.
DDS (Ver_2011-06-03.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Run by Administrator at 13:59:16 on 2011-06-05
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223.44 [GMT -6:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mPolicies-explorer: RestrictRun = 0 (0x0)
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\iogear\bluetooth software\btsendto_ie.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{2AE3B0D1-42E3-4E8F-9E5B-40147968A645} : DhcpNameServer = 192.168.1.254
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath -
.
============= SERVICES / DRIVERS ===============
.
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-7 135664]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [2010-1-7 57856]
.
=============== Created Last 30 ================
.
2011-06-05 19:13:37 -------- d-----w- c:\windows\pss
2011-06-05 19:05:34 358912 ------w- c:\documents and settings\all users\application data\16375588.exe
2011-06-05 18:35:04 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-06-05 06:18:34 -------- d--h--w- c:\documents and settings\administrator\local settings\application data\Adobe
2011-06-04 23:57:00 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE
2011-06-04 21:05:55 456704 ---ha-w- c:\documents and settings\all users\application data\sqoXnmCuXYw.exe
2011-06-03 04:08:04 766158 ---ha-w- c:\windows\TheColourClock.scr
2011-06-03 04:08:03 -------- d--h--w- c:\windows\TheColourClock Uninstaller
2011-05-25 21:10:26 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-08 01:33:22 -------- d--h--w- c:\program files\common files\DivX Shared
2011-05-08 01:30:22 -------- d--h--w- c:\program files\DivX
2011-05-08 01:29:36 -------- d--h--w- c:\documents and settings\all users\application data\DivX
2011-05-08 01:18:41 -------- d--h--w- c:\program files\The Weather Channel FW
.
==================== Find3M ====================
.
2011-05-29 15:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-28 16:23:30 398760 ---ha-r- c:\windows\system32\cpnprt2.cid
2011-05-19 13:28:06 0 ---ha-w- c:\windows\Wkesoce.bin
2011-03-18 18:32:10 71072 ---ha-w- c:\windows\CouponPrinter.ocx
.
============= FINISH: 14:00:03.70 ===============
Update: I ran ComboFix which got rid of a whole lot of this mess and allowed me to be able to move forward. I then used rootkill which found nothing, unhide to see my files, and tdsskiller. I may have done other things I've forgotten and my machine is functioning well. However, I ran Malwarebytes overnight and found eight more infected files. Will this ever end?
EDIT: Posts merged ~Budapest
Attached File(s)
-
attach.txt (7.77K)
Number of downloads: 0 -
ark.txt (8.63K)
Number of downloads: 0
This post has been edited by Budapest: 08 June 2011 - 06:46 PM

Help
This topic is locked

Back to top
button.









