Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

win32.bagle combofix request


  • This topic is locked This topic is locked
2 replies to this topic

#1 eleegee

eleegee

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:01:03 AM

Posted 25 December 2008 - 04:10 PM

i have a combofix report that i would like to submit. i am still encountering issues with programs not opening and reporting "...not a valid win 32 program".

Combofix readme said to still post my logfile just in case!

thanks!

eleeegee

-------------
ComboFix 08-12-24.01 - dirt 2008-12-25 21:56:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.186 [GMT 2:00]
Running from: c:\documents and settings\dirt\Desktop\tool.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\dirt\Application Data\drivers\downld
c:\documents and settings\dirt\Application Data\drivers\winupgro.exe
c:\program files\RMClock\RMClockLauncher.exe
c:\windows\system32\ban_list.txt
c:\windows\system32\drivers\downld
c:\windows\system32\mdelk.exe

.
((((((((((((((((((((((((( Files Created from 2008-11-25 to 2008-12-25 )))))))))))))))))))))))))))))))
.

2008-12-25 19:44 . 2008-12-25 19:44 <DIR> d-------- c:\program files\XoftSpySE
2008-12-25 16:53 . 2008-12-25 21:57 <DIR> d--h----- c:\documents and settings\dirt\Application Data\drivers
2008-12-25 16:35 . 2008-12-25 16:40 <DIR> d-------- c:\program files\Plagiarism
2008-12-25 16:35 . 2008-12-25 16:35 249,856 --------- c:\windows\Setup1.exe
2008-12-25 16:35 . 2008-12-25 16:35 73,216 --a------ c:\windows\ST6UNST.EXE
2008-12-24 14:12 . 2008-12-25 22:00 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-21 01:12 . 2008-12-22 03:15 <DIR> d-------- c:\program files\VDMSound
2008-12-20 17:58 . 2008-12-20 17:58 21,581 --a------ C:\FRAGLIST.LUAR
2008-12-18 15:23 . 2008-12-20 23:44 <DIR> d-------- c:\program files\Sins of a Solar Empire
2008-12-17 18:48 . 2008-12-17 18:48 <DIR> d-------- c:\program files\MS pano
2008-12-17 18:32 . 2008-12-25 14:51 <DIR> d-------- c:\program files\Everything
2008-12-17 12:25 . 2008-12-17 12:25 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-17 12:19 . 2008-12-18 01:56 <DIR> d-------- c:\program files\Colonization
2008-12-17 01:40 . 2008-12-17 01:40 <DIR> d-------- c:\program files\Hotspot Shield
2008-12-16 18:09 . 2008-12-25 16:56 <DIR> d-------- c:\program files\T3
2008-12-04 18:04 . 2008-12-13 15:26 <DIR> d--h----- c:\windows\$hf_mig$
2008-12-04 17:41 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-04 12:23 . 2008-12-04 12:23 <DIR> d-------- c:\documents and settings\dirt\.housecall6.6
2008-12-04 11:27 . 2008-12-04 11:27 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-12-04 11:27 . 2008-12-04 11:27 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-12-04 11:26 . 2008-12-04 11:26 <DIR> d-------- c:\program files\Kaspersky Lab
2008-12-04 11:26 . 2008-12-25 16:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-04 11:26 . 2008-12-25 22:00 4,852,768 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-04 11:26 . 2008-12-25 22:00 237,600 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-12-04 11:26 . 2008-12-25 22:00 38,992 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-04 11:26 . 2008-12-25 22:00 1,892 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-12-04 11:08 . 2008-12-04 11:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-25 19:59 --------- d-----w c:\program files\RMClock
2008-12-25 19:55 --------- d-----w c:\program files\Mozilla FirefoxII
2008-12-25 14:00 --------- d-----w c:\documents and settings\dirt\Application Data\Skype
2008-12-23 15:04 --------- d-----w c:\program files\PowerStrip
2008-12-14 21:59 --------- d-----w c:\documents and settings\dirt\Application Data\Move Networks
2008-12-06 18:02 85,992 ----a-w c:\documents and settings\dirt\Application Data\GDIPFONTCACHEV1.DAT
2008-12-05 19:48 --------- d-----w c:\program files\Trillian
2008-12-03 16:07 --------- d-----w c:\program files\Common Files\Apple
2008-11-27 11:04 --------- d-----w c:\program files\DU Meter
2008-11-20 21:47 --------- d-----w c:\documents and settings\All Users\Application Data\Hagel Technologies
2008-11-20 11:24 --------- d-----w c:\documents and settings\dirt\Application Data\InstallShield
2008-11-20 11:14 --------- d-----w c:\program files\DAEMON Tools
2008-11-20 10:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-20 10:57 --------- d-----w c:\program files\civ4
2008-11-11 17:58 25,601 ----a-w c:\windows\system32\drivers\klopp.dat
2008-11-09 21:33 --------- d-----w c:\program files\PrimoPDF
2008-11-09 10:16 --------- d-----w c:\program files\Replay AV 8
2008-11-08 14:24 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-08 14:24 --------- d-----w c:\documents and settings\dirt\Application Data\DAEMON Tools
2008-11-06 19:39 --------- d-----w c:\program files\Bonjour
2008-11-06 15:34 --------- d-----w c:\program files\Common Files\Adobe
2008-11-06 15:10 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-11-06 15:09 --------- d-----w c:\program files\NOS
2008-11-04 13:29 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-04 13:29 --------- d-----w c:\program files\BlinkoTvAir
2008-11-04 13:29 --------- d-----w c:\documents and settings\dirt\Application Data\BlinkoTvAir.D8ABBB8B5913CE95C170D57FCA2CA8CDE7219937.1
2008-11-04 11:50 --------- d-----w c:\program files\JLC's Software
2008-11-04 11:50 --------- d-----w c:\documents and settings\dirt\Application Data\JLC's Software
2008-11-04 10:59 --------- d-----w c:\program files\TVUPlayer
2008-11-04 10:59 --------- d-----w c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-02 18:52 --------- d-----w c:\documents and settings\dirt\Application Data\AdobeUM
2008-10-28 13:00 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-28 12:57 --------- d-----w c:\documents and settings\dirt\Application Data\Apple Computer
2008-10-28 12:56 --------- d-----w c:\program files\QuickTime
2008-10-28 12:55 --------- d-----w c:\program files\Apple Software Update
2008-10-28 12:54 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-10-28 12:12 --------- d-----w c:\program files\Windows Desktop Search
2008-10-27 16:35 --------- d-----w c:\documents and settings\dirt\Application Data\Windows Search
2008-10-26 14:15 --------- d-----w c:\program files\PDF Enhancer
2008-10-26 14:12 --------- d-----w c:\documents and settings\All Users\Application Data\Apago
2008-09-22 20:09 1,234 ----a-w c:\documents and settings\dirt\Application Data\SAS7_000.DAT
2007-09-26 11:18 32,746,185 ----a-w c:\program files\Trillian.rar
2005-07-14 19:31 27,648 --sha-w c:\windows\system32\AVSredirect.dll
.

------- Sigcheck -------

2008-07-16 00:36 360320 b04394e418cbe151a03ba242a635c31e c:\windows\system32\dllcache\TCPIP.SYS
2008-07-16 00:36 360320 b04394e418cbe151a03ba242a635c31e c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2008-12-17 01:40 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mobmeter"="c:\documents and settings\dirt\Start Menu\Programs\mobmeter.exe" [2008-03-29 41984]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2006-11-27 1582616]

c:\documents and settings\dirt\Start Menu\Programs\Startup\
SynTPEnh.lnk - c:\program files\Synaptics\SynTP\SynTPEnh.exe [2008-03-28 774233]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyPictures"= 01000000
"NoLogoff"= 00000000

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\program files\DVD Region+CSS Free\DVDShell.dll" [2004-10-09 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv50"= c:\progra~1\REPLAY~1\ir50_32.dll
"vidc.ffds"= c:\progra~1\CCCP\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop.ini]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\desktop.ini
backup=c:\windows\pss\desktop.iniCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"rpcapd"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"IDriverT"=3 (0x3)
"ABBYY.Licensing.FineReader.Professional.9.0"=3 (0x3)
"wltrysvc"=2 (0x2)
"SandraAgentSrv"=2 (0x2)
"LiveUpdate"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business XII.SP2\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business XII.SP2\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\civ4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\civ4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25261:TCP"= 25261:TCP:BitComet 25261 TCP
"25261:UDP"= 25261:UDP:BitComet 25261 UDP
"21565:TCP"= 21565:TCP:BitComet 21565 TCP
"21565:UDP"= 21565:UDP:BitComet 21565 UDP
"9681:TCP"= 9681:TCP:BitComet 9681 TCP
"9681:UDP"= 9681:UDP:BitComet 9681 UDP
"25331:TCP"= 25331:TCP:BitComet 25331 TCP
"25331:UDP"= 25331:UDP:BitComet 25331 UDP
"14271:TCP"= 14271:TCP:BitComet 14271 TCP
"14271:UDP"= 14271:UDP:BitComet 14271 UDP
"17040:TCP"= 17040:TCP:BitComet 17040 TCP
"17040:UDP"= 17040:UDP:BitComet 17040 UDP
"60000:TCP"= 60000:TCP:BitComet 60000 TCP
"60000:UDP"= 60000:UDP:BitComet 60000 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 HFXP2;HFXP2;c:\windows\system32\DRIVERS\HFXP2.SYS [2008-04-02 17264]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-05-13 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-05-13 55024]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl [2008-08-08 10:15:56 41456]
R2 PStrip;PSTRIP;\??\c:\windows\system32\DRIVERS\PSTRIP.SYS [2007-07-15 27992]
R3 hexmagic;hexmagic;\??\c:\windows\system32\drivers\hexmagic.sys []
R3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2008-03-28 200192]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-06 33752]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-05-13 7408]
S3 ultradfg;ultradfg;c:\windows\system32\DRIVERS\ultradfg.sys [2008-03-09 23040]
S4 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.EXE []
S4 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe [2008-05-30 98488]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed3338be-274b-11dd-9fbe-00904bf44a5c}]
\Shell\AutoRun\command - E:\AUTORUN.EXE

*Newly Created Service* - HEXMAGIC
.
Contents of the 'Scheduled Tasks' folder

2008-12-22 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\dirt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 18:54]

2008-12-25 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 19:08]

2008-12-25 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 19:08]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-RMClock - c:\program files\RMClock\RMClockLauncher.exe


.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = local;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-25 22:02:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(1096)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-25 22:08:07 - machine was rebooted [dirt]
ComboFix-quarantined-files.txt 2008-12-25 20:08:03

Pre-Run: 7,886,274,560 bytes free
Post-Run: 7,923,081,216 bytes free

247

Attached Files


Edited by eleegee, 25 December 2008 - 04:15 PM.


BC AdBot (Login to Remove)

 


#2 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the &quot;Logic Free Zone&quot;, in Md, USA
  • Local time:02:03 AM

Posted 07 January 2009 - 12:55 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE


Please Hold on it may take us a day or so to get back with you.

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)

#3 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the &quot;Logic Free Zone&quot;, in Md, USA
  • Local time:02:03 AM

Posted 12 January 2009 - 08:47 AM

Due to the lack of feedback, this Topic is now closed.

If you still have problems, please Start a new topic.

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users