Cannot get rid of Trojans

Messages
2,973
Name
Kev
Edit My Images
No
I have Vista and run Microsoft Security Essentials.
Today I got a message that MSE had detected problems and I should clean my computer. The Trojans it had found and suspended were:
win32/Sirefef.S
win64/Sirefef.E
win64/sirefef.D
win32/sirefef.P
win32/sirefef.J
win32/conedex.A

I let MSE do the cleanup and it reported that the computer was Ok but a few minutes later it flagged up the same trojans. I cleaned them again but they reappeared. I did a complete scan with MSE but while it was doing it the warning came up again about the same trojans and that they had been suspended. The full scan did not find anything else.

I then disconnected from the internet and did a full scan with the latest Malwarebytes free version and that found Backdoor.Agent which it cleaned and then restarted the computer. A quick scan with Malwarebytes still found Backdoor.Agent.

MIcrosoft recommended their Safety Scanner program to get rid of Backdooragent but this only found sirefef.S and got rid of it.

Another quick scan with Malewarebytes still showed Backdoor.Agent, it was removed by Malewarebytes, the computer restarted but it is still being picked up on a quick scan.
The Registry Value is HKCU\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon|shell and the Value:Winlogon|Shell

I am still getting the Trojans being shown and suspended by MSE

The only unusual things I had done on the computer today was to update Adobe Air and to visit some slovenian sites looking at holidays but I looked at the same sites yesterday and Tuesday.

Any advice? Would a restore help or the manufacturer's rescue disk?
 
Last edited:
Hi Suvv,

Firstly, don't use this computer for any online banking or to access any important information until you are sure the system is clean.

I'm a malware analyst at a site called TSF: Profile Link

If you want, I can go through the malware removal process with you at TSF, but I can't give proper support here. Alternatively, I'll give you some general steps that may or may not help you. Apologies for sounding like a second hand car salesman. :lol:

Whatever you do, back up your data now. Any important files/photos need to be backed up in the event the PC becomes unbootable.

Would a restore help or the manufacturer's rescue disk?

Sirefef is a serious detection, a system restore is unlikely to wipe it. The quickest and safest option is a complete reformat. If you have re-installation discs, make sure a full destructive reformat is done - restoring from the recovery partition or a system restore is unlikely to be sufficient.

Running any other tools without diagnosing the infection in full first is risky, lots of tools will chase this infection round in circles and will bork your internet connection - at worst you'll end up with an expensive paperweight.
 
Last edited by a moderator:
Before paying anyone to do it, can I suggest you start the PC in Safe mode and then run a full scan of MSE and Malwarebytes. I would also suggest downloading a copy of CCleaner (free, do a google), and let it also clean the PC (temp folder etc) also while in safe mode.
 
Before paying anyone to do it, can I suggest you start the PC in Safe mode and then run a full scan of MSE and Malwarebytes.

Unlikely to work with this infection. To clarify, in case you were referring to my post, TSF offers only free support.
 
Unlikely to work with this infection. To clarify, in case you were referring to my post, TSF offers only free support.

No mate, not you.

Just in case the OP panicked and decided to take it in somewhere.
 
All those little nasty's hide themselves in your system restore on your computer which is a protected area of your hard and because it is a protected area your anti virus/malware software etc. can not get rid of it properly.

Because of the above once you do a scan the little nasty's will just restore themselves from the protected system restore area of your hard drive.

What I would suggest you do first is turn off your system restore and then do an online virus scan, the reason you should do an online scan as opposed to using the software on your pc is simply because the software on your pc could very well be compromised by those little nasty's you have picked up.

Once you have turned off your system restore you can do an online virus scan at the following places:

Eset Online Scan

Symantec Security Check

Trend Micro Online Scan
 
Last edited:
Thanks for the replies.
Before I read the first reply where someguy201 said "Running any other tools without diagnosing the infection in full first is risky" I had run Malewarebytes quick scan again and it found Backdoor.Agent again. I deleted it and restarted the computer, I then did another Malwarebytes quick scan and it did not detect anything. I have checked the registry and the value Malewarebytes was reporting before for Backdoor.Agent, HKCU\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\W inlogon|shell and the Value:Winlogon|Shell, has gone.
MSE no longer brings up any problems, the computer has been running for about 1 hour connected to the internet.
Have the Trojans hidden themselves somewhere else or have I got rid of them? and how do I make sure?
I have not carried out any of the suggestions yet apart from running CCleaner and also Norton Utilites Cleanup (Not Nortons Anti-Virus), I thought I would let you know the latest before doing anything else.
I have all my data backed up in 3 places and I am using a different computer at the moment.
Kev
 
Last edited:
I would at the very least carry out an online virus scan before doing anything else for the reasons I suggested above.
 
What I would suggest you do first is turn off your system restore and then do an online virus scan,

Not yet ;). Always wipe the restore points after you've cleaned the computer. That way if something goes wrong you have something to get back to - it's better to have an infected computer than a doorstop.

Have the Trojans hidden themselves somewhere else or have I got rid of them? and how do I make sure?

I'm not sure how effective MSE and MBAM are at the moment removing this infection, it may be completely removed but there may be remnants left. Not all elements of this infection are visible, so if an AV program doesn't find them then you won't know they are still there.

If you want, run this tool: DDS, and post up the log it creates in your next reply. It will give an overview of your computer, and will usually indicate whether or not you're infected.

Also a good idea to run an ESET online scan.
 
Thanks for the replies.
I ran ESET which found and deleted what it called variants of : InstallCore.D (two of those) Kryptic.YEF (two of those) Sirefef.CH (one of those)

I have run DDs and have the DDS.txt file - how do I post it here please?
 
Just copy and paste DDS.txt into a post - don't need to see attach.txt at this time.
 
OK here it is:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by Kev at 14:44:48 on 2011-12-30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3071.1477 [GMT 0:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\Kev & Brenda\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Kev & Brenda\AppData\Local\Akamai\netsession_win.exe
C:\Users\Kev & Brenda\AppData\Roaming\Trusteer\Rapport\app\bin\RapportService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wuauclt.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=8&key=IESTART
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\google\google_bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [<NO NAME>]
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
mRunOnce: [NoIE4StubProcessing] c:\windows\system32\reg.exe delete "hklm\software\microsoft\active setup\Installed Components" /v "NoIE4StubProcessing" /f
mRunOnce: [WD Smartware Upgrader - Uninstall] cmd /c MsiExec.exe /X{10D331D2-A17B-47BF-BFA7-3F316736EC06} /qn
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\programdata\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Locate Spot on Map by GPS - c:\program files\opanda\iexif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\program files\opanda\iexif 2.3\IExifCom.htm
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7B280CC0-4422-4778-8DBA-D9C89B0B7CD2} : DhcpNameServer = 192.168.1.254
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kev\appdata\roaming\mozilla\firefox\profiles\1o60mi3d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.guardian.co.uk/|http://www.talktalk.co.uk/mail/?check_cookie=1|http://www.talkphotography.co.uk/forums/
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165648]
R1 MpKsl42175a5a;MpKsl42175a5a;c:\programdata\microsoft\microsoft antimalware\definition updates\{6d9779ba-915c-412e-ab5c-1b61905a6e62}\MpKsl42175a5a.sys [2011-12-30 29904]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\adobe\elements 9 organizer\PhotoshopElementsFileAgent.exe [2010-9-6 169408]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2010-9-15 21504]
R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files\norton utilities 15\tools\disk doctor\DiskDoctorSrv.exe [2011-9-23 1029480]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-9-15 21504]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-7-20 2214504]
R2 SpeedDiskService;Norton SpeedDisk Service;c:\program files\norton utilities 15\tools\speeddisk\SpeedDiskSrv.exe [2011-9-23 1037672]
R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2011-12-13 5554552]
R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2011-12-13 451960]
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2011-3-9 238592]
R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2011-3-9 1060864]
R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2011-3-9 484352]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2011-2-16 11520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-3 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;"c:\program files\google\google desktop search\googledesktop.exe" --> c:\program files\google\google desktop search\GoogleDesktop.exe [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-10-3 136176]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]
S3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [2011-9-23 128248]
S3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [2011-9-23 108800]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-30 11:24:07 -------- d-----w- c:\program files\ESET
2011-12-30 10:55:40 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6d9779ba-915c-412e-ab5c-1b61905a6e62}\MpKsl42175a5a.sys
2011-12-30 10:55:38 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6d9779ba-915c-412e-ab5c-1b61905a6e62}\offreg.dll
2011-12-29 20:21:08 6823496 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6d9779ba-915c-412e-ab5c-1b61905a6e62}\mpengine.dll
2011-12-29 17:08:48 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-29 17:08:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-22 20:04:18 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2011-12-13 13:23:06 -------- d-----w- c:\programdata\Wacom
2011-12-13 13:22:34 -------- d-----w- c:\program files\Bamboo Dock
2011-12-13 13:21:27 1107832 ----a-w- c:\windows\system32\Pen_Touch_Tablet.dll
2011-12-13 13:21:17 -------- d-----w- c:\program files\TabletPlugins
2011-12-13 13:20:28 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys
2011-12-13 13:19:36 14120 ----a-w- c:\windows\system32\drivers\wacomvhid.sys
2011-12-13 13:19:34 1156472 ----a-w- c:\windows\system32\Wintab32.dll
2011-12-13 13:19:34 1152888 ----a-w- c:\windows\system32\WacomMT.dll
2011-12-13 13:19:33 1369464 ----a-w- c:\windows\system32\Pen_Tablet.dll
2011-12-13 13:19:29 -------- d-----w- c:\program files\Tablet
2011-12-11 10:09:30 -------- d-----w- c:\program files\Amazon
.
==================== Find3M ====================
.
2011-12-18 09:36:58 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 14:29:02 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 14:29:02 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-09 15:47:26 106496 ----a-w- c:\windows\system32\ATL71.DLL
2011-10-06 16:42:56 92208 ----a-w- c:\windows\system\WING.DLL
2011-10-06 16:42:56 12800 ----a-w- c:\windows\system\WING32.DLL
.
============= FINISH: 14:45:04.03 ===============
 
Nothing pertinent in the DDS log. Your Java is out of date - you should update this and clear the Java cache.

There are other tools I would normally run in this situation, but this forum isn't the best place for it. No signs of active infection in the DDS log. Try this, it shouldn't take long:

Download aswMBR.exe and save it to your desktop.

Click Scan
Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply. Note - do NOT attempt any Fix yet.

Do not click Fix, or FixMBR regardless of what is detected. This tool is safe to scan with, but in the wrong circumstances fixing the MBR will brick your PC.

I would also run a scan with Trend Micro: Post 6.

Are you getting any symptoms other than the detections?
 
No other symptoms and I am not getting any auto detections from MSE now.
Here is the aswMBR log

aswMBR version 0.9.9.1124 Copyright(c) 2011 AVAST Software
Run date: 2011-12-30 15:14:49
-----------------------------
15:14:49.185 OS Version: Windows 6.0.6002 Service Pack 2
15:14:49.185 Number of processors: 2 586 0xF0D
15:14:49.186 ComputerName: PBDESKTOP UserName: Kev
15:14:51.333 Initialize success
15:15:10.235 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2
15:15:10.238 Disk 0 Vendor: ST3360320AS 3.AAM Size: 343399MB BusType: 3
15:15:10.251 Disk 0 MBR read successfully
15:15:10.254 Disk 0 MBR scan
15:15:10.258 Disk 0 Windows VISTA default MBR code
15:15:10.262 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 8192 MB offset 2048
15:15:10.277 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 335205 MB offset 16779264
15:15:10.293 Disk 0 scanning sectors +703279104
15:15:10.348 Disk 0 scanning C:\Windows\system32\drivers
15:15:15.299 Service scanning
15:15:15.949 Service MpKsl42175a5a c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6D9779BA-915C-412E-AB5C-1B61905A6E62}\MpKsl42175a5a.sys **LOCKED** 32
15:15:15.955 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
15:15:16.560 Modules scanning
15:15:21.811 Disk 0 trace - called modules:
15:15:21.836 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
15:15:21.842 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x850ac030]
15:15:21.846 3 CLASSPNP.SYS[8a3ad8b3] -> nt!IofCallDriver -> [0x84ee68d0]
15:15:21.852 5 acpi.sys[8069f6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-2[0x84f14390]
15:15:21.859 Scan finished successfully
15:16:14.742 Disk 0 MBR has been saved successfully to "C:\Users\Kev\Documents\MBR.dat"
15:16:14.752 The log file has been saved successfully to "C:\Users\Kev\Documents\aswMBR.txt"
 
Looking good. If Trend Micro doesn't find anything then you should be fine.

If the scan is clean, wipe your system restore points (Turn System Restore off and then back on), make sure Java is fully updated and the cache cleared, and run Ccleaner.
 
Trend Micro did not find anything. I wiped the restore points and then I removed Java and reinstalled the latest version, not sure how to clear the cache? and I have run Ccleaner as well as Norton Utilities Cleanup.

Any suggestions as to how I got infected? When I was on the Slovenian Tourist Office Holiday site I did get redirected to the property owners sites and clicked on some pictures to enlarge them, apart from that I have not done anything unusual.

Kev
 
Go to Control Panel, find the Java settings - should be either as it's own icon or in the Programs sub-menu. Click Settings in the General Tab, click Delete Files

May have been through outdated Java, or through something else on the site. Alternatively, if you use USB transfers between other peoples systems frequently then it may have been something like that. There are lots of vectors for infection - one reason that system security isn't only about common sense.

A browser add-on I would recommend is Web of Trust. It's a community based website rating tool that displays a colour code for links on Google and other sites. Green means the site is "safe", whereas red is unsafe/untrusted. It's not 100% accurate, but it provides useful information.

Here are some links I normally give out:

PC Safety & Security - What Do I Need?
Think Prevention
 
Thanks for all your help Will and the others who replied, very much appreciated.
I know it is a bit early to say I am completely free of all nasties but it certainly seems OK.
Let me know your favourite charity Will and I will drop a note or two in the next box I see :)

Kev
 
Back
Top