Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Win32.bho Dskquou.dll Removed. Hl And Cf Log. Done Yet?


  • This topic is locked This topic is locked
1 reply to this topic

#1 SpywareDisaster

SpywareDisaster

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 15 February 2008 - 04:29 PM

One full scan with Ad-Adware and S & D I noticed some strange keys in my hijackthis log. I went ahead and ran a virus scan with avg and found a win32.bho trojan. I ran another scan with avg anti-spyware and yet found more spyware and I used XoftSpySE and that found even more spyware. I'm afraid that I'll download another spyware remover tool and it will find more spyware that the rest didn't pick up. Am I clean yet?


Here's the hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:02, on 2008-02-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Ringo\Hub.exe
C:\Program Files\GetRight\GetRight_.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\System32\wuauclt.exe
N:\Tech\HijackThis.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {87312A88-FA21-4F09-92D6-D604B4304A35} - C:\WINDOWS\System32\mljjg.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TalkRun] "C:\Program Files\NCH Swift Sound\Talk\talk.exe" -logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKCU\..\Run: [QdrModule12] "C:\Program Files\QdrModule\QdrModule12.exe"
O4 - HKCU\..\Run: [QdrPack12] "C:\Program Files\QdrPack\QdrPack12.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Ringo Launcher.lnk = C:\Program Files\Ringo\Hub.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .evc: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 8840 bytes



Here's the combofix log:

ComboFix 08-02-15.1 - Owner 2008-02-14 22:38:56.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.99 [GMT -5:00]
Running from: C:\Documents and Settings\Owner.FAMILY\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\persist.dbs
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Owner.FAMILY\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Owner.FAMILY\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Owner.FAMILY\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico

.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-14 22:01 . 2002-08-29 07:00 375,808 --a------ C:\kmd.exe
2008-02-14 21:28 . 2008-02-14 21:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-14 21:28 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-14 21:21 . 2008-02-14 21:22 <DIR> d-------- C:\Program Files\XoftSpySE
2008-02-14 20:29 . 2008-02-14 20:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-02-14 17:45 . 2008-02-14 20:52 <DIR> d-------- C:\Documents and Settings\Owner.FAMILY\Application Data\AVG7
2008-02-14 17:45 . 2008-02-14 17:45 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-14 17:44 . 2008-02-14 21:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-14 17:44 . 2008-02-14 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-14 17:06 . 2008-02-14 17:14 <DIR> d-------- C:\Documents and Settings\Owner.FAMILY\Application Data\U3
2008-02-14 10:26 . 2008-02-14 10:26 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-14 10:25 . 2008-02-14 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-14 10:13 . 2008-02-14 10:13 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-02-14 10:11 . 2008-02-14 10:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-14 10:08 . 2003-10-14 00:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-14 10:08 . 2003-10-10 23:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-14 10:08 . 2003-10-11 00:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-02-14 10:08 . 2003-10-14 00:24 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2008-02-13 15:30 . 2008-02-14 14:56 654 --ahs---- C:\WINDOWS\system32\wicrgesr.ini
2008-02-13 15:30 . 2008-02-13 15:30 294 --ahs---- C:\WINDOWS\system32\wuphtddi.ini
2008-02-12 15:34 . 2008-02-12 17:39 84,729 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-02-10 14:02 . 2008-02-11 11:54 354 --ahs---- C:\WINDOWS\system32\jlsqxvsj.ini
2008-02-03 13:24 . 2008-02-03 13:14 2,642,600 --a------ C:\WINDOWS\system32\ukyinbyn.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 01:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-15 01:38 --------- d-----w C:\Documents and Settings\Owner.FAMILY\Application Data\Hamachi
2008-02-14 22:43 --------- d-----w C:\Program Files\GetRight
2008-02-14 15:39 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-14 15:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-14 15:18 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-06 22:14 --------- d-----w C:\Program Files\MSN Messenger
2008-02-04 04:53 --------- d-----w C:\Program Files\HP
2008-02-04 04:51 --------- d-----w C:\Program Files\Quicken
2008-02-04 04:45 --------- d-----w C:\Program Files\Microsoft Plus! Digital Media Edition
2008-02-04 04:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 04:41 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-04 04:20 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-02-01 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ringo
2008-01-15 14:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 10:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 23:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-08 04:08 --------- d-----w C:\Program Files\Ringo
2008-01-07 22:21 --------- d-----w C:\Program Files\Norton 360
2007-01-22 23:35 5,255,731 ----a-w C:\Program Files\gdbfn.zip
2003-08-27 19:19 36,963 ----a-w C:\Program Files\Common Files\SM1updtr.dll
2007-02-23 17:34 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
<pre>
----a-w		   115,816 2008-02-14 15:18:32  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
</pre>


((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 151,597 2003-10-11 04:58:42 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

----a-w 110,592 2003-08-19 15:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe

----a-w 132,496 2007-07-12 08:00:36 C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe

----a-w 1,289,000 2006-11-13 17:39:52 C:\Program Files\Microsoft ActiveSync\bak\Wcescomm.exe

----a-w 139,264 2003-08-15 01:11:32 C:\Program Files\Multimedia Card Reader\bak\shwicon2k.exe

----a-w 544,772 2007-09-14 18:24:41 C:\Program Files\NCH Swift Sound\Talk\bak\talk.exe

----a-w 181 2007-10-25 00:38:30 C:\WINDOWS\system\bak\hpsysdrv.DAT
----a-w 248 2007-10-04 01:28:19 C:\WINDOWS\system\hpsysdrv.dat

----a-w 52,736 1998-05-07 23:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe

----a-w 114,688 2003-04-07 14:07:38 C:\WINDOWS\system32\bak\hkcmd.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87312A88-FA21-4F09-92D6-D604B4304A35}]
C:\WINDOWS\System32\mljjg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"eyeBeam SIP Client"="" []
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [ ]
"QdrModule12"="C:\Program Files\QdrModule\QdrModule12.exe" [ ]
"QdrPack12"="C:\Program Files\QdrPack\QdrPack12.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [ ]
"VTTimer"="VTTimer.exe" [2004-10-22 10:53 53248 C:\WINDOWS\system32\VTTimer.exe]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:31 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-02-14 10:40 517768]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 12:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [ ]
"TalkRun"="C:\Program Files\NCH Swift Sound\Talk\talk.exe" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-14 17:45 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-14 17:45 219136]

C:\Documents and Settings\Owner.FAMILY\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-11-15 14:56:29 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
GetRight - Tray Icon.lnk - C:\Program Files\GetRight\getright.exe [2007-09-15 16:05:59 57344]
Ringo Launcher.lnk - C:\Program Files\Ringo\Hub.exe [2008-01-07 23:08:48 759344]

S2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\System32\DRIVERS\nvcap.sys [2003-07-30 04:15]
S2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\System32\DRIVERS\NVxbar.sys [2003-07-30 04:15]

*Newly Created Service* - AVGASCLN
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 03:15:02 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-02-15 03:15:00 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-14 22:44:48
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-14 22:49:09
ComboFix-quarantined-files.txt 2008-02-15 03:49:05
ComboFix2.txt 2008-02-15 03:27:46
.
2007-12-04 01:06:58 --- E O F ---

Edited by SpywareDisaster, 15 February 2008 - 04:33 PM.


BC AdBot (Login to Remove)

 


#2 Bobbi Flekman

Bobbi Flekman

    The computer whisperer


  • Malware Response Team
  • 4,423 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:13 AM

Posted 20 February 2008 - 04:56 AM

This thread is closed because the poster is being helped at Spyware Warrior.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users