_______________________________________
Windows 2000 Professional
5.00.2195
Service Pack 4
_______________________________________
Mozilla FireFox
Version: 3.5.3
_______________________________________
Internet Explorer
Version: 6.0.2800.1106
_______________________________________
ESET NOD32 Antivirus 4.0.417.0
_______________________________________
SUPERAntiSpyware
_______________________________________
Malwarebytes' Anti-Malware
_______________________________________
SysInspector by ESET
_______________________________________
Avenger
_______________________________________
GMER
_______________________________________
ComboFix
_______________________________________
SpywareBlaster
version 4.2
______________________________________________________________
After re-starting SpywareBlaster I repeatedly notice under "SpywareBlaster Protection Status" on the "Restricted Sites" line the following message..........
"1 items have protection disabled".
The item is as follows:
ITEM NAME: AntiMalwareGuard
ADDRESS: antimalwareguard.com
This is happening despite the fact that I (earlier) in the same day already clicked on "Enable all protection" link in SpywareBlaster.
1) Why is this occurring?
2) What can I do to solve this problem?
3) Is this related to the following message that I keep seeing after running ComboFix as in the ComboFix Log:
"c:\winnt\system32\comres.dll . . . is infected!!"
4) Is this related to the messages that I receive after running Avenger?
[COLOR="Indigo"]"Error: file "C:\WINNT\system32\CF15096.exe" not found!
Deletion of file "C:\WINNT\system32\CF15096.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF25469.exe" not found!
Deletion of file "C:\WINNT\system32\CF25469.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9828.exe" not found!
Deletion of file "C:\WINNT\system32\CF9828.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF6762.exe" not found!
Deletion of file "C:\WINNT\system32\CF6762.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9462.exe" not found!
Deletion of file "C:\WINNT\system32\CF9462.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist"[/COLOR]
5) Is this related to the following results that I receive after opening GMER:
TYPE: "Service"
Name: "C:\WINNT\system32\clipsrv.exe? (*** hidden ***)"
Value: "(MANUAL)" ClipSrv
-------------------------------------------------------------------------
TYPE: "Service"
Name: "C:\WINNT\system32\MSTask.exe? (*** hidden ***)"
Value: "(AUTO)" Schedule
PS. GMER typically highlights the above results in RED.
________________________________________
ESET NOD32 antivirus repeatedly detects and quarantines the following:
Object name: “C:\DOCUME~1\v\LOCALS~1\Temp\Av-test.txt”
Reason: “Eicar test file”
1) Why does this thing keep coming back?
2) How can I permanently fix this problem?
_______________________________________________________________________
GMER Results:
GMER 1.0.15.15087 - http://www.gmer.net
Rootkit quick scan 2009-09-27 17:58:26
Windows 5.0.2195 Service Pack 4
Running: 0xt9fcyh.exe; Driver: C:\DOCUME~1\v\LOCALS~1\Temp\pfxiipob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
---- Processes - GMER 1.0.15 ----
Process hidden process (*** hidden *** ) 0
Process System (*** hidden *** ) 8
Process SMSS.EXE (*** hidden *** ) 148
Process CSRSS.EXE (*** hidden *** ) 172
Process WINLOGON.EXE (*** hidden *** ) 192
Process SERVICES.EXE (*** hidden *** ) 220
Process LSASS.EXE (*** hidden *** ) 232
Process svchost.exe (*** hidden *** ) 408
Process spoolsv.exe (*** hidden *** ) 432
Process DkService.exe (*** hidden *** ) 460
Process ekrn.exe (*** hidden *** ) 476
Process svchost.exe (*** hidden *** ) 492
Process firefox.exe (*** hidden *** ) 508
Process jqs.exe (*** hidden *** ) 544
Process nvsvc32.exe (*** hidden *** ) 580
Process regsvc.exe (*** hidden *** ) 616
Process stisvc.exe (*** hidden *** ) 664
Process WinMgmt.exe (*** hidden *** ) 772
Process mspmspsv.exe (*** hidden *** ) 800
Process svchost.exe (*** hidden *** ) 816
Process svchost.exe (*** hidden *** ) 828
Process explorer.exe (*** hidden *** ) 1120
Process WINWORD.EXE (*** hidden *** ) 1184
Process 0xt9fcyh.exe (*** hidden *** ) 1216
Process jusched.exe (*** hidden *** ) 1244
Process egui.exe (*** hidden *** ) 1248
Process robotaskbaricon (*** hidden *** ) 1260
---- Services - GMER 1.0.15 ----
Service C:\WINNT\system32\clipsrv.exe? (*** hidden *** ) [DISABLED] ClipSrv <-- ROOTKIT !!!
Service C:\WINNT\system32\MSTask.exe? (*** hidden *** ) Schedule <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----