Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Jul 2 2008, 08:43 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
hijackthis.log ( 10.91k )
Number of downloads: 4Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:34:50 PM, on 7/2/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\MBK\MBackMonitor.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\SiteAdvisor\6261\SAService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\SiteAdvisor\6261\SiteAdv.exe C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\PeerGuardian2\pg2.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Orb Networks\Orb\bin\Orb.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Safari\Safari.exe C:\Documents and Settings\Jeff\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {018B27FF-E05F-4CB5-8763-540CB3FD457A} - C:\WINDOWS\system32\ljJAQHwu.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6D1C4CE7-84C8-45FE-B533-12CAB66BC4A5} - C:\WINDOWS\system32\nnnnMExX.dll O2 - BHO: (no name) - {A39EDCF9-E13C-45BE-81A1-4447CE2FCE5F} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: (no name) - {B7417220-F191-4347-A546-4FE76502D31C} - (no file) O2 - BHO: (no name) - {FBA32D54-ADFD-4DD9-9B0C-45E0138E3FD7} - (no file) O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Orb] C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite...vex-2.0.6.0.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128216977417 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128217886687 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin...ows-i586-jc.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://printinc.webex.com/client/v_mywebex...bex/ieatgpc.cab O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://connect2.pb.com/dana-cached/setup/J...perSetupSP1.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...598/mcfscan.cab O20 - Winlogon Notify: ljJAQHwu - C:\WINDOWS\SYSTEM32\ljJAQHwu.dll O23 - Service: McAfee Application Installer Cleanup (0140431215024895) (0140431215024895mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\014043~1.EXE O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe -- End of file - 11170 bytes |
|
|
|
Jul 3 2008, 08:37 AM
Post
#2
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 2,251 Joined: 12-December 05 From: Belgium Member No.: 44,294 |
Hello Emptyclip and welcome to BleepingComputer,
1. * Clean your Cache and Cookies in IE:
Doubleclick mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. 3. Please visit this webpage for instructions for downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix Please ensure you read this guide carefully and install the Recovery Console first (not for Windows Vista users !). The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you. (WinXP SP3 users, please download the appropriate SP2 file, Home or Pro, to install the RC) In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial. It must be saved directly to your desktop. Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze. Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. If you have any questions along the way, STOP and ask them before proceeding !! Greetings, Thunder -------------------- Whatever happens, make believe it was intended to ...
----------------------------------------------------------------------- - If I have helped you in any way, please consider a donation to help me continue the fight against malware.----------------------------------------------------------------------- Stand Up & Be Counted --> <-- And make a difference |
|
|
|
Jul 3 2008, 10:03 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
Here is my new hijack this log, thanks for the help
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:37:26 PM, on 7/3/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\SiteAdvisor\6261\SiteAdv.exe C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\PeerGuardian2\pg2.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\MBK\MBackMonitor.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\SiteAdvisor\6261\SAService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Documents and Settings\Jeff\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {018B27FF-E05F-4CB5-8763-540CB3FD457A} - (no file) O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll O2 - BHO: {ddbab976-f0a4-44a8-7d64-d7e78d940dc2} - {2cd049d8-7e7d-46d7-8a44-4a0f679babdd} - C:\WINDOWS\system32\znsecb.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6D1C4CE7-84C8-45FE-B533-12CAB66BC4A5} - (no file) O2 - BHO: (no name) - {A39EDCF9-E13C-45BE-81A1-4447CE2FCE5F} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: (no name) - {B7417220-F191-4347-A546-4FE76502D31C} - (no file) O2 - BHO: (no name) - {FBA32D54-ADFD-4DD9-9B0C-45E0138E3FD7} - (no file) O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Orb] C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite...vex-2.0.6.0.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1128216977417 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128217886687 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin...ows-i586-jc.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://printinc.webex.com/client/v_mywebex...bex/ieatgpc.cab O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://connect2.pb.com/dana-cached/setup/J...perSetupSP1.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...598/mcfscan.cab O20 - Winlogon Notify: ljJAQHwu - C:\WINDOWS\ O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe -- End of file - 10937 bytes This post has been edited by emptyclip: Jul 3 2008, 10:04 PM |
|
|
|
Jul 3 2008, 10:06 PM
Post
#4
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
Here is my combo fix log also spybot asked me to allow a change caller scr handler is that ok.
ComboFix 08-07-03.1 - Jeff 2008-07-03 21:47:43.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.124 [GMT -4:00] Running from: C:\Documents and Settings\Jeff\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Jeff\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe * Created a new restore point * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM3f202ed7.txt C:\WINDOWS\pskt.ini C:\WINDOWS\system32\afilsl.dll C:\WINDOWS\system32\bcdywbei.dll C:\WINDOWS\system32\fiynnhak.dll C:\WINDOWS\system32\iebwydcb.ini C:\WINDOWS\system32\iylbrgms.dll C:\WINDOWS\system32\ljJAQHwu.dll C:\WINDOWS\system32\lovmudlj.dll C:\WINDOWS\system32\lpxxekvp.dll C:\WINDOWS\system32\mhgsha.dll C:\WINDOWS\system32\nnnnMExX.dll C:\WINDOWS\system32\qlvcmz.dll C:\WINDOWS\system32\wkhldcys.dll C:\WINDOWS\system32\XxEMnnnn.ini C:\WINDOWS\system32\XxEMnnnn.ini2 C:\WINDOWS\system32\znsecb.dll . ((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 ))))))))))))))))))))))))))))))) . 2008-07-03 21:03 . 2008-07-03 21:03 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\Malwarebytes 2008-07-03 21:02 . 2008-07-03 21:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-03 21:02 . 2008-07-03 21:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-03 21:02 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-03 21:02 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-03 09:42 . 2008-07-03 10:09 <DIR> d-------- C:\VundoFix Backups 2008-07-01 20:41 . 2008-07-02 22:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-06-30 21:01 . 2008-06-30 21:01 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-30 21:01 . 2008-06-30 21:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-30 21:00 . 2008-06-30 21:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-06-30 16:54 . 2008-06-30 17:03 <DIR> d-------- C:\Documents and Settings\Administrator 2008-06-30 02:55 . 2008-06-30 02:55 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee 2008-06-29 20:25 . 2008-07-01 21:27 110,446 --a------ C:\WINDOWS\BM3f202ed7.xml 2008-06-29 13:54 . 2008-06-29 13:54 <DIR> d-------- C:\Documents and Settings\Debbie\Application Data\McAfee 2008-06-29 13:53 . 2008-06-29 13:53 <DIR> d-------- C:\Documents and Settings\Debbie\Application Data\SiteAdvisor 2008-06-29 00:34 . 2008-06-29 18:44 244 --a------ C:\WINDOWS\wininit.ini 2008-06-28 23:24 . 2008-06-28 23:24 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\McAfee 2008-06-19 11:49 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll 2008-06-11 18:19 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 18:19 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys 2008-06-09 15:51 . 2008-06-09 15:51 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\Snapfish . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-04 02:07 --------- d-----w C:\Program Files\PeerGuardian2 2008-07-03 14:12 --------- d-----w C:\Program Files\McAfee 2008-07-03 14:10 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor 2008-07-02 00:42 --------- d-----w C:\Program Files\Google 2008-06-30 20:34 --------- d-----w C:\Program Files\ffdshow 2008-06-29 03:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-06-29 03:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee 2008-06-22 23:33 --------- d-----w C:\Documents and Settings\Jeff\Application Data\SiteAdvisor 2008-06-22 18:05 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\SiteAdvisor 2008-06-19 23:10 --------- d-----w C:\Program Files\Common Files\McAfee 2008-06-19 15:55 --------- d-----w C:\Program Files\SiteAdvisor 2008-06-19 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor 2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-12 00:46 --------- d-----w C:\Program Files\winpwn 2008-06-09 19:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser 2008-06-03 16:41 --------- d-----w C:\Documents and Settings\User_01\Application Data\SiteAdvisor 2008-06-03 12:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL 2008-06-03 12:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS 2008-05-29 12:02 --------- d-----w C:\Documents and Settings\Jeff\Application Data\Elaborate Bytes 2008-05-29 00:20 --------- d-----w C:\Documents and Settings\Jeff\Application Data\ZoomBrowser EX 2008-05-29 00:03 --------- d-----w C:\Program Files\Canon 2008-05-28 23:58 --------- d-----w C:\Program Files\Common Files\Canon 2008-05-28 00:06 --------- d-----w C:\Documents and Settings\Jeff\Application Data\SlySoft 2008-05-26 18:00 --------- d-----w C:\Program Files\MSTpscre 2008-05-26 17:47 --------- d-----w C:\Program Files\SlySoft 2008-05-26 17:44 --------- d-----w C:\Program Files\Elaborate Bytes 2008-05-13 02:00 --------- d-----w C:\Program Files\McAfee.com 2008-05-12 20:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks 2008-05-08 23:06 --------- d-----w C:\Program Files\Orb Networks 2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll 2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll 2008-04-14 00:11 376,832 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msinfo.dll 2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll 2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll 2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll 2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll 2006-09-08 22:44 25,600 ----a-w C:\Documents and Settings\Jeff\usbsermptxp.sys 2006-09-08 22:44 22,768 ----a-w C:\Documents and Settings\Jeff\usbsermpt.sys . ------- Sigcheck ------- 2005-05-25 15:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$hf_mig$\KB893066\SP2GDR\tcpip.sys 2005-05-25 15:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys 2006-01-13 13:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys 2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys 2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\TCPIP.SYS 2008-06-03 08:41 361344 8e036eec565910417ea020ce0962aa24 C:\WINDOWS\system32\dllcache\TCPIP.SYS 2008-06-03 08:41 361344 8e036eec565910417ea020ce0962aa24 C:\WINDOWS\system32\drivers\TCPIP.SYS . ((((((((((((((((((((((((((((( snapshot@2008-06-29_21.03.53.64 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-30 00:16:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-04 02:00:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2008-07-03 22:25:47 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2008-07-03 22:25:47 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2008-07-03 22:25:47 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2008-04-29 15:19:50 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys + 2008-04-29 15:19:54 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys + 2008-04-29 15:20:00 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys + 2008-05-16 15:58:04 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe - 2008-05-29 23:35:11 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe + 2008-05-29 20:35:12 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] "Orb"="C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [2008-03-31 21:54 507904] "AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2008-05-27 15:35 499712] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 20:41 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-31 00:40 57344] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992] "SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-24 16:28 35992] "McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576] "McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952] "MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480] "RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2005-02-04 09:14 1695744] "CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 09:47 57344] C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\ Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 13:57:16 2913584] [HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au] "NoAutoUpdate"= 1 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk] backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk] backup=C:\WINDOWS\pss\DataViz Inc Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk] backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Jeff^Start Menu^Programs^Startup^Desktop Manager.lnk] backup=C:\WINDOWS\pss\Desktop Manager.lnkStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\emoze HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\eMule\\emule.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\Xpress Mail\\Personal Edition\\Connection.exe"= "C:\\Program Files\\Internet Explorer\\iexplore.exe"= "C:\\Program Files\\uTorrent\\utorrent.exe"= "C:\\Program Files\\BitLord\\BitLord.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Touchpad Pro\\Touchpad Media Server Trial\\TouchpadMediaServer.exe"= "C:\\Program Files\\TightVNC\\WinVNC.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"= "C:\\Program Files\\Orb Networks\\Orb\\bin\\OrbTray.exe"= "C:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= . Contents of the 'Scheduled Tasks' folder "2008-07-01 14:37:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-06-15 05:23:09 C:\WINDOWS\Tasks\McDefragTask.job" - C:\WINDOWS\system32\defrag.exe "2008-06-01 05:12:07 C:\WINDOWS\Tasks\McQcTask.job" - c:\program files\mcafee\mqc\QcConsol.exe.4158 0 . - - - - ORPHANS REMOVED - - - - BHO-{018B27FF-E05F-4CB5-8763-540CB3FD457A} - (no file) BHO-{2cd049d8-7e7d-46d7-8a44-4a0f679babdd} - (no file) BHO-{6D1C4CE7-84C8-45FE-B533-12CAB66BC4A5} - (no file) BHO-{A39EDCF9-E13C-45BE-81A1-4447CE2FCE5F} - (no file) BHO-{B7417220-F191-4347-A546-4FE76502D31C} - (no file) BHO-{FBA32D54-ADFD-4DD9-9B0C-45E0138E3FD7} - (no file) Notify-ljJAQHwu - (no file) ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-03 22:03:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe -> C:\Program Files\SiteAdvisor\6261\saHook.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\MBK\MBackMonitor.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe C:\Program Files\McAfee\MPF\MpfSrv.exe C:\Program Files\McAfee\MSK\msksrver.exe C:\Program Files\SiteAdvisor\6261\SAService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Zune\ZuneNss.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Orb Networks\Orb\bin\Orb.exe . ************************************************************************** . Completion time: 2008-07-03 22:46:28 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-04 02:44:52 ComboFix2.txt 2008-06-30 18:03:44 ComboFix3.txt 2008-06-30 01:07:33 Pre-Run: 22,041,538,560 bytes free Post-Run: 22,007,681,024 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=signature(1)disk(1)rdisk(0)partition(1)\WINDOWS [operating systems] signature(1)disk(1)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 265 --- E O F --- 2008-06-21 07:02:16 |
|
|
|
Jul 3 2008, 10:09 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
I cant post the malware it is too long so ill upload it
Attached File(s)
|
|
|
|
Jul 4 2008, 07:26 AM
Post
#6
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 2,251 Joined: 12-December 05 From: Belgium Member No.: 44,294 |
Hello Emptyclip,
This does definitely look a lot better. Did you disable Windows Update yourself ? Let's clean up some more : Open Notepad - don't use any other texteditor than Notepad or the script will fail ! Copy/paste the bold, blue text below into an empty notepad window:
C:\WINDOWS\BM3f202ed7.xml Folder:: C:\VundoFix Backups Then drag the CFScript into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog. Are you still having problems ? Greetings, Thunder -------------------- Whatever happens, make believe it was intended to ...
----------------------------------------------------------------------- - If I have helped you in any way, please consider a donation to help me continue the fight against malware.----------------------------------------------------------------------- Stand Up & Be Counted --> <-- And make a difference |
|
|
|
Jul 4 2008, 10:39 AM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
I did not stop windows update, and it seems that the pop ups are gone, but the computer is still a little sluggish im going to do the next step you suggested and i will post the log. i appreciate your help Thunder.
|
|
|
|
Jul 4 2008, 11:35 AM
Post
#8
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 2-July 08 Member No.: 220,098 |
Here are the 2 new logs ComboFix 08-07-03.1 - Jeff 2008-07-04 11:45:46.4 - NTFSx86 Running from: C:\Documents and Settings\Jeff\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Jeff\Desktop\CFScript.txt * Created a new restore point * Resident AV is active FILE :: C:\WINDOWS\BM3f202ed7.xml . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\VundoFix Backups C:\VundoFix Backups\addmorefiles.txt C:\VundoFix Backups\NCTAudioCDGrabber2.dll.bad C:\VundoFix Backups\NCTAudioFile2.dll.bad C:\VundoFix Backups\NCTAudioPlayer2.dll.bad C:\VundoFix Backups\NCTAudioRecord2.dll.bad C:\VundoFix Backups\NCTAVIFile.dll.bad C:\VundoFix Backups\NCTQuickTimeFile.dll.bad C:\VundoFix Backups\NCTVideoCoreM.dll.bad C:\VundoFix Backups\NCTWMAFile2.dll.bad C:\WINDOWS\BM3f202ed7.xml . ((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 ))))))))))))))))))))))))))))))) . 2008-07-04 03:55 . 2008-07-04 03:55 <DIR> d-------- C:\WINDOWS\LastGood 2008-07-03 21:03 . 2008-07-03 21:03 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\Malwarebytes 2008-07-03 21:02 . 2008-07-03 21:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-03 21:02 . 2008-07-03 21:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-03 21:02 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-03 21:02 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-01 20:41 . 2008-07-03 23:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-06-30 21:01 . 2008-06-30 21:01 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-30 21:01 . 2008-06-30 21:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-30 21:00 . 2008-06-30 21:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-06-30 16:54 . 2008-06-30 17:03 <DIR> d-------- C:\Documents and Settings\Administrator 2008-06-30 02:55 . 2008-06-30 02:55 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee 2008-06-29 13:54 . 2008-06-29 13:54 <DIR> d-------- C:\Documents and Settings\Debbie\Application Data\McAfee 2008-06-29 13:53 . 2008-06-29 13:53 <DIR> d-------- C:\Documents and Settings\Debbie\Application Data\SiteAdvisor 2008-06-29 00:34 . 2008-06-29 18:44 244 --a------ C:\WINDOWS\wininit.ini 2008-06-28 23:24 . 2008-06-28 23:24 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\McAfee 2008-06-19 11:49 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll 2008-06-11 18:19 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 18:19 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys 2008-06-09 15:51 . 2008-06-09 15:51 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\Snapfish . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-04 15:53 --------- d-----w C:\Program Files\PeerGuardian2 2008-07-04 07:55 --------- d-----w C:\Program Files\McAfee 2008-07-03 14:10 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor 2008-07-02 00:42 --------- d-----w C:\Program Files\Google 2008-06-30 20:34 --------- d-----w C:\Program Files\ffdshow 2008-06-29 03:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-06-29 03:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee 2008-06-22 23:33 --------- d-----w C:\Documents and Settings\Jeff\Application Data\SiteAdvisor 2008-06-22 18:05 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\SiteAdvisor 2008-06-19 23:10 --------- d-----w C:\Program Files\Common Files\McAfee 2008-06-19 15:55 --------- d-----w C:\Program Files\SiteAdvisor 2008-06-19 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor 2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-12 00:46 --------- d-----w C:\Program Files\winpwn 2008-06-09 19:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser 2008-06-03 16:41 --------- d-----w C:\Documents and Settings\User_01\Application Data\SiteAdvisor 2008-06-03 12:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL 2008-06-03 12:41 361,344 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS 2008-05-29 12:02 --------- d-----w C:\Documents and Settings\Jeff\Application Data\Elaborate Bytes 2008-05-29 00:20 --------- d-----w C:\Documents and Settings\Jeff\Application Data\ZoomBrowser EX 2008-05-29 00:03 --------- d-----w C:\Program Files\Canon 2008-05-28 23:58 --------- d-----w C:\Program Files\Common Files\Canon 2008-05-28 00:06 --------- d-----w C:\Documents and Settings\Jeff\Application Data\SlySoft 2008-05-26 18:00 --------- d-----w C:\Program Files\MSTpscre 2008-05-26 17:47 --------- d-----w C:\Program Files\SlySoft 2008-05-26 17:44 --------- d-----w C:\Program Files\Elaborate Bytes 2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-05-13 02:00 --------- d-----w C:\Program Files\McAfee.com 2008-05-12 20:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks 2008-05-08 23:06 --------- d-----w C:\Program Files\Orb Networks 2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll 2008-04-14 09:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll 2008-04-14 09:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe 2008-04-14 09:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll 2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin 2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe 2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll 2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll 2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll 2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll 2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll 2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll 2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll 2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys 2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe 2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys 2008-04-13 18:43 9,728 ----a-w C:\WINDOWS\system32\comsdupd.exe 2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe 2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll 2008-04-13 18:31 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe 2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll 2008-04-13 18:14 76,800 ----a-w C:\WINDOWS\system32\msshavmsg.dll 2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll 2008-04-13 17:39 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll 2008-04-13 17:39 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll 2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll 2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll 2008-04-13 17:27 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll 2008-04-13 17:26 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll 2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll 2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll 2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll 2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll 2008-04-13 17:03 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll 2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll 2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll 2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll 2008-04-13 16:22 48,128 ----a-w C:\WINDOWS\system32\inetres.dll 2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll 2006-09-08 22:44 25,600 ----a-w C:\Documents and Settings\Jeff\usbsermptxp.sys 2006-09-08 22:44 22,768 ----a-w C:\Documents and Settings\Jeff\usbsermpt.sys . ------- Sigcheck ------- 2005-05-25 15:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$hf_mig$\KB893066\SP2GDR\tcpip.sys 2005-05-25 15:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys 2006-01-13 13:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys 2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys 2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\TCPIP.SYS 2008-06-03 08:41 361344 8e036eec565910417ea020ce0962aa24 C:\WINDOWS\system32\dllcache\TCPIP.SYS 2008-06-03 08:41 361344 8e036eec565910417ea020ce0962aa24 C:\WINDOWS\system32\drivers\TCPIP.SYS . ((((((((((((((((((((((((((((( snapshot@2008-06-29_21.03.53.64 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-30 00:16:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-04 02:00:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2008-07-04 12:24:17 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2008-07-04 12:24:17 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2008-06-29 22:16:52 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2008-07-04 12:24:17 32,768 -c--a-w C:\WINDOWS\system32\config\syst |