Hi,
I am not sure I went to the right place, but I found the file "Stu2" in C: Win: System32,,,, and this was file version it said: 5.1.2600.5512 (xpsp.080413-2113) Size: 25.5 KB (26,112 bytes)
When you say to rename it to "userinit.exe" do I right click the file and click on Rename? Then type in userinit.exe?
I will be doing the scan and sending..thanks
George
Here is the ComboFix results. I did wanna say that I ran Trojan Remover program about 2 hours ago or so.....anyway:
ComboFix 08-12-04.04 - George 2008-12-04 22:44:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.559 [GMT -5:00]
Running from: c:\documents and settings\George.GEORGE-6JXTPIR4\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\George.GEORGE-6JXTPIR4\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\jfidoj.exe
c:\windows\system32\iiffEvWP.dll.vir
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\jfidoj.exe
c:\windows\system32\iiffEvWP.dll.vir
----- BITS: Possible infected sites -----
hxxp://79.143.177.12
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.
2008-12-04 22:08 . 2008-09-12 11:12 69,168 --a------ c:\windows\system32\drivers\sbapifs.sys
2008-12-04 22:08 . 2008-09-12 11:12 13,360 --a------ c:\windows\system32\drivers\sbaphd.sys
2008-12-04 22:06 . 2008-12-04 22:06 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Sunbelt
2008-12-04 22:05 . 2008-12-04 22:05 <DIR> d-------- c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\Sunbelt
2008-12-04 22:04 . 2008-12-04 22:04 <DIR> d-------- c:\program files\Sunbelt Software
2008-12-04 22:04 . 2008-10-09 10:21 202,928 --a------ c:\windows\system32\drivers\sbtis.sys
2008-12-04 14:51 . 2008-01-04 20:34 23,920 --a------ c:\windows\system32\drivers\sskbfd.sys
2008-12-03 18:40 . 2008-07-14 05:09 212,728 --a------ c:\windows\CMDLIC.DLL
2008-12-03 18:40 . 2008-07-14 05:09 205,560 --a------ c:\windows\UNBOC.EXE
2008-12-03 18:40 . 2008-04-13 19:12 22,528 --a------ c:\windows\system32\wsock32.dlb
2008-12-03 18:39 . 2008-12-03 21:14 <DIR> d-------- c:\program files\Comodo
2008-12-03 06:14 . 2008-12-03 06:21 <DIR> d-------- c:\program files\SpeedBit Video Accelerator
2008-12-03 06:14 . 2008-12-03 06:14 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-11-30 18:12 . 2008-11-30 18:12 <DIR> d-------- c:\windows\system32\unknown
2008-11-28 06:58 . 2008-12-04 22:34 26,112 --a------ c:\windows\system32\stu2.exe
2008-11-26 20:09 . 2008-11-26 20:09 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-26 20:07 . 2008-11-26 20:50 <DIR> d-------- c:\program files\Sony Ericsson
2008-11-22 08:10 . 2008-12-04 18:58 <DIR> d-------- c:\program files\Webroot
2008-11-15 13:29 . 2008-11-15 13:29 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-11-15 13:29 . 2007-09-04 11:56 164,352 --a------ c:\windows\system32\unrar.dll
2008-11-15 08:21 . 2008-11-15 08:21 23,392 --a------ c:\windows\system32\nscompat.tlb
2008-11-15 08:21 . 2008-11-15 08:21 16,832 --a------ c:\windows\system32\amcompat.tlb
2008-11-15 08:02 . 2008-11-15 08:04 <DIR> d-------- c:\program files\WhatsRunning
2008-11-13 05:34 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-13 05:34 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-09 15:37 . 2008-10-03 12:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-09 15:37 . 2007-04-17 04:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-09 15:37 . 2007-03-08 00:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-09 15:37 . 2008-08-26 02:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-09 15:37 . 2008-08-26 02:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-09 15:37 . 2008-08-26 02:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-09 15:37 . 2008-08-26 02:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-09 15:37 . 2008-08-26 02:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-09 15:37 . 2008-08-25 03:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-09 00:00 . 2008-12-04 07:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-09 00:00 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-09 00:00 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-08 15:01 . 2008-11-08 15:01 <DIR> d-------- c:\program files\Windows Installer Clean Up
2008-11-05 11:46 . 2008-11-05 12:03 <DIR> d-------- c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 02:54 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2008-12-04 22:46 --------- d-----w c:\program files\Trojan Remover
2008-12-02 10:18 --------- d-----w c:\program files\MSECACHE
2008-11-19 11:28 --------- d-----w c:\program files\IrfanView
2008-11-02 20:12 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Viewpoint
2008-10-30 02:23 124 ----a-w c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\netstat.bat
2008-10-28 21:28 65,320 ----a-w c:\windows\system32\sbbd.exe
2008-10-26 14:57 --------- d-----w c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\Image Zone Express
2008-10-26 03:11 --------- d-----w c:\program files\MSXML 4.0
2008-10-24 20:17 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 09:09 92,464 ----a-w c:\windows\system32\drivers\SBREDrv.sys
2008-10-19 16:00 34,816 ----a-w c:\windows\system32\BGData.bin
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-12 17:50 --------- d-----w c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\Lavasoft
2008-10-11 17:10 --------- d-----w c:\program files\CCleaner
2008-10-11 16:46 --------- d-----w c:\documents and settings\Default User.WINDOWS\Application Data\DivX
2008-10-10 22:26 --------- d-----w c:\documents and settings\George.GEORGE-6JXTPIR4\Application Data\Uniblue
2008-10-10 11:29 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Matrox
2008-10-08 10:46 --------- d-----w c:\program files\Free Window Registry Repair
2008-10-06 20:02 --------- d-----w c:\program files\QuickTime
2008-10-06 20:00 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-05-30 18:37 97,916 ----a-w c:\program files\dxupdate.cab
2008-05-30 18:36 4,165,878 ----a-w c:\program files\Apr2006_MDX1_x86_Archive.cab
2008-05-30 18:36 13,267,416 ----a-w c:\program files\dxnt.cab
2008-05-30 18:36 1,805,306 ----a-w c:\program files\Nov2007_d3dx9_36_x64.cab
2008-05-30 18:36 1,803,408 ----a-w c:\program files\AUG2007_d3dx9_35_x64.cab
2008-05-30 18:34 528,392 ----a-w c:\program files\DXSETUP.exe
2008-02-04 17:02 228,207 ----a-w c:\program files\address book.WAB
2008-02-03 18:48 54,784 --sha-w c:\program files\Thumbs.db
2007-08-01 21:12 1,156,096 ----a-w c:\program files\iview400_setup.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-04_13.05.30.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-05 01:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\CONFLICT.3\FP_AX_CAB_INSTALLER.exe
+ 2008-10-05 01:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\CONFLICT.4\FP_AX_CAB_INSTALLER.exe
+ 2008-10-05 01:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\CONFLICT.5\FP_AX_CAB_INSTALLER.exe
+ 2008-10-05 01:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\CONFLICT.6\FP_AX_CAB_INSTALLER.exe
- 2008-11-22 18:13:04 297,086 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\ARPPRODUCTICON.exe
+ 2008-12-05 03:04:30 297,086 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\ARPPRODUCTICON.exe
- 2008-11-22 18:13:04 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut2_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2008-12-05 03:04:30 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut2_339C927BB4B547F9804FDF51F01D2D57.exe
- 2008-11-22 18:13:04 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut21_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2008-12-05 03:04:30 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut21_339C927BB4B547F9804FDF51F01D2D57.exe
- 2008-11-29 20:30:12 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-05 02:36:58 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-29 20:30:12 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-05 02:36:58 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-14 00:12:38 26,112 -c--a-w c:\windows\system32\dllcache\userinit.exe
- 2008-12-04 14:46:42 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-12-05 03:13:34 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-11-28 11:58:19 10,752 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-14 00:12:38 26,112 ----a-w c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-28 955688]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 14:49 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Matrox Powerdesk]
--a------ 2008-10-13 17:28 684032 c:\windows\system32\PDesk\pdesk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-07-21 15:39 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 avgntmgr;avgntmgr;c:\windows\system32\DRIVERS\avgntmgr.sys [2008-10-22 22336]
R1 avgntdd;avgntdd;c:\windows\system32\DRIVERS\avgntdd.sys [2008-10-22 45376]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2008-12-04 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2008-12-04 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;"c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe" [2008-10-28 886056]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2008-12-04 69168]
S1 streamm;streamm; []
S3 SBRE;SBRE;\??\c:\windows\System32\drivers\SBREdrv.sys [2008-10-23 92464]
S3 UtilNT;UtilNT;\??\c:\windows\system32\drivers\UtilNT.sys [2008-10-09 5533]
.
Contents of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart\ErrorSmart.exe []
2008-12-02 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart []
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Windows Defender - c:\program files\Windows Defender\MSASCui.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-04 22:48:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3100)
c:\program files\Sunbelt Software\VIPRE\oehook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-12-04 22:53:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-05 03:53:07
ComboFix2.txt 2008-12-04 18:07:11
Pre-Run: 11,404,541,952 bytes free
Post-Run: 11,579,846,656 bytes free
213 --- E O F --- 2008-12-03 23:28:19