that identified no instances of ehiilm.ini or stuwvw.ini in C:\Windows (see log appended below). I also noticed a folder C:\!KillBox that contained renamed versions of ehiilm.ini and stuwvw.ini.

I'm hoping this means the fix was successful, but I await your assessment. A new HijackThis log is appended below. If this was the last of the pests and I'm now clean, I have a few final questions for you that I'll include in a separate post below.

KillBox log

Pocket Killbox version 2.0.0.881
Running on Windows XP as Annie Fowler(Administrator)
was started @ Wednesday, October 10, 2007, 7:13 AM

# 1 [Delete on Reboot]
Path = C:\WINDOWS\ehiilm.ini


# 2 [Delete on Reboot]
Path = C:\WINDOWS\stuwvw.ini

I Rebooted @ 7:17:01 AM
Killbox Closed(Exit) @ 7:17:02 AM
__________________________________________________

F-Secure scan report

Scanning Report
Wednesday, October 10, 2007 07:26:10 - 09:58:15
Computer name: DD41RK31
Scanning type: Scan target for viruses, rootkits, spyware
Target: C:\WINDOWS


--------------------------------------------------------------------------------

Result: 0 malware found

--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 128764
System: 0
Not scanned: 13
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
None: 0
Submitted: 0
Files not scanned:
C:\WINDOWS\TEMP\ZLT029CF.TMP
C:\WINDOWS\SYSTEM32\BIOS1.ROM
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.TMP.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG

--------------------------------------------------------------------------------

Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-10-07
F-Secure AVP: 7.0.171, 2007-10-10
F-Secure Orion: 1.2.37, 2007-10-10
F-Secure Blacklight: 1.0.64
F-Secure Pegasus: 1.19.0, 2007-09-02
Scanning options:
Scan all files
Scan inside archives
Use Advanced heuristics

--------------------------------------------------------------------------------

Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.

HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:40:22 AM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader

8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK

SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft

Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -

http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -

http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) -

http://support.f-secure.com/ols3beta/fscax.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware

2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware

7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: F-Secure BlackLight Sensor - Unknown owner -

C:\DOCUME~1\ANNIEF~1\LOCALS~1\Temp\F-Secure\Anti-Virus\fsblsrv.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 8093 bytes

59 Posts

October 10th, 2007 13:00

A few remaining questions:

(1) Can I now delete all the folders created by our most recent round of disinfection: C:\!KillBox, C:\qoobox, and C:\VundoFix Backups?

(2) For preventative scans, I've installed Ad-Aware 2007, AVG Anti-Spyware, AVG Anti-Virus, SpywareBlaster, and Spybot-S&D. What I can't find in any of the documentation or tutorials is recommendations on how often to scan with each of these. Could you make a recommendation for how frequently to scan with each of these?

(3) Referring back to my earlier question about OpenOffice 2.3, does this package contain any bundled malicious software or is it susceptible to security threats as far as you know?

Thanks!

3.3K Posts

October 11th, 2007 02:00

Good work...you're logs look clean.
Please follow through with the instructions from my post #78.

1) Yes. You can delete the Killbox folder and the application.
2) If you scan once a week, it would be sufficient.
3) Open Office does not contain any bundled malicious software to the best of my knowledge. I use it and have not experienced any problems. Is it susceptible to security threats?...if you keep your software and protective applications up to date, (including of course, Windows) you shouldn't have anything anywhere near to the extent that you had just been through.

59 Posts

October 11th, 2007 02:00

Thank you so much. I can't tell you how much I appreciate your help and patience. I hope that everyone realizes the tremendous value of this forum and appreciates the analysts like yourself who volunteer their time and expertise.

3.3K Posts

October 11th, 2007 13:00

Just very glad we could help you. Warmest regards,
No Events found!

Top