[RESOLVED] Broni- I need help again.
Hi Broni,
Thank you, again, for helping me with my computer, but now I need help for my sons’ computer.
I have a cable modem, that goes to a Linksys router, then to my computer, the computer that my boys share, my daughter’s computer, and a network shared wireless printer. I know nothing about setting up the network, firewalls, and setting up security software, but, the router has an enabled firewall, all computers are running McAfee anti-virus and firewall software, Webroot Spy Sweeper, CCleaner and Malwarebytes is frequently run.
I may have all of the correct security measures, but it is entirely possible that I have set up horrible settings and such, and don’t even know it.
One of my sons’ email account has started sending spoofed emails to all of his contacts. It is various online drug and internet sex site promotions and links. It has caused major embarrassment, as this material was sent to his grandparents, coaches, teachers etc.
I contacted MSN, and they instructed me to change his password, run anti-virus and maleware programs, and to run Microsoft’s Free Malicious Software Removal Tool. Nothing was discovered or removed.
I have done this, but these spoofed emails still go out. I know that they are not physically going out from their computer, as these messages do not appear in any sent folders, but his contact list is still being accessed somehow. So, as a temp fix, I deleted all of his contacts from his address book, and added a few bogus addresses. ( ex: [email protected], etc) He does still frequently receive messages from the MSN mailmasters that these messages failed to deliver, but no more mail is going to real people.
I have just now followed the steps listed in the above stickey, and here are the results:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7393
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/6/2011 12:29:50 PM
mbam-log-2011-08-06 (12-29-49).txt
Scan type: Full scan (C:\|)
Objects scanned: 240454
Time elapsed: 1 hour(s), 30 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--------------------------------------------------------------------------
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-06 14:52:57
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3160812AS rev.3.ADH
Running: download.exe; Driver: C:\DOCUME~1\KENHEN~1\LOCALS~1\Temp\kftcypod.sys
---- System - GMER 1.0.15 ----
SSDT 865D6AF8 ZwAllocateVirtualMemory
SSDT 86572BF8 ZwCreateKey
SSDT 8658BF30 ZwCreateProcess
SSDT 865D6FA8 ZwCreateProcessEx
SSDT 865D6DC8 ZwCreateThread
SSDT 865AC130 ZwDeleteKey
SSDT 8658BFA8 ZwDeleteValueKey
SSDT 865D6B70 ZwQueueApcThread
SSDT 865D6A08 ZwReadVirtualMemory
SSDT 865AC0B8 ZwRenameKey
SSDT 865D6C60 ZwSetContextThread
SSDT 865E7340 ZwSetInformationKey
SSDT 865D6EB8 ZwSetInformationProcess
SSDT 865D6CD8 ZwSetInformationThread
SSDT 865E72C8 ZwSetValueKey
SSDT 865D6E40 ZwSuspendProcess
SSDT 865D6BE8 ZwSuspendThread
SSDT 865D6F30 ZwTerminateProcess
SSDT 865D6D50 ZwTerminateThread
SSDT 865D6A80 ZwWriteVirtualMemory
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF736A29E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF736A1FC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF736A1D4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF736A1E8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF736A274]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF736A2B4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF736A288]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2CA1 8050453D 5 Bytes [BF, 58, 86, A8, 6F] {MOV EDI, 0x6fa88658}
.text ntkrnlpa.exe!ZwCallbackReturn + 2CB8 80504554 2 Bytes [C8, 6D]
.text ntkrnlpa.exe!ZwCallbackReturn + 2EB4 80504750 2 Bytes [70, 6B] {JO 0x6d}
.text ntkrnlpa.exe!ZwCallbackReturn + 2F38 805047D4 2 Bytes [60, 6C] {PUSHA ; INSB }
.text ntkrnlpa.exe!ZwCallbackReturn + 2FD8 80504874 2 Bytes [40, 6E] {INC EAX; OUTSB }
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtCreateFile 7C90D0AE 3 Bytes JMP 00910FEF
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtCreateFile + 4 7C90D0B2 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtCreateProcess 7C90D14E 3 Bytes JMP 00910000
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtCreateProcess + 4 7C90D152 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 3 Bytes JMP 00910FD4
.text C:\WINDOWS\system32\svchost.exe[260] ntdll.dll!NtProtectVirtualMemory + 4 7C90D6F2 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0090000A
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009000A2
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0090007D
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0090006C
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00900FAF
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00900FD4
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009000B3
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00900F77
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00900F35
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009000CE
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00900F24
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00900051
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00900F88
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00900040
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00900025
.text C:\WINDOWS\system32\svchost.exe[260] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00900F50
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C00039
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C0006F
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C00FDE
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C00FEF
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C00FB2
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C00000
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C00054
.text C:\WINDOWS\system32\svchost.exe[260] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C00FC3
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BF0FC3
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BF000C
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BF003A
.text C:\WINDOWS\system32\svchost.exe[260] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BF001D
.text C:\WINDOWS\system32\svchost.exe[260] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00920FE5
.text C:\WINDOWS\system32\svchost.exe[260] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00920000
.text C:\WINDOWS\system32\svchost.exe[260] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00920011
.text C:\WINDOWS\system32\svchost.exe[260] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 00920FB6
.text C:\WINDOWS\system32\svchost.exe[260] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\WINDOWS\System32\svchost.exe[360] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00F80FEF
.text C:\WINDOWS\System32\svchost.exe[360] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00F8001E
.text C:\WINDOWS\System32\svchost.exe[360] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F80FDE
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F70000
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F70FCA
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F700C9
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F700A2
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F70091
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F7006C
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F70112
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F700F7
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F70159
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F7013E
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F70FAF
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F70FE5
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F70025
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F700DA
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F70051
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F70040
.text C:\WINDOWS\System32\svchost.exe[360] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F70123
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F6001B
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F6004A
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F60FCA
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F60FEF
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F60F8D
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F60000
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F60F9E
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [16, 89]
.text C:\WINDOWS\System32\svchost.exe[360] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F60FB9
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F50FA8
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F50FC3
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F50FEF
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F5000C
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F50FD4
.text C:\WINDOWS\System32\svchost.exe[360] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F50029
.text C:\WINDOWS\System32\svchost.exe[360] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F40FEF
.text C:\WINDOWS\system32\svchost.exe[416] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B50000
.text C:\WINDOWS\system32\svchost.exe[416] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B50FD4
.text C:\WINDOWS\system32\svchost.exe[416] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B50FEF
.text C:\WINDOWS\system32\svchost.exe[416] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B40FE5