Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

combo fix


  • This topic is locked This topic is locked
5 replies to this topic

#1 k20sikvic

k20sikvic

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 08 September 2010 - 09:46 PM

ComboFix 10-09-08.01 - Owner 09/08/2010 22:18:35.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.472 [GMT -4:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Local Settings\Application Data\{7683A927-592D-40DF-822D-13368C5657D3}
c:\documents and settings\Owner\Local Settings\Application Data\{7683A927-592D-40DF-822D-13368C5657D3}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{7683A927-592D-40DF-822D-13368C5657D3}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{7683A927-592D-40DF-822D-13368C5657D3}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{7683A927-592D-40DF-822D-13368C5657D3}\install.rdf
c:\windows\system32\Drivers\csrcuacr.sys

c:\windows\explorer.exe . . . is infected!!

c:\windows\system32\winlogon.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2010-08-09 to 2010-09-09 )))))))))))))))))))))))))))))))
.

2010-09-09 01:59 . 2010-09-09 01:59 -------- d-----w- c:\windows\system32\wbem\snmp
2010-09-09 01:59 . 2010-09-09 01:59 -------- d-----w- c:\windows\srchasst
2010-09-09 01:59 . 2010-09-09 01:59 -------- d-----w- c:\windows\system32\xircom
2010-09-09 01:59 . 2010-09-09 01:59 -------- d-----w- c:\windows\msagent
2010-09-09 01:59 . 2010-09-09 01:59 -------- d-----w- c:\program files\microsoft frontpage
2010-09-09 00:11 . 2010-09-09 00:11 -------- d-----w- C:\found.000
2010-09-07 00:19 . 2010-09-07 02:19 2843 ----a-w- c:\windows\Bhibuy.dat
2010-09-07 00:19 . 2010-09-07 00:19 0 ----a-w- c:\windows\Gbucowohon.bin
2010-09-07 00:17 . 2010-09-07 10:57 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\nteuagucc
2010-08-25 13:28 . 2010-08-25 13:28 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-08-11 21:28 . 2010-08-11 21:28 -------- d-----w- c:\program files\iPod
2010-08-11 21:28 . 2010-08-11 21:29 -------- d-----w- c:\program files\iTunes
2010-08-11 21:28 . 2010-08-11 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-11 21:14 . 2010-08-11 21:14 -------- d-----w- c:\program files\Bonjour
2010-08-11 21:09 . 2010-08-11 21:09 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-09 02:05 . 2010-01-21 01:42 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2010-09-07 11:07 . 2009-12-16 22:21 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-07 11:07 . 2009-12-16 22:21 -------- d-----w- c:\program files\Symantec
2010-09-07 11:07 . 2009-12-16 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-09-07 11:06 . 2010-01-21 01:24 -------- d-----w- c:\program files\LogMeIn
2010-09-06 23:34 . 2010-01-21 01:09 -------- d-----w- c:\documents and settings\Owner\Application Data\TeraCopy
2010-08-11 21:28 . 2010-01-21 01:37 -------- d-----w- c:\program files\Common Files\Apple
2010-08-11 21:20 . 2009-12-16 22:11 -------- d-----w- c:\program files\QT Lite
2010-07-28 00:55 . 2010-07-28 00:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-07-28 00:55 . 2010-07-28 00:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-28 00:29 . 2010-07-28 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-14 14:31 . 2009-12-16 21:15 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
.

------- Sigcheck -------

[-] 2008-08-22 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2008-04-14 . 803B37C2B7BABCEA1B4615347083BD46 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2008-04-14 . CDAAF797DF22553896EB5AFB66A5A56F . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe



c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-01-21 289584]
"Desktop Software"="c:\program files\Common Files\SupportSoft\bin\bcont.exe" [2009-04-24 1025320]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-08-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"QuickTime Task"="c:\program files\QT Lite\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"Agajiyovupomub"="c:\windows\erabinurifucipis.dll" [2008-04-14 200192]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-14 99840]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

S0 yhdeyrl;yhdeyrl;c:\windows\system32\drivers\cutter.sys --> c:\windows\system32\drivers\cutter.sys [?]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys --> c:\program files\LogMeIn\x86\RaInfo.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jhyqgd9h.default\
FF - prefs.js: browser.startup.homepage - hxxp://gamebox.my-quick-search.com/?hp=df
FF - prefs.js: keyword.URL - hxxp://gamebox.my-quick-search.com/search.aspx?srch=ku&q=
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jhyqgd9h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-08 22:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\LMIinit.dll
.
Completion time: 2010-09-08 22:22:32
ComboFix-quarantined-files.txt 2010-09-09 02:22
ComboFix2.txt 2010-09-09 02:02

Pre-Run: 15,182,487,552 bytes free
Post-Run: 15,176,249,344 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 32323A1018FFF793CE750634C8999F91


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:18 PM

Posted 15 September 2010 - 07:38 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks thumbup2.gif
Posted Image
m0le is a proud member of UNITE

#3 k20sikvic

k20sikvic
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:18 PM

Posted 19 September 2010 - 07:55 PM

Hi and Thanks!

#4 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:18 PM

Posted 20 September 2010 - 08:47 AM

Hi,

We'll start with some information

Please note: ComboFix is an extremely powerful tool which should only be used when instructed to do so by someone who has been properly trained. ComboFix is intended by its creator to be "used under the guidance and supervision of an expert." It is NOT for private use. Please read Combofix's Disclaimer.

Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.


Please now run Combofix again - make sure you agree to any updates. Instructions are below.

Please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop making sure you rename it comfix.exe
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Comfix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Posted Image
m0le is a proud member of UNITE

#5 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:18 PM

Posted 23 September 2010 - 06:18 PM

Hi,

I have not had a reply from you for 3 days. Can you please tell me if you still need help with your computer as I am unable to help other members with their problems while I have your topic still open. The time taken between posts can also change the situation with your PC making it more difficult to help you.

If you like you can PM me.

Thanks,


m0le
Posted Image
m0le is a proud member of UNITE

#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:18 PM

Posted 24 September 2010 - 07:25 PM

This topic has been closed.

If you're the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users