Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

infected with cutwail combofix log


  • This topic is locked This topic is locked
2 replies to this topic

#1 bidav

bidav

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:05 AM

Posted 15 May 2009 - 09:41 AM

Hello. I ran combofix after I was infected with cutwail
am I ok now?

ComboFix 09-05-14.07 - Beni 05/15/2009 17:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1255.972.1033.18.2047.1519 [GMT 3:00]
Running from: c:\documents and settings\Beni\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Beni\Beni.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\acleditq.exe
c:\windows\system32\digiwet.dll
c:\windows\system32\drivers\acpi32.sys
c:\windows\system32\FTPx.dll
c:\windows\system32\Ijl11.dll
c:\windows\system32\tmp.reg
D:\install.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ACPI32
-------\Legacy_EPSON_PM_RPCV4_01HIDSERV
-------\Legacy_FIPS32CUP
-------\Legacy_I386SI
-------\Legacy_NETSIK
-------\Legacy_NICSK32
-------\Legacy_PORT135SIK
-------\Legacy_SECURENTM
-------\Legacy_SYSTEMNTMI
-------\Legacy_WS2_32SIK
-------\Service_acpi32
-------\Service_EPSON_PM_RPCV4_01HidServ
-------\Service_fips32cup
-------\Service_i386si
-------\Service_ksi32sk
-------\Service_netsik
-------\Service_nicsk32
-------\Service_port135sik
-------\Service_securentm
-------\Service_systemntmi
-------\Service_ws2_32sik


((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-15 12:56 . 2009-05-15 12:56 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-15 12:55 . 2009-05-15 12:55 -------- d-----w c:\documents and settings\Beni\Application Data\SUPERAntiSpyware.com
2009-05-15 07:39 . 2009-05-15 11:10 16416 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-15 07:39 . 2009-05-15 11:10 1944352 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-14 20:45 . 2009-05-14 20:45 -------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-05-14 20:45 . 2009-05-15 11:07 -------- d-----w c:\program files\Common Files\ParetoLogic
2009-05-14 20:45 . 2009-05-15 11:07 -------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-05-14 17:19 . 2009-05-14 17:19 32 --s-a-w c:\windows\system32\3964090211.dat
2009-05-08 11:48 . 2009-05-08 11:48 -------- d-----w c:\windows\Performance
2009-05-08 11:46 . 2009-05-08 11:46 -------- d-----w c:\documents and settings\Beni\Local Settings\Application Data\Microsoft Corporation
2009-04-30 20:15 . 2009-04-30 20:15 -------- d-sh--w c:\documents and settings\Beni\IECompatCache
2009-04-30 20:14 . 2009-04-30 20:14 -------- d-sh--w c:\documents and settings\Beni\PrivacIE
2009-04-30 00:06 . 2009-04-30 00:06 -------- d-sh--w c:\documents and settings\Beni\IETldCache
2009-04-29 17:03 . 2009-04-29 17:03 -------- d-----w c:\documents and settings\Beni\Application Data\eBay
2009-04-29 13:31 . 2009-04-29 13:31 -------- d-----w c:\windows\ie8updates
2009-04-29 13:31 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-29 13:30 . 2009-04-29 13:31 -------- dc-h--w c:\windows\ie8
2009-04-29 13:23 . 2009-04-29 13:23 -------- d-----w c:\windows\system32\XPSViewer
2009-04-29 13:23 . 2009-04-29 13:23 -------- d-----w c:\program files\Reference Assemblies
2009-04-29 13:23 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-29 13:23 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-29 13:23 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-29 13:23 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-29 13:23 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-29 13:23 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-29 13:23 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-29 13:23 . 2009-04-30 00:06 -------- d-----w c:\windows\SxsCaPendDel
2009-04-29 11:18 . 2009-04-29 11:18 -------- d-----w c:\program files\EASEUS
2009-04-19 20:01 . 2009-04-19 20:01 -------- d-----w c:\documents and settings\Beni\Local Settings\Application Data\RcIncidents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 12:55 . 2007-07-06 20:08 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-15 11:10 . 2009-05-15 07:39 3656 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-15 11:10 . 2009-05-15 07:39 32336 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-29 14:30 . 2006-09-04 18:20 59568 ----a-w c:\documents and settings\Beni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 13:12 . 2006-09-04 17:15 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-29 13:10 . 2006-09-08 00:30 -------- d-----w c:\program files\ATITool
2009-03-26 18:48 . 2008-05-28 17:39 -------- d-----w c:\program files\Nokia
2009-03-26 18:47 . 2008-05-28 17:36 -------- d-----w c:\program files\Common Files\Nokia
2009-03-18 19:53 . 2008-06-24 12:32 -------- d-----w c:\program files\ICQ6
2009-03-08 01:34 . 2004-08-03 22:56 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2004-08-03 22:56 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2004-08-03 22:56 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2004-08-03 22:56 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2004-08-03 22:56 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2004-08-03 22:56 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2004-08-03 22:56 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2004-08-03 22:56 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2004-08-03 22:56 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-08-23 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-03 22:56 284160 ------w c:\windows\system32\pdh.dll
2009-03-02 13:09 . 2007-11-18 14:06 53272 ---ha-w c:\windows\system32\mlfcache.dat
.

------- Sigcheck -------

[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Yahoo! Pager"="d:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"H/PC Connection Agent"="d:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896]
"PC Suite Tray"="d:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-06-21 160592]
"Google Update"="c:\documents and settings\Beni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"LPAgent"="d:\progra~1\ANDALE~1\ListerProAgent.exe" [2006-02-16 102400]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-15 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-06-02 385024]
"DAEMON Tools"="d:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2007-01-26 516096]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"TrueImageMonitor.exe"="d:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-30 2595616]
"AcronisTimounterMonitor"="d:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-30 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-30 140568]
"Nitro PDF Printer Monitor"="d:\program files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe" [2008-06-25 210224]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-22 13582336]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-22 86016]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2006-12-12 20480]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-22 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ip.url]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ip.url
backup=c:\windows\pss\ip.urlCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privoxy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Privoxy.lnk
backup=c:\windows\pss\Privoxy.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Beni^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Beni\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IAANTMON"=2 (0x2)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"NBService"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"WinDefend"=2 (0x2)
"ose"=3 (0x3)
"PDEngine"=3 (0x3)
"PDAgent"=2 (0x2)
"RServer3"=2 (0x2)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=2 (0x2)
"CCALib8"=2 (0x2)
"Bonjour Service"=2 (0x2)
"ICQ Service"=2 (0x2)
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\ircN\\system\\mirc.exe"=
"d:\\Program Files\\Miranda IM\\miranda32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\program files\Microsoft ActiveSync\rapimgr.exe"= d:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"d:\program files\Microsoft ActiveSync\wcescomm.exe"= d:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"d:\program files\Microsoft ActiveSync\WCESMgr.exe"= d:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\AV-CLS\\WGET.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"e:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"e:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\windows\\system32\\WgaTray.exe"=
"d:\\Program Files\\DAEMON Tools\\daemon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07/04/2008 23:39 114768]
R1 raddrvv3;raddrvv3;c:\windows\system32\rserver30\raddrvv3.sys [02/02/2007 14:54 41176]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [28/04/2009 11:33 9968]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [28/04/2009 11:33 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/04/2008 23:39 20560]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [09/09/2006 02:09 3712]
R3 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [01/11/2006 05:01 3328]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [28/04/2009 11:33 7408]
S2 amd64si;amd64si;\??\c:\windows\system32\drivers\amd64si.sys --> c:\windows\system32\drivers\amd64si.sys [?]
S3 aswArKrn;aswArKrn;\??\c:\docume~1\Beni\LOCALS~1\Temp\aswArKrn.sys --> c:\docume~1\Beni\LOCALS~1\Temp\aswArKrn.sys [?]
S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [11/09/2006 16:13 6494]
S3 NDSPCIIO;NDSPCIIO;\??\c:\windows\system32\DRIVERS\NDSPCIIO.SYS --> c:\windows\system32\DRIVERS\NDSPCIIO.SYS [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [26/03/2009 21:48 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [26/03/2009 21:48 8320]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [27/06/2008 01:39 332928]
S4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [24/06/2008 15:33 222456]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;d:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 08:01 2799808]
S4 RServer3;Radmin Server V3;c:\windows\system32\rserver30\rserver3.exe [02/02/2007 14:35 1235032]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\SETUP.EXE
\Shell\configure\command - H:\SETUP.EXE
\Shell\install\command - H:\SETUP.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09740442-3c75-11db-bdd9-806d6172696f}]
\Shell\AutoRun\command - G:\ASUSACPI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2009-05-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-09 21:00]

2009-05-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-2052111302-1801674531-1003.job
- c:\documents and settings\Beni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 19:26]

2009-05-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-Beni - c:\documents and settings\Beni\Beni.exe


.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
uInternet Settings,ProxyOverride = *.local
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Do&wnload by ReGet Deluxe - c:\program files\Common Files\ReGet Shared\CC_Link.htm
IE: Download A&ll by ReGet Deluxe - c:\program files\Common Files\ReGet Shared\CC_All.htm
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: pador.co.il\www
TCP: {E7EF862E-BD7A-42F2-AB70-A45DF20EEF15} = 10.0.0.2
DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} - hxxp://www.tapuz.co.il/irc/main/launcher.cab
DPF: {EAA9520F-10B8-4B49-A3F2-3C8587E2D8CD} - hxxp://server.inklogic.net/PrnScan.cab
DPF: {F59AB0C4-3443-4551-A78F-C101F9DE0215} - hxxp://irc.nana.co.il/Cabs/launcher39.cab
FF - ProfilePath - c:\documents and settings\Beni\Application Data\Mozilla\Firefox\Profiles\9hllbg6b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\documents and settings\Beni\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: d:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 17:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-117609710-2052111302-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5d,e9,79,f3,aa,a7,72,97,0e,86,cc,6b,c5,f3,16,d3,13,a7,e8,8c,ba,69,86,
af,ef,d5,2d,34,1a,95,f3,f1,bb,c8,ec,f6,77,26,3d,eb,35,e1,6e,a1,06,1e,43,38,\
"??"=hex:87,af,aa,94,ba,4a,84,47,17,09,02,dc,6b,19,ed,07

[HKEY_USERS\S-1-5-21-117609710-2052111302-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:4c,b0,93,8a,28,a7,b2,95,dd,95,34,c0,ac,a1,1f,33,ed,8d,9c,21,57,
95,68,58,dc,0f,9e,88,c4,ca,d4,b6,40,79,13,bc,96,f2,4f,7f,ac,d8,11,40,cf,1e,\
"rkeysecu"=hex:db,c4,20,79,17,6f,40,f4,52,f9,2a,d6,07,06,c8,f3

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OOPM02.00.00.01PRO"="E47582E58A970912A641FA2AD7ED2C2B0BFB3362C7B4F5AB2421ABAC13FE8F0CCD56B645EF6DBC751E2C3747C71DAA6ED9ADEE40F658BEDE85C3DA17262783D177E028BD21A01B988C05A939D698C9B9588D6D73CE1686A3F85457E0469BA5C3E822D3F3CD40105DF0ED9062FB9786B61FEECEBAAE6A7B95CFFA42C6DFBFF48C4C377CC08A348997F09AEFD815A4E008EABCF789DB244D41027600B8C0C5F1C371D428B24CB5798DD3538DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A9C6AECB7A5D1407A9C6AECB7A5D1407CE78A7CAE41A0AF77A3EB64B7937C3A71F5EBAEB8481A007343840132B73576869D5DA607BA9583D98133FE1C3C30FD989CEACDB4466F0400BA9211D293EE0FECFDDE4E854A1DAA1AA2062E97EB7FBAC0E10513B23B149AEE13D2A7DB81A59DB2A37F17D43A7BDC07633516D2BB0C9FB2D3C0025EC1E1E901AF4F7FE95798ABF546D83BB8F08BFFEF60192F8BBF3CE6D1F4EE1386286F9EA45B5F9F26DF253B0DFECEE4574B1348058207E229AE971674D287798B9EBF7862C49742EE13F27F691095B409F3581B1FB8CC3FDA19C2E94D70D14EE1BF44BEF4B5E7D8988BD8A1FE078C755364CA3BEF825E42822BD96658F26DCE623E838F54F8383E06B6E977B7A5683B2CDD02A9A162C37BDDE20CD0CFA7F4CAF64B519AD1E30449588F87EA13F9E330AF041387BD44BE26392BC0C7F560933FAE2EA5A6E4FBCD30D53A57F69C3B6D0919F4184DB620DE8BDE52F9DFA0E97320417BEFC55ACE71B2EB16473F0506228814D17DBF8A7E11878FAB664FDC5E34104EE891842B651D3E5FAC5C19961CDDA19DFAD9B563C1B974265B6D24CD489AB3A4BC752D8220090278000E807A807DB19B31438396EF0E0CD2EB8F06BC4890F6D011BEA02D35C32E202ECFDA208FEF547957DB8AABF7E41524FE7DC28D3495F615A4832E8E9B37215378A251B1B8EC4EDCB41387B65455C093A144511F40F616511B80DFE3238DCB849F998E02CEE3A590AD8E53B4AA5A5B0D131EEF7CE88B145D9F7F6F631FECF4E5582A6A83D3E1ADBFDE306420968680E6FD7B276BB46BE5858377A4A1E81815B6E0DB2EB81FEFCCCC4266EA875B9C1E55E427C66C9BB4BF3244DBAB3E31D77E89BA832676397CF02F1058B4D95A824035FD14CE63D426EF3CC30EBB4A2138E02D485AE1D7CD2545D8D8CDA54A027D334258A36DA8A9611B8527F57912E8976B889F9C752A05F9E3D916B7221060EEC4CD892E36ADCD7F4A6A8FADB518D8833209B81300FD1CE97896D73775E66985B2296378F7F140AAA233A06E8C07D7D9CD26038AC204A17FBAA031DA57B18666190ECE80A4ABF97991CE22C846FEA3CDCEB2261171875945C0EAB"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(988)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\Beni\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

- - - - - - - > 'lsass.exe'(1044)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(2640)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Alwil Software\Avast4\aswUpdSv.exe
d:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
c:\windows\system32\CNAB4RPK.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
d:\progra~1\MICROS~1\rapimgr.exe
d:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Common Files\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Completion time: 2009-05-15 17:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 14:34

Pre-Run: 15,141,441,536 bytes free
Post-Run: 15,263,113,216 bytes free

351 --- E O F --- 2009-05-12 19:19

BC AdBot (Login to Remove)

 


#2 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,805 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:05 AM

Posted 30 May 2009 - 01:13 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. You can find information on A/V control HERE

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,805 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:05 AM

Posted 16 June 2009 - 04:31 PM

Due to the lack of feedback, this Topic is now closed.

In case you still have problems, please start a new topic.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users