Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack This Log


  • This topic is locked This topic is locked
5 replies to this topic

#1 Ontabok

Ontabok

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 03 August 2012 - 11:14 AM

EDIT: MOVED to Virus,Trojan and Malware Removal Logs ~~boopme


Hello,

I was wondering if someone could take a look at my Hijack This Log to see if I have anything to remove. I've been dealing with a slow PC for a while and although I'm confident in most PC stuff, this is a little deep for me. I'm not really sure what all HJT shows? So, if more info is needed, just let me know.

Thanks,
Ontabok



________________________________________________________________________________________



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:03:17 AM, on 8/3/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\ArcGIS\License10.0\bin\lmgrd.exe
C:\Program Files\ArcGIS\License10.0\bin\lmgrd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\ArcGIS\License10.0\bin\ARCGIS.exe
C:\Program Files\Norton 360\Engine\6.2.1.5\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Zune\ZuneBusEnum.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Norton 360\Engine\6.2.1.5\ccSvcHst.exe
C:\Program Files\TeamViewer\Version7\TeamViewer.exe
C:\Program Files\TeamViewer\Version7\tv_w32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Printer Utility DCS\Appinterfaces\HPPUDS.exe
C:\Program Files\Hewlett-Packard\HP Printer Utility\HPPU.exe
C:\Program Files\Common Files\Hewlett-Packard\HP Printer Utility DCS\AppInterfaces\HPPUDH.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\ArcGIS\Desktop10.0\Bin\ArcMap.exe
C:\Program Files\ArcGIS\Desktop10.0\bin\AppROT.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HiJackThis\Crusty.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.2.1.5\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.2.1.5\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.2.1.5\coIEPlg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PowerPanel Personal Edition User Interaction] C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [PUStarter] C:\Program Files\Common Files\Hewlett-Packard\HP Printer Utility DCS\Appinterfaces\HPPUDS.exe
O4 - HKLM\..\Run: [RunPUTasktray] "C:\Program Files\Hewlett-Packard\HP Printer Utility\HPPU.exe" --regkeypath=Software\Hewlett-Packard\HP Printer Utility\HPPURun --valuename=InstallTTM
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://*.hp.com (HKLM)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265318042408
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342456641968
O18 - Protocol: HPPUDCS - {522CC7E5-F378-4F97-8BD7-125D17F5B332} - C:\Program Files\Common Files\Hewlett-Packard\HP Printer Utility DCS\APP\hplidcsapp.dll
O18 - Protocol: hppufile - {4BCA8E33-E18F-4358-9F6F-3C7206BCF72F} - C:\Program Files\Hewlett-Packard\HP Printer Utility\hpluCtrls.dll
O18 - Protocol: hppusam - {4BCA8E33-E18F-4358-9F6F-3C7206BCF72F} - C:\Program Files\Hewlett-Packard\HP Printer Utility\hpluCtrls.dll
O18 - Protocol: hppuzip - {4BCA8E33-E18F-4358-9F6F-3C7206BCF72F} - C:\Program Files\Hewlett-Packard\HP Printer Utility\hpluCtrls.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ArcGIS License Manager - Acresso Software Inc. - C:\Program Files\ArcGIS\License10.0\bin\lmgrd.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\6.2.1.5\ccSvcHst.exe
O23 - Service: Palm Novacom (NovacomD) - Palm - C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Cyber Power Systems, Inc. - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe

--
End of file - 10561 bytes

Edited by boopme, 03 August 2012 - 11:40 AM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,769 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:44 AM

Posted 08 August 2012 - 09:39 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Please download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Close any open browsers, and all other programs working. Make sure you save your file if working on a document.
  • Do not install any other programs until this if fixed.[/b]
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Some Rookit infection may damage your boot sector. The Windows Recovery Console may be needed to restore it. Do not bypass this installation. You may regret it.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: If you have difficulty properly disabling your protection programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

Do not mouse click ComboFix's window while it's running. That may cause it to stall

Note: If after running ComboFix you get this error message "Illegal operation attempted on a registry key that has been marked for deletion." when attempting to run a program all you need to do is restart the computer to reset the registry.
===

Third party programs if not up to date can be the cause of infiltration an infection.

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

Please post the logs and let me know if the problem persists.

#3 Ontabok

Ontabok
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 08 August 2012 - 11:46 AM

Ok...here goes!

First of all, thanks for the help! As I said earlier, I'm not too keen on trying to do something I'm not comfortable with. I've used ComboFix before, but that's it! I'm going to paste all the logs below!

ComboFix:


ComboFix 12-08-07.05 - Lee Harrell 08/08/2012 10:32:41.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1141 [GMT -5:00]
Running from: c:\documents and settings\Lee Harrell\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\81A2AF53AE.sys
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Lee Harrell\GoToAssistDownloadHelper.exe
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}\chrome.manifest
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}\chrome\content\_cfg.js
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}\chrome\content\c.js
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}\chrome\content\overlay.xul
c:\documents and settings\Lee Harrell\Local Settings\Application Data\{26ACE095-E6A6-4DD7-B7D2-D137F46399E3}\install.rdf
C:\Documents
C:\install.exe
c:\windows\system32\regobj.dll
c:\windows\system32\tmp.reg
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\system32\windrv.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BHDrvx86
-------\Legacy_IDSxpx86
-------\Service_BHDrvx86
-------\Service_IDSxpx86
.
.
((((((((((((((((((((((((( Files Created from 2012-07-08 to 2012-08-08 )))))))))))))))))))))))))))))))
.
.
2012-08-07 18:27 . 2012-08-07 18:27 -------- dc----w- c:\program files\Common Files\Macrovision Shared
2012-08-07 18:14 . 2012-08-07 18:14 -------- dc----w- c:\program files\Common Files\AnswerWorks 4.0
2012-08-07 18:11 . 2012-08-07 18:11 -------- dc----w- C:\Python26
2012-08-07 18:11 . 2012-08-07 18:11 -------- dc----w- c:\program files\Common Files\Data Dynamics
2012-08-07 18:11 . 2012-08-07 18:11 -------- dc----w- c:\program files\Common Files\Tom Sawyer Software
2012-08-07 14:35 . 2012-08-07 14:35 -------- dc----w- c:\documents and settings\Lee Harrell\Local Settings\Application Data\Temp
2012-08-06 17:18 . 2012-08-07 19:44 -------- dc----w- c:\program files\ESRI
2012-08-06 16:54 . 2012-08-07 20:18 -------- dc----w- c:\documents and settings\All Users\Application Data\ESRI
2012-08-06 16:54 . 2012-08-06 16:54 -------- dc----w- c:\documents and settings\Lee Harrell\Application Data\NCH Software
2012-08-06 16:20 . 2012-08-06 16:20 -------- dc----w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-08-06 15:27 . 2012-07-23 20:59 22400 -c--a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-08-06 14:56 . 2012-08-06 14:56 -------- dc----w- c:\documents and settings\All Users\Application Data\IObit
2012-08-06 14:55 . 2012-08-06 14:55 -------- dc----w- c:\documents and settings\Lee Harrell\Application Data\IObit
2012-08-06 14:55 . 2012-08-06 14:55 -------- dc----w- c:\program files\IObit
2012-08-06 14:31 . 2012-08-06 14:31 -------- dc----w- c:\program files\ERUNT
2012-08-06 14:15 . 2012-08-06 14:15 -------- dc----w- C:\Python27
2012-08-06 14:15 . 2012-08-07 20:23 -------- dc----w- c:\program files\Common Files\ArcGIS
2012-08-06 14:15 . 2012-08-07 19:20 -------- dc----w- c:\program files\ArcGIS
2012-08-03 16:50 . 2012-08-03 16:50 -------- dc----w- c:\documents and settings\All Users\Application Data\NCH Software
2012-07-30 18:12 . 2012-07-30 18:12 -------- dc----w- C:\usr
2012-07-30 18:08 . 2012-07-30 18:11 -------- dc----w- c:\program files\Kyocera
2012-07-25 18:08 . 2012-07-30 15:41 -------- dc----w- c:\documents and settings\Lee Harrell\Application Data\ESRI
2012-07-25 17:59 . 2012-07-25 17:59 -------- dc----w- c:\documents and settings\Lee Harrell\Application Data\Apple Computer
2012-07-19 21:37 . 2012-07-19 21:37 -------- dc----w- c:\program files\Conduit
2012-07-19 21:37 . 2012-07-24 18:34 -------- dc----w- c:\documents and settings\Lee Harrell\Local Settings\Application Data\Conduit
2012-07-10 14:12 . 2012-03-02 21:02 25728 -c--a-w- c:\windows\system32\drivers\lgandadb.sys
2012-07-10 14:12 . 2012-03-02 21:02 25088 -c--a-w- c:\windows\system32\drivers\lgandmodem.sys
2012-07-10 14:12 . 2012-03-02 21:02 20736 -c--a-w- c:\windows\system32\drivers\lganddiag.sys
2012-07-10 14:12 . 2012-03-02 21:02 20096 -c--a-w- c:\windows\system32\drivers\lgandgps.sys
2012-07-10 14:12 . 2012-03-02 21:02 14336 -c--a-w- c:\windows\system32\drivers\lgandbus.sys
2012-07-10 14:10 . 2012-07-10 14:10 -------- dc----w- C:\LGUS670
2012-07-09 19:04 . 2012-07-09 19:04 -------- dc----w- c:\documents and settings\Lee Harrell\temp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 19:02 . 2012-03-29 14:47 426184 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-02 19:02 . 2011-06-29 16:51 70344 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 18:46 . 2012-04-20 18:38 22344 -c--a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 17:42 . 2012-06-13 17:42 143872 -c--a-w- c:\windows\system32\javacpl.cpl
2012-06-13 17:42 . 2011-12-13 14:39 772592 -c--a-w- c:\windows\system32\npdeployJava1.dll
2012-06-13 17:42 . 2010-04-15 18:22 687600 -c--a-w- c:\windows\system32\deployJava1.dll
2012-06-13 13:19 . 2008-04-14 06:00 1866112 -c--a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-14 10:42 1372672 -c--a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 10:42 1172480 -c--a-w- c:\windows\system32\msxml3.dll
2012-06-04 22:35 . 2008-07-02 14:05 222448 -c--a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2008-04-14 10:42 152576 -c--a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2007-07-31 00:18 22040 -c--a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2007-07-31 00:19 15384 -c--a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2004-08-11 22:12 329240 -c--a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2004-08-11 22:12 219160 -c--a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2004-08-11 22:12 210968 -c--a-w- c:\windows\system32\wuweb.dll
2012-06-02 20:19 . 2010-02-04 21:15 45080 -c--a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2008-04-14 10:41 97304 -c--a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2007-07-31 00:19 15384 -c--a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2004-08-11 22:12 53784 -c--a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2004-08-11 22:12 35864 -c--a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2007-07-31 00:18 17944 -c--a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2004-08-11 22:12 577048 -c--a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2004-08-11 22:12 1933848 -c--a-w- c:\windows\system32\wuaueng.dll
2012-06-02 20:18 . 2008-07-02 14:05 275696 -c--a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18 . 2008-07-02 14:05 17136 -c--a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2008-04-14 10:41 599040 -c--a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:14 . 2012-05-16 15:14 138056 -c--a-w- c:\documents and settings\Lee Harrell\Application Data\PnkBstrK.sys
2012-05-16 15:13 . 2012-05-16 15:13 189248 -c--a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-16 15:08 . 2008-04-14 10:42 916992 -c--a-w- c:\windows\system32\wininet.dll
2012-05-15 10:18 . 2012-03-16 14:00 883008 -c--a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:18 . 2012-03-16 14:00 18771968 -c--a-w- c:\windows\system32\nvoglnt.dll
2012-05-15 10:18 . 2012-03-16 14:00 1000768 -c--a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:18 . 2011-07-11 13:43 4373248 -c--a-w- c:\windows\system32\nv4_disp.dll
2012-05-15 10:18 . 2011-07-11 13:43 2359808 -c--a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:18 . 2011-07-11 13:43 14014656 -c--a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-05-15 10:18 . 2011-04-15 16:23 65536 -c--a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:18 . 2011-04-15 16:23 6012928 -c--a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:18 . 2011-04-15 16:23 2530624 -c--a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:18 . 2011-04-15 16:23 2445120 -c--a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:18 . 2011-04-15 16:23 17543168 -c--a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 09:40 . 2012-03-16 14:01 54272 -c--a-w- c:\windows\system32\nvwddi.dll
2012-05-15 09:40 . 2012-03-16 14:01 143680 -c--a-w- c:\windows\system32\nvcolor.exe
2012-05-15 09:40 . 2012-03-16 14:01 15504192 -c--a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:40 . 2012-03-16 14:01 164160 -c--a-w- c:\windows\system32\nvsvc32.exe
2012-05-15 09:40 . 2012-03-16 14:01 108352 -c--a-w- c:\windows\system32\nvmctray.dll
2012-05-11 14:42 . 2008-04-14 10:42 1469440 -c--a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 14:42 . 2008-04-14 10:41 43520 -c--a-w- c:\windows\system32\licmgr10.dll
2012-05-11 11:38 . 2008-04-14 05:07 385024 -c--a-w- c:\windows\system32\html.iec
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-02-04 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 -c--a-w- c:\documents and settings\Lee Harrell\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 -c--a-w- c:\documents and settings\Lee Harrell\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 -c--a-w- c:\documents and settings\Lee Harrell\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 -c--a-w- c:\documents and settings\Lee Harrell\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunPUTasktray"="c:\program files\Hewlett-Packard\HP Printer Utility\HPPU.exe --regkeypath=Software\Hewlett-Packard\HP Printer Utility\HPPURun --valuename=InstallTTM" [X]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 137752]
"PowerPanel Personal Edition User Interaction"="c:\program files\CyberPower PowerPanel Personal Edition\pppeuser.exe" [2010-04-10 316864]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"PUStarter"="c:\program files\Common Files\Hewlett-Packard\HP Printer Utility DCS\Appinterfaces\HPPUDS.exe" [2011-05-05 73728]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GPS Pathfinder Office Connection Manager.lnk]
backup=c:\windows\pss\GPS Pathfinder Office Connection Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GPS Pathfinder Office Project Changer.lnk]
backup=c:\windows\pss\GPS Pathfinder Office Project Changer.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\Lee Harrell\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\PANDORA.TV\\PanService\\PandoraService.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"1036:TCP"= 1036:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0602010.005\symds.sys [5/17/2012 11:59 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0602010.005\symefa.sys [5/17/2012 11:59 PM 905336]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\0602010.005\ccsetx86.sys [5/17/2012 11:59 PM 132744]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0602010.005\ironx86.sys [5/17/2012 11:59 PM 149624]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [8/8/2008 11:15 AM 41456]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [8/6/2012 9:55 AM 913792]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\ArcGIS\License10.0\bin\lmgrd.exe [11/9/2010 10:25 AM 1386320]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\6.2.1.5\ccsvchst.exe [5/17/2012 11:58 PM 138232]
R2 NovacomD;Palm Novacom;c:\program files\Palm, Inc\novacomd\x86\novacomd.exe [6/24/2011 9:16 PM 61440]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [7/16/2012 9:31 AM 2673064]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\drivers\dc3d.sys [9/13/2010 8:55 AM 45288]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/7/2012 1:30 PM 106656]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/23/2012 4:33 PM 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [3/16/2012 9:01 AM 1262400]
S2 VBoxDrv;VBox Support Driver;\??\c:\program files\YouWave_Android\vb\VBoxDrv.sys --> c:\program files\YouWave_Android\vb\VBoxDrv.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3/29/2012 9:47 AM 250056]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [7/10/2012 9:12 AM 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [7/10/2012 9:12 AM 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [7/10/2012 9:12 AM 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [7/10/2012 9:12 AM 25088]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\lgandadb.sys [7/10/2012 9:12 AM 25728]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 11:58 AM 11336]
S3 esihdrv;esihdrv;\??\c:\docume~1\LEEHAR~1\LOCALS~1\Temp\esihdrv.sys --> c:\docume~1\LEEHAR~1\LOCALS~1\Temp\esihdrv.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/23/2012 4:33 PM 116648]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [8/5/2011 12:30 PM 268512]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 19:02]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-23 21:33]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-23 21:33]
.
2012-08-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3986978163-821291658-3868846798-1005Core.job
- c:\documents and settings\Lee Harrell\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-29 18:20]
.
2012-08-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3986978163-821291658-3868846798-1005UA.job
- c:\documents and settings\Lee Harrell\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-29 18:20]
.
2011-08-09 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 20:56]
.
2012-08-06 c:\windows\Tasks\SwitchReminder.job
- c:\program files\NCH Software\Switch\switch.exe [2012-08-03 16:54]
.
.
------- Supplementary Scan -------
.
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Open with WordPerfect
Trusted Zone: hp.com
TCP: DhcpNameServer = 12.127.16.67 12.127.16.68
.
- - - - ORPHANS REMOVED - - - -
.
Notify-AtiExtEvent - (no file)
SafeBoot-ati8vvxx.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-08 10:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\6.2.1.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\6.2.1.5\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3986978163-821291658-3868846798-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3986978163-821291658-3868846798-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
.
[HKEY_USERS\S-1-5-21-3986978163-821291658-3868846798-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2A78C231-EFA0-851F-EF91-185E5640D7FC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"eadefadaja"=hex:66,61,66,68,6b,63,6f,64,70,63,67,70,00,31
"dagealbb"=hex:64,62,68,67,61,67,6e,67,65,70,66,61,6d,6c,61,61,6c,64,68,6b,70,
66,65,69,70,6f,6d,67,6c,62,6b,6f,64,6e,70,6c,68,68,6a,66,00,00
"ialgghncmpbiomakdb"=hex:6a,61,61,6b,70,6e,6a,6b,67,62,65,6b,65,64,68,68,6a,62,
6b,6b,00,00
"hanfajgoifmpfoda"=hex:6a,61,61,6b,70,6e,6a,6b,67,62,65,6b,65,64,68,68,6a,62,
6b,6b,00,e0
.
[HKEY_USERS\S-1-5-21-3986978163-821291658-3868846798-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{46936BC0-FB02-A09C-D73A-E81031CB0440}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"faeamaoichba"=hex:68,61,67,6a,63,68,6f,6a,70,63,67,68,62,6f,63,69,00,ef
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\09\03\1c\15'.?"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1148)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(5940)
c:\windows\system32\WININET.dll
c:\documents and settings\Lee Harrell\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\ArcGIS\License10.0\bin\ARCGIS.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberPower PowerPanel Personal Edition\ppped.exe
c:\program files\Zune\ZuneBusEnum.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Common Files\Hewlett-Packard\HP Printer Utility DCS\AppInterfaces\HPPUDH.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\progra~1\MICROS~3\rapimgr.exe
.
**************************************************************************
.
Completion time: 2012-08-08 10:59:14 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-08 15:59
.
Pre-Run: 89,520,967,680 bytes free
Post-Run: 89,881,993,216 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - D520590CE485603A1D4ED1768554CFF3


Security Check:


Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Norton 360
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.62.0.1300
Java™ 7 Update 5
Adobe Flash Player 11.3.300.270
Adobe Reader X (10.1.3)
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 10%
````````````````````End of Log``````````````````````


ADWCleaner:


# AdwCleaner v1.800 - Logfile created 08/08/2012 at 11:14:37
# Updated 01/08/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Lee Harrell - LEE-911
# Running from : C:\Documents and Settings\Lee Harrell\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Conduit
Folder Found : C:\Program Files\Conduit

***** [Registry] *****

Key Found : HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Conduit

***** [Registre - GUID] *****

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Google Chrome v21.0.1180.60

File : C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1048 octets] - [08/08/2012 11:14:37]

########## EOF - C:\AdwCleaner[R1].txt - [1176 octets] ##########


Thanks for all the Help! I did all the steps you suggested so far.

Ontabok

#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,769 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:44 AM

Posted 09 August 2012 - 07:16 AM

Your logs are clean.

Remove the items found by adwcleaner.

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Any remaining issues?

#5 Ontabok

Ontabok
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:44 AM

Posted 10 August 2012 - 03:15 PM

I did everything suggested and this is what was logged.


# AdwCleaner v1.800 - Logfile created 08/09/2012 at 10:07:20
# Updated 01/08/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Lee Harrell - LEE-911
# Running from : C:\Documents and Settings\Lee Harrell\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Conduit
Folder Deleted : C:\Program Files\Conduit

***** [Registry] *****

Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Conduit

***** [Registre - GUID] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Google Chrome v21.0.1180.75

File : C:\Documents and Settings\Lee Harrell\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1177 octets] - [08/08/2012 11:14:37]
AdwCleaner[S1].txt - [1118 octets] - [09/08/2012 10:07:20]

########## EOF - C:\AdwCleaner[S1].txt - [1246 octets] ##########


Thanks for the Help, Nasdaq

Ontabok

#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,769 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:44 AM

Posted 11 August 2012 - 07:16 AM

If all is well:

Time for some housekeeping

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
===

Please double click on adwcleaner.exe to run the tool.
Click on Uninstall.
Confirm with Yes.

Delete the other tools we used.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users