Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Log Combobox


  • This topic is locked This topic is locked
2 replies to this topic

#1 ryvboy

ryvboy

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:11 AM

Posted 08 February 2010 - 08:29 AM

Hi,
thanks for the help...

this is the log of the scan of combobox... is it normal that it deleted msconfig?

thanks a lot

QUOTE
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Vale\imPlayok.exe
c:\windows\logfile32.txt
c:\windows\msdrv32.exe
c:\windows\system32\21.scr
c:\windows\system32\46.scr
c:\windows\system32\62.scr
c:\windows\system32\66.scr
c:\windows\system32\75.scr
c:\windows\system32\81.scr
c:\windows\system32\Desktop_.ini
c:\windows\system32\imPlayok.exe
c:\windows\system32\incognito.exe
c:\windows\system32\msconfig.exe
D:\AUTORUN.INF

c:\windows\system32\midimap.dll . . . infetto!!

c:\windows\system32\drivers\cdrom.sys . . . is missing!!

.
((((((((((((((((((((((((( Files Creati Da 2010-01-08 al 2010-02-08 )))))))))))))))))))))))))))))))))))
.

2010-02-08 11:42 . 2010-02-08 11:42 41085 ----a-w- C:\minut.exe
2010-02-06 14:01 . 2010-02-06 14:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-02-03 11:54 . 2010-02-03 11:54 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\FastStone
2010-01-14 13:04 . 2010-01-14 13:04 -------- d-----w- c:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Google
2010-01-14 12:59 . 2010-01-28 17:07 -------- d-----w- c:\documents and settings\Vale\Impostazioni locali\Dati applicazioni\Temp
2010-01-14 12:59 . 2010-01-14 12:59 -------- d-----w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\Google
2010-01-14 12:59 . 2010-01-28 17:07 -------- d-----w- c:\programmi\Google
2010-01-14 12:59 . 2010-01-14 13:09 -------- d-----w- c:\documents and settings\Vale\Impostazioni locali\Dati applicazioni\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 13:12 . 2009-12-19 22:48 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\Skype
2010-02-08 12:34 . 2009-12-19 23:26 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\skypePM
2010-02-07 02:07 . 2010-01-01 23:35 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\vlc
2010-01-11 01:11 . 2009-12-20 00:33 2512 ----a-w- c:\documents and settings\LocalService\Impostazioni locali\Dati applicazioni\FontCache3.0.0.0.dat
2010-01-04 23:57 . 2010-01-04 23:57 -------- d-----w- c:\programmi\IrfanView
2010-01-04 22:53 . 2010-01-04 22:53 -------- d-----w- c:\programmi\WIDCOMM
2010-01-04 21:36 . 2001-08-31 15:00 79292 ----a-w- c:\windows\system32\perfc010.dat
2010-01-04 21:36 . 2001-08-31 15:00 478808 ----a-w- c:\windows\system32\perfh010.dat
2010-01-04 21:34 . 2010-01-04 21:34 -------- d-----w- c:\programmi\UTETGDU
2010-01-03 21:58 . 2010-01-03 21:58 -------- d-----w- c:\programmi\DivX
2010-01-03 21:58 . 2010-01-03 21:58 -------- d-----w- c:\programmi\File comuni\DivX Shared
2010-01-03 21:51 . 2010-01-03 21:51 -------- d-----w- c:\programmi\MP3Gain
2010-01-03 17:42 . 2009-12-19 20:34 -------- d-----w- c:\programmi\eMule
2010-01-03 17:39 . 2010-01-03 17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-03 17:39 . 2010-01-03 17:39 -------- d-----w- c:\programmi\Java
2010-01-03 17:38 . 2010-01-03 17:38 152576 ----a-w- c:\documents and settings\Vale\Dati applicazioni\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-03 17:38 . 2010-01-03 17:38 79488 ----a-w- c:\documents and settings\Vale\Dati applicazioni\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-03 17:03 . 2010-01-03 16:50 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\PhotoME
2010-01-03 16:58 . 2010-01-03 16:58 -------- d-----w- c:\programmi\Opanda
2010-01-03 13:47 . 2010-01-03 13:47 -------- d-----w- c:\programmi\Microsoft Silverlight
2009-12-30 00:45 . 2009-12-30 00:45 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-12-30 00:45 . 2009-12-30 00:45 -------- d-----w- c:\programmi\NETGEAR
2009-12-30 00:45 . 2009-12-19 17:56 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-12-29 23:36 . 2009-12-29 23:36 -------- d-----w- c:\programmi\File comuni\Real
2009-12-29 23:36 . 2009-12-29 23:36 -------- d-----w- c:\programmi\File comuni\xing shared
2009-12-29 23:36 . 2009-12-19 17:37 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-29 23:36 . 2009-12-29 23:36 -------- d-----w- c:\programmi\Real
2009-12-29 23:21 . 2009-12-29 23:21 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\Media Player Classic
2009-12-20 16:55 . 2009-12-20 16:55 -------- d-----w- c:\programmi\Microsoft LifeCam
2009-12-20 16:29 . 2009-12-20 16:29 -------- d-----w- c:\programmi\Driver Magician Lite
2009-12-20 00:32 . 2009-12-20 00:32 -------- d-----w- c:\programmi\MSBuild
2009-12-20 00:32 . 2009-12-20 00:32 -------- d-----w- c:\programmi\Reference Assemblies
2009-12-19 23:26 . 2009-12-19 23:26 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-19 22:48 . 2009-12-19 22:47 -------- d-----r- c:\programmi\Skype
2009-12-19 22:47 . 2009-12-19 22:47 -------- d-----w- c:\programmi\File comuni\Skype
2009-12-19 22:47 . 2009-12-19 22:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Skype
2009-12-19 22:44 . 2009-12-19 22:44 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-12-19 22:44 . 2009-12-19 22:44 14960 ----a-w- c:\documents and settings\Vale\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-12-19 20:39 . 2009-12-19 20:25 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\Winamp
2009-12-19 20:34 . 2009-12-19 20:30 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\DAEMON Tools Lite
2009-12-19 20:31 . 2009-12-19 20:31 -------- d-----w- c:\programmi\DAEMON Tools Lite
2009-12-19 20:31 . 2009-12-19 20:31 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-19 20:30 . 2009-12-19 20:30 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DAEMON Tools Lite
2009-12-19 20:30 . 2009-12-19 20:30 -------- d-----w- c:\programmi\FastStone Photo Resizer
2009-12-19 20:27 . 2009-12-19 20:25 -------- d-----w- c:\programmi\Winamp
2009-12-19 19:38 . 2009-12-19 19:38 0 ----a-w- c:\windows\nsreg.dat
2009-12-19 19:35 . 2009-12-19 19:35 -------- d-----w- c:\programmi\Alwil Software
2009-12-19 19:31 . 2009-12-19 19:31 -------- d-----w- c:\programmi\Realtek
2009-12-19 19:30 . 2009-12-19 19:30 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-12-19 17:56 . 2009-12-19 17:56 -------- d-----w- c:\programmi\Atheros
2009-12-19 17:56 . 2009-12-19 17:56 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Atheros
2009-12-19 17:56 . 2009-12-19 17:56 -------- d-----w- c:\documents and settings\Vale\Dati applicazioni\InstallShield
2009-12-19 17:55 . 2009-12-19 17:55 -------- d-----w- c:\programmi\DIFX
2009-12-19 17:52 . 2009-12-19 17:52 -------- d-----w- c:\programmi\Intel
2009-12-19 17:45 . 2009-12-19 17:45 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-12-19 17:44 . 2009-12-19 17:44 -------- d-----w- c:\programmi\Windows Live
2009-12-19 17:42 . 2009-12-19 17:42 -------- d-----w- c:\programmi\Foxit Reader
2009-12-19 17:42 . 2009-12-19 17:42 -------- d-----w- c:\programmi\7-Zip
2009-12-19 17:42 . 2009-12-19 17:42 -------- d-----w- c:\programmi\ImgBurn
2009-12-19 17:41 . 2009-12-19 17:41 -------- d-----w- c:\programmi\VideoLAN
2009-12-19 17:41 . 2009-12-19 17:41 -------- d-----w- c:\programmi\CCleaner
2009-12-19 17:39 . 2009-12-19 17:39 -------- d-----w- c:\programmi\Servizi in linea
2009-12-19 17:37 . 2009-12-19 17:37 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-19 17:37 . 2009-12-19 17:37 -------- d-----w- c:\programmi\Utilities
2009-12-19 17:37 . 2009-12-19 17:37 -------- d-----w- c:\programmi\System
2009-11-24 23:54 . 2009-12-19 19:35 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-12-19 19:35 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-12-19 19:35 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-12-19 19:35 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-12-19 19:35 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-12-19 19:35 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-12-19 19:35 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-12-19 19:35 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-12-19 19:35 97480 ----a-w- c:\windows\system32\AvastSS.scr
.

------- Sigcheck -------

[-] 2008-06-07 . 030DC4D48CC2B894FEE2F390D8E66AD5 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys

[-] 2008-09-26 . 6DC43081C760EEC1130D2C8C145DF375 . 549888 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2008-09-26 . 6C01B44D2A5A66137E80E8537E761914 . 111616 . . [5.4.3790.5512] . . c:\windows\system32\wuauclt.exe

[-] 2008-09-26 . 8B2A7229651894B07A5F750E1FEF99CC . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2009-10-21 . 8927DF23BEAE23755EE15216138DA2B1 . 2326784 . . [5.1.2600.5657] . . c:\windows\system32\ntoskrnl.exe

[-] 2008-09-26 . 19CB8AA5B83D0017EB9A9126AA2EEB55 . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-09-26 . 91B6AAC828F8BBE1796275424E44DFB0 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

[-] 2009-10-21 . 58BDBA0F02989A968DE4EE6A8C99C3EC . 2203648 . . [5.1.2600.5657] . . c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-09-27 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"LifeCam"="c:\programmi\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]
"VX1000"="c:\windows\vVX1000.exe" [2009-06-26 757248]
"TkBellExe"="c:\programmi\File comuni\Real\Update_OB\realsched.exe" [2009-12-29 198160]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2010-01-03 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-09-26 25088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]
"_nltide_3"="advpack.dll" [2009-03-08 128512]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
NETGEAR WG111v2 Smart Wizard.lnk - c:\programmi\NETGEAR\WG111v2\WG111v2.exe [2009-12-30 1261568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^BTTray.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-12-29 23:36 198160 ----a-w- c:\programmi\File comuni\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Programmi\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [19/12/2009 20.35.25 114768]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\programmi\System\CPL Bonus\vcdrom.sys [19/12/2009 18.37.15 8576]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/12/2009 20.35.25 20560]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [30/12/2009 1.45.38 272128]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19/12/2009 21.31.16 691696]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [14/01/2010 13.59.05 135664]

--- Altri Servizi/Drivers In Memoria ---

*NewlyCreated* - VCDROM
.
Contenuto della cartella 'Scheduled Tasks'

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-14 12:59]

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-01-14 12:59]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.com/
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Locate Spot on Map by GPS - c:\programmi\Opanda\IExif 2.3\IExifMap.htm
IE: View Exif/GPS/IPTC with IExif - c:\programmi\Opanda\IExif 2.3\IExifCom.htm
FF - ProfilePath - c:\documents and settings\Vale\Dati applicazioni\Mozilla\Firefox\Profiles\g6h04qpe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - component: c:\programmi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\programmi\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 14:20
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\scecli.dll
.
Ora fine scansione: 2010-02-08 14:21:58
ComboFix-quarantined-files.txt 2010-02-08 13:21

Pre-Run: 12.320.882.688 byte disponibili
Post-Run: 12.551.950.336 byte disponibili

- - End Of File - - 71966EDF979082F57627162E0B3DCFD5


BC AdBot (Login to Remove)

 


#2 pwgib

pwgib

  • Malware Response Team
  • 2,956 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:God's Country
  • Local time:09:11 AM

Posted 15 February 2010 - 11:31 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log

PW

#3 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:11 PM

Posted 23 February 2010 - 12:32 PM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users