Hello,
Just want to add that is a wonderful site... if it wasn't for this place, I'd probably was just going to reformat my hard drive.
So a roommate of mine decided to look for a keygen for a nvidia program and ended up installing some sort of virus that had the following symptoms as this member:
http://www.bleepingcomputer.com/forums/topic162553.html
So I continued reading the thread, and followed Simon's instructions and I'm hoping everything is back to normal. Can anyone let me know if there's more I have to do?
Here's the following logs from ComboFix, Hijack, CCleaner Uninstall List:
ComboFix 08-08-19.06 - Erljames 2008-08-21 13:49:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3069 [GMT -4:00]
Running from: C:\Documents and Settings\Erljames\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Erljames\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sex1.ico
C:\WINDOWS\system32\sex2.ico
C:\WINDOWS\system32\vav.cpl
.
((((((((((((((((((((((((( Files Created from 2008-07-21 to 2008-08-21 )))))))))))))))))))))))))))))))
.
2008-08-21 13:34 . 2008-08-21 13:34 <DIR> d-------- C:\Program Files\CCleaner
2008-08-21 12:04 . 2008-08-21 12:05 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-08-21 11:45 . 2008-08-21 11:45 <DIR> d-------- C:\WINDOWS\LastGood
2008-08-21 01:43 . 2008-08-21 01:42 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-08-21 01:42 . 2008-08-21 01:43 <DIR> d-------- C:\Documents and Settings\Erljames\.housecall6.6
2008-08-20 20:38 . 2008-08-20 20:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-20 20:25 . 2008-08-20 20:25 1,812 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-20 20:24 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-20 20:24 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-20 20:24 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-20 20:24 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-20 20:24 . 2008-08-14 21:52 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-20 20:24 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-20 20:24 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-20 20:24 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-20 20:24 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-20 20:06 . 2008-08-20 20:06 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-08-20 19:34 . 2008-08-20 19:34 <DIR> d-------- C:\Program Files\Sonic
2008-08-20 19:34 . 2008-08-20 19:34 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-08-20 19:34 . 2008-08-20 19:34 59 --a------ C:\WINDOWS\WININIT.INI
2008-08-20 19:06 . 2008-08-20 19:06 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-08-20 19:06 . 2008-08-20 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-08-20 19:06 . 2004-10-11 11:28 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-08-20 19:06 . 2004-11-12 16:01 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-08-20 19:06 . 2004-12-13 09:44 14,848 --a------ C:\WINDOWS\system32\drivers\nvndis.sys
2008-08-20 19:06 . 2004-10-11 11:28 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-08-20 18:20 . 2008-08-20 18:20 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-20 18:20 . 2008-08-20 18:20 <DIR> d-------- C:\Documents and Settings\Erljames\Application Data\vlc
2008-08-20 18:11 . 2008-08-20 18:11 <DIR> d-------- C:\divx
2008-08-20 17:57 . 2008-08-20 17:57 <DIR> d-------- C:\WINDOWS\Sun
2008-08-20 17:49 . 2007-09-17 08:07 135,089 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-08-20 17:42 . 2008-08-20 17:42 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-20 17:11 . 2008-08-20 17:11 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-20 16:42 . 2008-08-20 16:42 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-20 16:34 . 2008-08-20 16:34 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-20 16:31 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-20 16:24 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-08-20 15:54 . 2008-08-20 19:17 <DIR> d-------- C:\Documents and Settings\Erljames\Application Data\Yahoo!
2008-08-20 15:54 . 2008-06-13 07:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-20 15:54 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-20 15:53 . 2008-06-23 12:57 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-20 15:53 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-20 15:53 . 2007-03-08 01:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-20 15:53 . 2008-06-23 12:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-20 15:53 . 2008-06-23 12:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-20 15:53 . 2008-06-23 12:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-20 15:53 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-20 15:53 . 2008-06-23 12:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-20 15:53 . 2008-06-23 12:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-20 15:53 . 2008-06-23 05:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-20 15:52 . 2008-08-20 15:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-20 15:52 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-20 15:51 . 2008-08-20 16:00 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-20 15:49 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-08-20 15:49 . 2008-07-18 22:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-08-20 15:49 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-25 04:36 . 2008-07-25 04:36 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-07-25 04:36 . 2008-07-25 04:36 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-07-23 17:40 . 2008-07-23 17:40 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-07-23 17:30 . 2008-07-23 17:42 <DIR> d-------- C:\Program Files\Canon
2008-07-23 12:50 . 2008-07-23 12:50 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 12:48 . 2008-07-23 12:48 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-07-23 12:48 . 2008-07-23 12:48 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dtu100.dll.manifest
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dpl100.dll.manifest
2008-07-23 12:46 . 2008-07-23 12:46 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 16:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-21 02:24 --------- d-----w C:\Documents and Settings\Erljames\Application Data\U3
2008-08-21 01:15 --------- d-----w C:\Program Files\Lavasoft
2008-08-21 01:14 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 01:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-20 23:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 22:29 --------- d-----w C:\Program Files\Winamp
2008-08-20 22:02 --------- d-----w C:\Program Files\DivX
2008-08-20 21:42 --------- d-----w C:\Program Files\Common Files\Real
2008-08-20 21:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2007-09-28 19:00 10,022 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 08:07 8491008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 17:14 53408]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-06-15 01:40 124656]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 11:56 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-20 17:42 185896]
"CTHelper"="CTHELPER.EXE" [2006-12-12 10:46 19456 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 10:46 20480 C:\WINDOWS\system32\Ctxfihlp.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\UB-VPN\vpngui.exe [2007-08-27 14:40:17 1528880]
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\CineTray.exe [2006-07-25 02:01:00 114688]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Erljames^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Erljames\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-08-20 17:42 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R0 Si3124;Si3124;C:\WINDOWS\system32\drivers\Si3124.sys [2007-08-09 11:32]
R0 Si3531;Si3531;C:\WINDOWS\system32\drivers\Si3531.sys [2007-08-09 11:32]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-12-19 08:36]
*Newly Created Service* - CATCHME
*Newly Created Service* - DMADMIN
*Newly Created Service* - NTMSSVC
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{48776EE4-6AEA-4121-A341-559129C4A0DE} - C:\WINDOWS\twmxbsqrobw.dll
BHO-{F73DBD9E-5F1B-4BCA-8604-A911DCE08B37} - C:\WINDOWS\system32\fayo.dll
Toolbar-{C091867D-17C0-4855-B6E5-797649ED7A9A} - C:\WINDOWS\rafbsvnx.dll
HKCU-Run-\SUE23.exe - C:\Windows\SUE23.exe
HKCU-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKCU-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKCU-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKCU-Run-\SUE27.exe - C:\Windows\SUE27.exe
HKLM-Run-\SUE23.exe - C:\Windows\SUE23.exe
HKLM-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKLM-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKLM-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKLM-Run-\SUE27.exe - C:\Windows\SUE27.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Erljames\Application Data\Mozilla\Firefox\Profiles\709gmimy.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - myub.buffalo.edu
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 13:55:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\SUE23.exe"="C:\\Windows\\SUE23.exe"
"\\SUE24.exe"="C:\\Windows\\SUE24.exe"
"\\SUE25.exe"="C:\\Windows\\SUE25.exe"
"\\SUE26.exe"="C:\\Windows\\SUE26.exe"
"\\SUE27.exe"="C:\\Windows\\SUE27.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\SUE23.exe"="C:\\Windows\\SUE23.exe"
"\\SUE24.exe"="C:\\Windows\\SUE24.exe"
"\\SUE25.exe"="C:\\Windows\\SUE25.exe"
"\\SUE26.exe"="C:\\Windows\\SUE26.exe"
"\\SUE27.exe"="C:\\Windows\\SUE27.exe"
.
Completion time: 2008-08-21 14:04:49
ComboFix-quarantined-files.txt 2008-08-21 18:04:19
Pre-Run: 178,156,179,456 bytes free
Post-Run: 178,365,579,264 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
234 --- E O F --- 2008-08-20 21:25:07
Just want to add that is a wonderful site... if it wasn't for this place, I'd probably was just going to reformat my hard drive.
So a roommate of mine decided to look for a keygen for a nvidia program and ended up installing some sort of virus that had the following symptoms as this member:
http://www.bleepingcomputer.com/forums/topic162553.html
Quote
1. Computer time has changed to Military Time and "VIRUS ALERT!" shows up next to the time.
2. In the start tab I cannot see the program files fly out, control panel, run tab, ect.
3. On my computer I cannot see my C:/ drive.
4. Various spyware and virus alerts popping up all the time.
5. Computer trys to access various web pages automatically
6. Desktop picture changed to red screen with text "Your Privacy is in Danger - Download privacy protection software now"
7. New icons installed on desktop for "privacy protector" , "error cleaner" and "spyware and malware protection"
8. When doing an cntl-alt-delete it says this has been disabled by the administrator
2. In the start tab I cannot see the program files fly out, control panel, run tab, ect.
3. On my computer I cannot see my C:/ drive.
4. Various spyware and virus alerts popping up all the time.
5. Computer trys to access various web pages automatically
6. Desktop picture changed to red screen with text "Your Privacy is in Danger - Download privacy protection software now"
7. New icons installed on desktop for "privacy protector" , "error cleaner" and "spyware and malware protection"
8. When doing an cntl-alt-delete it says this has been disabled by the administrator
So I continued reading the thread, and followed Simon's instructions and I'm hoping everything is back to normal. Can anyone let me know if there's more I have to do?
Here's the following logs from ComboFix, Hijack, CCleaner Uninstall List:
ComboFix 08-08-19.06 - Erljames 2008-08-21 13:49:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3069 [GMT -4:00]
Running from: C:\Documents and Settings\Erljames\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Erljames\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sex1.ico
C:\WINDOWS\system32\sex2.ico
C:\WINDOWS\system32\vav.cpl
.
((((((((((((((((((((((((( Files Created from 2008-07-21 to 2008-08-21 )))))))))))))))))))))))))))))))
.
2008-08-21 13:34 . 2008-08-21 13:34 <DIR> d-------- C:\Program Files\CCleaner
2008-08-21 12:04 . 2008-08-21 12:05 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-08-21 11:45 . 2008-08-21 11:45 <DIR> d-------- C:\WINDOWS\LastGood
2008-08-21 01:43 . 2008-08-21 01:42 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-08-21 01:42 . 2008-08-21 01:43 <DIR> d-------- C:\Documents and Settings\Erljames\.housecall6.6
2008-08-20 20:38 . 2008-08-20 20:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-20 20:25 . 2008-08-20 20:25 1,812 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-20 20:24 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-20 20:24 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-20 20:24 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-20 20:24 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-20 20:24 . 2008-08-14 21:52 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-20 20:24 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-20 20:24 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-20 20:24 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-20 20:24 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-20 20:06 . 2008-08-20 20:06 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-08-20 19:34 . 2008-08-20 19:34 <DIR> d-------- C:\Program Files\Sonic
2008-08-20 19:34 . 2008-08-20 19:34 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-08-20 19:34 . 2008-08-20 19:34 59 --a------ C:\WINDOWS\WININIT.INI
2008-08-20 19:06 . 2008-08-20 19:06 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-08-20 19:06 . 2008-08-20 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-08-20 19:06 . 2004-10-11 11:28 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-08-20 19:06 . 2004-11-12 16:01 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-08-20 19:06 . 2004-12-13 09:44 14,848 --a------ C:\WINDOWS\system32\drivers\nvndis.sys
2008-08-20 19:06 . 2004-10-11 11:28 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-08-20 18:20 . 2008-08-20 18:20 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-20 18:20 . 2008-08-20 18:20 <DIR> d-------- C:\Documents and Settings\Erljames\Application Data\vlc
2008-08-20 18:11 . 2008-08-20 18:11 <DIR> d-------- C:\divx
2008-08-20 17:57 . 2008-08-20 17:57 <DIR> d-------- C:\WINDOWS\Sun
2008-08-20 17:49 . 2007-09-17 08:07 135,089 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-08-20 17:42 . 2008-08-20 17:42 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-20 17:13 . 2008-08-20 17:13 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-20 17:11 . 2008-08-20 17:11 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-20 16:42 . 2008-08-20 16:42 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-20 16:34 . 2008-08-20 16:34 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-20 16:31 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-20 16:24 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-08-20 15:54 . 2008-08-20 19:17 <DIR> d-------- C:\Documents and Settings\Erljames\Application Data\Yahoo!
2008-08-20 15:54 . 2008-06-13 07:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-20 15:54 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-20 15:53 . 2008-06-23 12:57 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-20 15:53 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-20 15:53 . 2007-03-08 01:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-20 15:53 . 2008-06-23 12:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-20 15:53 . 2008-06-23 12:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-20 15:53 . 2008-06-23 12:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-20 15:53 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-20 15:53 . 2008-06-23 12:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-20 15:53 . 2008-06-23 12:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-20 15:53 . 2008-06-23 05:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-20 15:52 . 2008-08-20 15:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-20 15:52 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-20 15:51 . 2008-08-20 16:00 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-20 15:49 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-08-20 15:49 . 2008-07-18 22:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-08-20 15:49 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-25 04:36 . 2008-07-25 04:36 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-07-25 04:36 . 2008-07-25 04:36 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-07-23 17:40 . 2008-07-23 17:40 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-07-23 17:30 . 2008-07-23 17:42 <DIR> d-------- C:\Program Files\Canon
2008-07-23 12:50 . 2008-07-23 12:50 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 12:48 . 2008-07-23 12:48 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-07-23 12:48 . 2008-07-23 12:48 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dtu100.dll.manifest
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dpl100.dll.manifest
2008-07-23 12:46 . 2008-07-23 12:46 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 16:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-21 02:24 --------- d-----w C:\Documents and Settings\Erljames\Application Data\U3
2008-08-21 01:15 --------- d-----w C:\Program Files\Lavasoft
2008-08-21 01:14 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 01:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-20 23:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 22:29 --------- d-----w C:\Program Files\Winamp
2008-08-20 22:02 --------- d-----w C:\Program Files\DivX
2008-08-20 21:42 --------- d-----w C:\Program Files\Common Files\Real
2008-08-20 21:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2007-09-28 19:00 10,022 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 08:07 8491008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 17:14 53408]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-06-15 01:40 124656]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 11:56 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-20 17:42 185896]
"CTHelper"="CTHELPER.EXE" [2006-12-12 10:46 19456 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 10:46 20480 C:\WINDOWS\system32\Ctxfihlp.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\UB-VPN\vpngui.exe [2007-08-27 14:40:17 1528880]
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\CineTray.exe [2006-07-25 02:01:00 114688]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Erljames^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Erljames\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-08-20 17:42 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R0 Si3124;Si3124;C:\WINDOWS\system32\drivers\Si3124.sys [2007-08-09 11:32]
R0 Si3531;Si3531;C:\WINDOWS\system32\drivers\Si3531.sys [2007-08-09 11:32]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-12-19 08:36]
*Newly Created Service* - CATCHME
*Newly Created Service* - DMADMIN
*Newly Created Service* - NTMSSVC
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{48776EE4-6AEA-4121-A341-559129C4A0DE} - C:\WINDOWS\twmxbsqrobw.dll
BHO-{F73DBD9E-5F1B-4BCA-8604-A911DCE08B37} - C:\WINDOWS\system32\fayo.dll
Toolbar-{C091867D-17C0-4855-B6E5-797649ED7A9A} - C:\WINDOWS\rafbsvnx.dll
HKCU-Run-\SUE23.exe - C:\Windows\SUE23.exe
HKCU-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKCU-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKCU-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKCU-Run-\SUE27.exe - C:\Windows\SUE27.exe
HKLM-Run-\SUE23.exe - C:\Windows\SUE23.exe
HKLM-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKLM-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKLM-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKLM-Run-\SUE27.exe - C:\Windows\SUE27.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Erljames\Application Data\Mozilla\Firefox\Profiles\709gmimy.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - myub.buffalo.edu
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 13:55:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\SUE23.exe"="C:\\Windows\\SUE23.exe"
"\\SUE24.exe"="C:\\Windows\\SUE24.exe"
"\\SUE25.exe"="C:\\Windows\\SUE25.exe"
"\\SUE26.exe"="C:\\Windows\\SUE26.exe"
"\\SUE27.exe"="C:\\Windows\\SUE27.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\SUE23.exe"="C:\\Windows\\SUE23.exe"
"\\SUE24.exe"="C:\\Windows\\SUE24.exe"
"\\SUE25.exe"="C:\\Windows\\SUE25.exe"
"\\SUE26.exe"="C:\\Windows\\SUE26.exe"
"\\SUE27.exe"="C:\\Windows\\SUE27.exe"
.
Completion time: 2008-08-21 14:04:49
ComboFix-quarantined-files.txt 2008-08-21 18:04:19
Pre-Run: 178,156,179,456 bytes free
Post-Run: 178,365,579,264 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
234 --- E O F --- 2008-08-20 21:25:07
This post has been edited by infamouscaption: 21 August 2008 - 02:16 PM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top









