Skip to content


Reply
Stone Esquire
angel7
Posts: 1
Registered: ‎02-21-2012

infected file keeps coming back

Yesterday my Trend was constantly blocking web threats from the same website (x-web.in) The number was over 200,000. I ran a full scan with Trend but nothing was found. I downloaded Malwarebytes and it found 2 problems. I clicked to remove them and after reboot the web threats stopped for a few minutes before resuming. I downloaded Combofix and ran a scan. It said it fixed the problem but when I ran another quick scan with Malwarebytes, it found the same 2 files again. And I get messages saying Malwarebytes has successfully blocked a malicious site (type:smileysurprised:utgoing process: coreserviceshell.exe

 

Oh, and Trend doesn't show the web threats anymore but I can't get the security report to open and it says there have been 0 web threats in the last month.

 

Here is the combofix log from today.  

 

ComboFix 12-02-21.02 - Ohnofan 02/21/2012  10:51:37.3.4 - x64 MINIMAL Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3895.2873 [GMT -6:00] Running from: c:\users\Ohnofan\Desktop\ComboFix.exe AV: Trend Micro Titanium Internet Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} FW: Trend Micro Firewall Booster *Disabled* {49A8346C-6900-54B6-B1B3-5F678736DDE9} SP: Trend Micro Titanium Internet Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}  * Created a new restore point . . (((((((((((((((((((((((((((((((((((((((   Other Deletions   ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\svchost.exe . . (((((((((((((((((((((((((   Files Created from 2012-01-21 to 2012-02-21  ))))))))))))))))))))))))))))))) . . 2012-02-21 16:57 . 2012-02-21 16:57 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-02-21 14:24 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{91B9214D-4E27-4BC2-BD30-6A8B2B336A94}\mpengine.dll 2012-02-20 15:53 . 2012-02-20 15:53 -------- d-----w- c:\windows\Sun 2012-02-20 15:49 . 2012-02-20 15:49 -------- d-----w- c:\users\Ohnofan\AppData\Roaming\Malwarebytes 2012-02-20 15:49 . 2012-02-20 15:49 -------- d-----w- c:\programdata\Malwarebytes 2012-02-20 15:49 . 2012-02-20 15:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-02-20 15:49 . 2011-12-10 21:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-02-17 23:54 . 2012-01-29 11:10 279656 ------w- c:\windows\system32\MpSigStub.exe 2012-02-16 21:58 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll 2012-02-16 21:58 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll 2012-02-16 21:58 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl 2012-02-16 21:58 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl 2012-02-16 21:58 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys 2012-02-16 21:58 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys 2012-02-16 21:57 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll 2012-02-16 21:57 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll . . . ((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-06 17:51 . 2011-06-25 01:51 45568 ----a-w- c:\windows\system32\iolobtdfg.exe 2012-01-06 17:51 . 2011-06-25 01:51 14848 ----a-w- c:\windows\system32\smrgdf.exe 2012-01-06 17:29 . 2011-06-25 01:51 2141832 ----a-w- c:\windows\system32\Incinerator64.dll 2012-01-06 17:29 . 2011-06-25 01:51 2083464 ----a-w- c:\windows\SysWow64\Incinerator32.dll 2011-12-18 06:01 . 2011-12-18 06:01 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-05 21:54 . 2010-12-11 19:08 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll . . (((((((((((((((((((((((((((((   SnapShot@2012-02-21_16.19.11   ))))))))))))))))))))))))))))))))))))))))) . 

Please use plain text.
Legendary Noble
malwarekiller
Posts: 3,967
Registered: ‎08-08-2011

Re: infected file keeps coming back

Welcome aboard! Posted Image

Never run combofix unless asked by knowledgeable person.

Download aswmbr.exe ( 1.8mb ) to your desktop. 

http://public.avast.com/~gmerek/aswMBR.htm
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan.

  • Click the [Scan] button to start scan

  • On completion of the scan click [Save log], save it to your desktop and post in your next reply.


—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.