Unsolved
This post is more than 5 years old
8 Posts
0
1572
July 16th, 2008 05:00
taskmanager disabled after reboot
Hello, I scanned my computer with several antivirus-software. Most of the originally found viruses seem to be removed, but the taskmanager still is disabled everytime the pc is rebooted.
I hope you can help me with this.
This is the latest HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:30:54, on 16.07.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nipalsm.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
C:\Program Files\PenScope\PenScope\TPPOLL10.EXE
C:\WINDOWS\system32\winds32.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://aquanet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.5.0.150:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.*.*.*; 190.100.205.*;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [niDevMon] C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
O4 - HKLM\..\Run: [TPPOLL10] C:\Program Files\PenScope\PenScope\TPPOLL10.EXE
O4 - HKLM\..\Run: [System32] C:\WINDOWS\system32\winds32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O14 - IERESET.INF: START_PAGE_URL=http://aquanet
O16 - DPF: {304171C0-65EA-4B51-B5D9-93A311E26EB1} (MxPEG_ActiveX Control) - http://10.5.1.96/cgi-bin/MxPEG_ActiveX.cab?dummy=9343383
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164960987482
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = glamox.local
O17 - HKLM\Software\..\Telephony: DomainName = glamox.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = glamox.local
O23 - Service: FLIR Camera Monitor (CameraMonitor) - FLIR Systems - C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
--
End of file - 5783 bytes


aM-
54 Posts
0
July 16th, 2008 08:00
try download this software
http://www.ognizer.net/downloads/Ultimate%20Washer/uw2rc2.zip
this software will fix Missing Task Manager, Folder Options, Registry Editor, Run, Search & Command Prompt.
After download, unzip thats and run it.
To fix your problem, click Registry's tab and click at button Repair Registry.
aqua08
8 Posts
0
July 16th, 2008 09:00
mh.. that didn´t really work. the tool only enables the taskmanager (what I had tried before in the registry) temporarily. after reboot it is disabled again....
another idea?
bamajim
10.4K Posts
0
July 16th, 2008 12:00
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
"The world is what you make of it"
aqua08
8 Posts
0
July 16th, 2008 12:00
ehm... this is a long log.... ?
ComboFix 08-07-14.2 - Administrator 2008-07-16 15:29:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.568 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\combofix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 24064 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\Install.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\brlabor4\Application Data\install.dat
C:\WINDOWS\msserv.config
C:\WINDOWS\msserv.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\11422561741.dll
C:\WINDOWS\system32\70534.exe
C:\WINDOWS\system32\dflgh8jkd2q1.exe
C:\WINDOWS\system32\dflgh8jkd2q2.exe
C:\WINDOWS\system32\dflgh8jkd2q5.exe
C:\WINDOWS\system32\dflgh8jkd2q6.exe
C:\WINDOWS\system32\dflgh8jkd2q7.exe
C:\WINDOWS\system32\dflgh8jkd2q8.exe
C:\WINDOWS\system32\Dll.dll
C:\WINDOWS\system32\drivers\Khye57.sys
C:\WINDOWS\system32\drivers\Winxe38.sys
C:\WINDOWS\system32\icqmlib.exe
C:\WINDOWS\system32\iepref32.dll
C:\WINDOWS\system32\ierplc.dll
C:\WINDOWS\system32\ips.dll
C:\WINDOWS\system32\KernelDrv.exe
C:\WINDOWS\system32\ksvcl.dll
C:\WINDOWS\system32\lanmandrv.sys
C:\WINDOWS\system32\lanmanwrk.exe
C:\WINDOWS\system32\laprxy.dllexe
C:\WINDOWS\system32\maxpaynow1.exe
C:\WINDOWS\system32\maxpaynowti1.exe
C:\WINDOWS\system32\msdefender.exe
C:\WINDOWS\system32\ocxapi.dll
C:\WINDOWS\system32\ocxloader.exe
C:\WINDOWS\system32\qmopt.dll
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\vedxg3am1et3.exe
C:\WINDOWS\system32\WinCtrl32.dl_
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\winds32.exe
----- BITS: Possible infected sites -----
hxxp://debremsus01
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CCEVTSVC
-------\Legacy_FCI
-------\Legacy_KHYE57
-------\Legacy_LANMANDRV
-------\Legacy_WINXE38
-------\Service_Khye57
-------\Service_Winxe38
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 )))))))))))))))))))))))))))))))
.
2008-07-16 13:43 . 2008-07-16 13:43 36,352 --a------ C:\WINDOWS\system32\drivers\843lozjc.exe
2008-07-16 13:33 . 2008-07-16 13:33
2008-07-16 13:13 . 2008-07-16 13:41 34,468 --a------ C:\WINDOWS\system32\kcopt.dll
2008-07-16 12:47 . 2008-07-16 12:47 29 --a------ C:\WINDOWS\system32\opurerdp.tmp
2008-07-16 12:46 . 2008-07-16 12:46 15,360 --a------ C:\WINDOWS\system32\wpx33.cpx
2008-07-16 12:46 . 2008-07-16 12:46 0 --a------ C:\12.tmp
2008-07-16 12:43 . 2008-07-16 12:43
2008-07-16 12:40 . 2008-07-16 12:41
2008-07-16 12:23 . 2008-07-16 12:23
2008-07-16 12:04 . 2004-08-04 14:00 119,808 --a--c--- C:\WINDOWS\system32\dllcache\winmine.exe
2008-07-16 12:04 . 2004-08-04 14:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-07-16 12:04 . 2004-08-04 14:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2008-07-16 12:04 . 2004-08-04 14:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-07-16 12:04 . 2004-08-04 14:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-07-16 12:04 . 2004-08-04 14:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-07-16 12:04 . 2004-08-04 14:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-07-16 12:04 . 2004-08-04 14:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-07-16 12:04 . 2004-08-04 14:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-07-16 12:02 . 2004-08-04 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-07-16 12:01 . 2004-08-04 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-07-16 12:00 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-16 11:58 . 2004-08-04 14:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-07-16 10:04 . 2008-07-16 10:04 23,484 --a------ C:\WINDOWS\Microsoft Outlook.FAV
2008-07-16 09:48 . 2008-02-12 14:59 1,306,624 --a------ C:\WINDOWS\system32\msxml6.dll
2008-07-16 09:48 . 2008-02-12 02:48 79,872 --a------ C:\WINDOWS\system32\msxml6r.dll
2008-07-16 09:39 . 2008-02-12 03:13 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-07-16 09:38 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\ 003374_.tmp
2008-07-16 08:14 . 2008-07-16 08:14
2008-07-16 07:53 . 2008-07-16 08:30
2008-07-16 07:42 . 2008-07-16 07:43
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 12:43
2008-07-16 07:05 . 2008-07-16 13:42
2008-07-15 16:08 . 2008-07-16 07:05
2008-07-15 13:16 . 2008-07-15 13:16 0 --a------ C:\23990098.$$$
2008-07-15 11:17 . 2008-07-15 11:42 26 --a------ C:\WINDOWS\Lic.xxx
2008-07-15 11:16 . 2008-07-15 13:52
2008-07-15 11:16 . 2004-08-04 01:56 146,432 --a------ C:\WINDOWS\R.COM
2008-07-15 11:16 . 2004-08-04 01:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-07-15 11:09 . 2008-07-15 11:09
2008-07-15 11:03 . 2008-07-15 11:03 300 --a------ C:\WINDOWS\wininit.ini
2008-07-15 10:33 . 2008-07-16 07:08
2008-07-14 08:41 . 2008-07-15 13:52
2008-07-10 16:39 . 2008-07-10 16:39 44 --a------ C:\WINDOWS\73334xxx00_AN.PJT
2008-07-10 16:12 . 2008-07-10 16:12 44 --a------ C:\WINDOWS\73334xxx00_BE.PJT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 06:29 --------- d-----w C:\Program Files\Google
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 08:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 11:25 493024]
"niDevMon"="C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" [2007-02-24 02:34 92960]
"TPPOLL10"="C:\Program Files\PenScope\PenScope\TPPOLL10.EXE" [2007-05-10 20:57 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\brlabor4\Start Menu\Programs\Startup\
Shortcut to hardcopy.lnk - C:\Program Files\Hardcopy\hardcopy.exe [2004-07-26 18:49:30 1093632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10010:TCP"= 10010:TCP:190.100.0.0/255.255.0.0:Enabled:AdAware
"2868:TCP"= 2868:TCP:190.100.0.0/255.255.0.0:Enabled:NVC
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2007-02-15 22:59]
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\WINDOWS\system32\drivers\nipbcfk.sys [2007-02-15 17:23]
R2 CameraMonitor;FLIR Camera Monitor;C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe [2006-06-08 13:58]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 10:01]
R2 glpntdrv;glpntdrv;C:\WINDOWS\system32\drivers\glpntdrv.sys [1998-11-25 17:48]
R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 02:29]
R2 mxssvr;NI Configuration Manager;C:\Program Files\National Instruments\MAX\nimxs.exe [2007-02-22 08:46]
R2 ni488enumsvc;NI-488.2 Enumeration Service;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nidevldu;NI Device Loader;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nipxirmk;nipxirmk;C:\WINDOWS\system32\drivers\nipxirmkl.sys [2007-02-22 11:18]
R2 NITaggerService;National Instruments Variable Engine;C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2007-02-06 22:47]
R2 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiKl.sys [2007-02-23 10:25]
R3 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimkl.sys [2007-02-21 22:20]
R3 nimdbgk;nimdbgk;C:\WINDOWS\system32\drivers\nimdbgkl.sys [2007-02-21 21:46]
R3 nimru2k;nimru2k;C:\WINDOWS\system32\drivers\nimru2kl.sys [2007-02-21 22:39]
R3 nimstsk;nimstsk;C:\WINDOWS\system32\drivers\nimstskl.sys [2007-02-25 20:12]
R3 nimxdfk;nimxdfk;C:\WINDOWS\system32\drivers\nimxdfkl.sys [2007-02-21 22:10]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);C:\WINDOWS\system32\Drivers\icd2w2k.sys [2004-03-22 02:43]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 02:27]
S3 CA_LIC_SRVR;CA License Server;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 02:41]
S3 DCamUSBTP10;Pen Scope;C:\WINDOWS\system32\Drivers\TP6810.sys [2007-07-26 19:56]
S3 FLIRUSBNET;FLIR USB Network Adapter;C:\WINDOWS\system32\DRIVERS\FLIRUSB.sys [2006-05-05 13:20]
S3 lvalarmk;lvalarmk;C:\WINDOWS\system32\drivers\lvalarmk.sys [2007-01-11 10:18]
S3 ni1006k;NI PXI-1006 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1006k.sys [2007-02-22 11:40]
S3 ni1045k;NI PXI-1045 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1045kl.sys [2007-02-22 11:43]
S3 ni488lock;NI-488.2 Locking Service;C:\WINDOWS\system32\drivers\ni488lock.sys [2007-02-26 12:40]
S3 nicdrk;nicdrk;C:\WINDOWS\system32\drivers\nicdrkl.sys [2007-02-22 18:18]
S3 nidmxfk;nidmxfk;C:\WINDOWS\system32\drivers\nidmxfkl.sys [2007-02-25 20:12]
S3 nidsark;nidsark;C:\WINDOWS\system32\drivers\nidsarkl.sys [2007-02-23 17:43]
S3 niemrk;niemrk;C:\WINDOWS\system32\drivers\niemrkl.sys [2007-02-25 19:13]
S3 niesrk;niesrk;C:\WINDOWS\system32\drivers\niesrkl.sys [2007-02-25 19:13]
S3 nifslk;nifslk;C:\WINDOWS\system32\drivers\nifslkl.sys [2007-02-22 13:21]
S3 nimsdrk;nimsdrk;C:\WINDOWS\system32\drivers\nimsdrkl.sys [2007-02-25 20:10]
S3 nimslk;nimslk;C:\WINDOWS\system32\drivers\nimslk.dll [2006-12-18 12:55]
S3 nimsrlk;nimsrlk;C:\WINDOWS\system32\drivers\nimsrlk.dll [2006-12-18 12:55]
S3 nimxpk;nimxpk;C:\WINDOWS\system32\drivers\nimxpkl.sys [2007-02-22 13:26]
S3 ninshsdk;ninshsdk;C:\WINDOWS\system32\drivers\ninshsdkl.sys [2007-02-23 17:25]
S3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbkl.sys [2007-02-21 21:39]
S3 nipalfwedl;nipalfwedl;C:\WINDOWS\system32\drivers\nipalfwedl.sys [2007-02-15 23:00]
S3 nipalusbedl;nipalusbedl;C:\WINDOWS\system32\drivers\nipalusbedl.sys [2007-02-15 23:00]
S3 nipxigpk;NI PXI Generic Chassis Pilot;C:\WINDOWS\system32\drivers\nipxigpk.sys [2007-02-22 11:45]
S3 niscdk;niscdk;C:\WINDOWS\system32\drivers\niscdkl.sys [2007-02-26 16:31]
S3 nisdigk;nisdigk;C:\WINDOWS\system32\drivers\nisdigkl.sys [2007-02-25 19:11]
S3 nisftk;nisftk;C:\WINDOWS\system32\drivers\nisftkl.sys [2007-02-24 00:17]
S3 nismbusk;nismbusk;C:\WINDOWS\system32\drivers\nismbusk.sys [2007-02-22 11:34]
S3 nispdk;nispdk;C:\WINDOWS\system32\drivers\nispdkl.sys [2007-02-26 16:31]
S3 nissrk;nissrk;C:\WINDOWS\system32\drivers\nissrkl.sys [2007-02-25 19:13]
S3 nistc2k;nistc2k;C:\WINDOWS\system32\drivers\nistc2kl.sys [2007-02-22 20:17]
S3 nistcrk;nistcrk;C:\WINDOWS\system32\drivers\nistcrkl.sys [2007-02-23 03:14]
S3 niswdk;niswdk;C:\WINDOWS\system32\drivers\niswdkl.sys [2007-02-23 20:44]
S3 nitiork;nitiork;C:\WINDOWS\system32\drivers\nitiorkl.sys [2007-02-23 15:54]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWKl.sys [2007-02-22 10:42]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciKl.sys [2007-02-23 10:25]
S3 niwfrk;niwfrk;C:\WINDOWS\system32\drivers\niwfrkl.sys [2007-02-25 19:13]
S3 nixsrk;nixsrk;C:\WINDOWS\system32\drivers\nixsrkl.sys [2007-02-25 19:13]
S3 TTUSB1;TTUSB1.SYS TechTools USB device driver;C:\WINDOWS\system32\Drivers\TTUSB1.sys [2007-06-25 07:31]
S3 usb6xxxk;usb6xxxk;C:\WINDOWS\system32\drivers\usb6xxxk.sys [2007-02-25 19:11]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-msdefender - C:\WINDOWS\system32\msdefender.exe
HKLM-Run-lanmanwrk.exe clean - C:\WINDOWS\System32\lanmanwrk.exe
HKLM-Run-KernelDrv.exe clean - C:\WINDOWS\System32\KernelDrv.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 15:35:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
.
**************************************************************************
.
Completion time: 2008-07-16 15:37:54 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-07-16 13:37:47
Pre-Run: 3,730,567,168 bytes free
Post-Run: 3,659,853,824 bytes free
245 --- E O F --- 2008-07-16 10:23:00
bamajim
10.4K Posts
0
July 16th, 2008 13:00
Drat! :smileysad:
Appologies. I made a typo error.
We are going to have to do this again
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
C:\WINDOWS\system32\drivers\843lozjc.exe
C:\WINDOWS\system32\kcopt.dll
C:\WINDOWS\system32\opurerdp.tmp
C:\WINDOWS\system32\wpx33.cpx
C:\WINDOWS\zts2.exe
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\logo1_.exe
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
"The world is what you make of it"
bamajim
10.4K Posts
0
July 16th, 2008 13:00
Not near as long as some I have seen
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
C:\WINDOWS\system32\drivers\843lozjc.exe
C:\WINDOWS\system32\kcopt.dll
C:\WINDOWS\system32\opurerdp.tmp
C:\WINDOWS\system32\wpx33.cpx
C:\WINDOWS\zts2.exe
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\logo1_.exe
Folder::
C:\Temp\gis63c50
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
"The world is what you make of it"
aqua08
8 Posts
0
July 16th, 2008 13:00
So.. latest log... Looking good?
ComboFix 08-07-14.2 - Administrator 2008-07-16 16:47:42.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.691 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\combofix\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\logo1_.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\system32\drivers\843lozjc.exe
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\system32\kcopt.dll
C:\WINDOWS\system32\opurerdp.tmp
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\wpx33.cpx
C:\WINDOWS\zts2.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\843lozjc.exe
C:\WINDOWS\system32\kcopt.dll
C:\WINDOWS\system32\opurerdp.tmp
C:\WINDOWS\system32\wpx33.cpx
.
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 )))))))))))))))))))))))))))))))
.
2008-07-16 13:33 . 2008-07-16 13:33
2008-07-16 12:46 . 2008-07-16 12:46 0 --a------ C:\12.tmp
2008-07-16 12:43 . 2008-07-16 12:43
2008-07-16 12:40 . 2008-07-16 12:41
2008-07-16 12:23 . 2008-07-16 12:23
2008-07-16 12:04 . 2004-08-04 14:00 119,808 --a--c--- C:\WINDOWS\system32\dllcache\winmine.exe
2008-07-16 12:04 . 2004-08-04 14:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-07-16 12:04 . 2004-08-04 14:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2008-07-16 12:04 . 2004-08-04 14:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-07-16 12:04 . 2004-08-04 14:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-07-16 12:04 . 2004-08-04 14:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-07-16 12:04 . 2004-08-04 14:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-07-16 12:04 . 2004-08-04 14:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-07-16 12:04 . 2004-08-04 14:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-07-16 12:02 . 2004-08-04 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-07-16 12:01 . 2004-08-04 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-07-16 12:00 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-16 11:58 . 2004-08-04 14:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-07-16 10:04 . 2008-07-16 10:04 23,484 --a------ C:\WINDOWS\Microsoft Outlook.FAV
2008-07-16 09:48 . 2008-02-12 14:59 1,306,624 --a------ C:\WINDOWS\system32\msxml6.dll
2008-07-16 09:48 . 2008-02-12 02:48 79,872 --a------ C:\WINDOWS\system32\msxml6r.dll
2008-07-16 09:39 . 2008-02-12 03:13 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-07-16 09:38 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\ 003374_.tmp
2008-07-16 08:14 . 2008-07-16 08:14
2008-07-16 07:53 . 2008-07-16 08:30
2008-07-16 07:42 . 2008-07-16 07:43
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 12:43
2008-07-16 07:05 . 2008-07-16 13:42
2008-07-15 16:08 . 2008-07-16 07:05
2008-07-15 13:16 . 2008-07-15 13:16 0 --a------ C:\23990098.$$$
2008-07-15 11:17 . 2008-07-15 11:42 26 --a------ C:\WINDOWS\Lic.xxx
2008-07-15 11:16 . 2008-07-15 13:52
2008-07-15 11:16 . 2004-08-04 01:56 146,432 --a------ C:\WINDOWS\R.COM
2008-07-15 11:16 . 2004-08-04 01:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-07-15 11:09 . 2008-07-15 11:09
2008-07-15 11:03 . 2008-07-15 11:03 300 --a------ C:\WINDOWS\wininit.ini
2008-07-15 10:33 . 2008-07-16 07:08
2008-07-10 16:39 . 2008-07-10 16:39 44 --a------ C:\WINDOWS\73334xxx00_AN.PJT
2008-07-10 16:12 . 2008-07-10 16:12 44 --a------ C:\WINDOWS\73334xxx00_BE.PJT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 10:46 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-07-16 06:29 --------- d-----w C:\Program Files\Google
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 08:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 11:25 493024]
"niDevMon"="C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" [2007-02-24 02:34 92960]
"TPPOLL10"="C:\Program Files\PenScope\PenScope\TPPOLL10.EXE" [2007-05-10 20:57 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\brlabor4\Start Menu\Programs\Startup\
Shortcut to hardcopy.lnk - C:\Program Files\Hardcopy\hardcopy.exe [2004-07-26 18:49:30 1093632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10010:TCP"= 10010:TCP:190.100.0.0/255.255.0.0:Enabled:AdAware
"2868:TCP"= 2868:TCP:190.100.0.0/255.255.0.0:Enabled:NVC
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2007-02-15 22:59]
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\WINDOWS\system32\drivers\nipbcfk.sys [2007-02-15 17:23]
R2 CameraMonitor;FLIR Camera Monitor;C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe [2006-06-08 13:58]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 10:01]
R2 glpntdrv;glpntdrv;C:\WINDOWS\system32\drivers\glpntdrv.sys [1998-11-25 17:48]
R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 02:29]
R2 mxssvr;NI Configuration Manager;C:\Program Files\National Instruments\MAX\nimxs.exe [2007-02-22 08:46]
R2 ni488enumsvc;NI-488.2 Enumeration Service;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nidevldu;NI Device Loader;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nipxirmk;nipxirmk;C:\WINDOWS\system32\drivers\nipxirmkl.sys [2007-02-22 11:18]
R2 NITaggerService;National Instruments Variable Engine;C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2007-02-06 22:47]
R2 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiKl.sys [2007-02-23 10:25]
R3 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimkl.sys [2007-02-21 22:20]
R3 nimdbgk;nimdbgk;C:\WINDOWS\system32\drivers\nimdbgkl.sys [2007-02-21 21:46]
R3 nimru2k;nimru2k;C:\WINDOWS\system32\drivers\nimru2kl.sys [2007-02-21 22:39]
R3 nimstsk;nimstsk;C:\WINDOWS\system32\drivers\nimstskl.sys [2007-02-25 20:12]
R3 nimxdfk;nimxdfk;C:\WINDOWS\system32\drivers\nimxdfkl.sys [2007-02-21 22:10]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);C:\WINDOWS\system32\Drivers\icd2w2k.sys [2004-03-22 02:43]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 02:27]
S3 CA_LIC_SRVR;CA License Server;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 02:41]
S3 DCamUSBTP10;Pen Scope;C:\WINDOWS\system32\Drivers\TP6810.sys [2007-07-26 19:56]
S3 FLIRUSBNET;FLIR USB Network Adapter;C:\WINDOWS\system32\DRIVERS\FLIRUSB.sys [2006-05-05 13:20]
S3 lvalarmk;lvalarmk;C:\WINDOWS\system32\drivers\lvalarmk.sys [2007-01-11 10:18]
S3 ni1006k;NI PXI-1006 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1006k.sys [2007-02-22 11:40]
S3 ni1045k;NI PXI-1045 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1045kl.sys [2007-02-22 11:43]
S3 ni488lock;NI-488.2 Locking Service;C:\WINDOWS\system32\drivers\ni488lock.sys [2007-02-26 12:40]
S3 nicdrk;nicdrk;C:\WINDOWS\system32\drivers\nicdrkl.sys [2007-02-22 18:18]
S3 nidmxfk;nidmxfk;C:\WINDOWS\system32\drivers\nidmxfkl.sys [2007-02-25 20:12]
S3 nidsark;nidsark;C:\WINDOWS\system32\drivers\nidsarkl.sys [2007-02-23 17:43]
S3 niemrk;niemrk;C:\WINDOWS\system32\drivers\niemrkl.sys [2007-02-25 19:13]
S3 niesrk;niesrk;C:\WINDOWS\system32\drivers\niesrkl.sys [2007-02-25 19:13]
S3 nifslk;nifslk;C:\WINDOWS\system32\drivers\nifslkl.sys [2007-02-22 13:21]
S3 nimsdrk;nimsdrk;C:\WINDOWS\system32\drivers\nimsdrkl.sys [2007-02-25 20:10]
S3 nimslk;nimslk;C:\WINDOWS\system32\drivers\nimslk.dll [2006-12-18 12:55]
S3 nimsrlk;nimsrlk;C:\WINDOWS\system32\drivers\nimsrlk.dll [2006-12-18 12:55]
S3 nimxpk;nimxpk;C:\WINDOWS\system32\drivers\nimxpkl.sys [2007-02-22 13:26]
S3 ninshsdk;ninshsdk;C:\WINDOWS\system32\drivers\ninshsdkl.sys [2007-02-23 17:25]
S3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbkl.sys [2007-02-21 21:39]
S3 nipalfwedl;nipalfwedl;C:\WINDOWS\system32\drivers\nipalfwedl.sys [2007-02-15 23:00]
S3 nipalusbedl;nipalusbedl;C:\WINDOWS\system32\drivers\nipalusbedl.sys [2007-02-15 23:00]
S3 nipxigpk;NI PXI Generic Chassis Pilot;C:\WINDOWS\system32\drivers\nipxigpk.sys [2007-02-22 11:45]
S3 niscdk;niscdk;C:\WINDOWS\system32\drivers\niscdkl.sys [2007-02-26 16:31]
S3 nisdigk;nisdigk;C:\WINDOWS\system32\drivers\nisdigkl.sys [2007-02-25 19:11]
S3 nisftk;nisftk;C:\WINDOWS\system32\drivers\nisftkl.sys [2007-02-24 00:17]
S3 nismbusk;nismbusk;C:\WINDOWS\system32\drivers\nismbusk.sys [2007-02-22 11:34]
S3 nispdk;nispdk;C:\WINDOWS\system32\drivers\nispdkl.sys [2007-02-26 16:31]
S3 nissrk;nissrk;C:\WINDOWS\system32\drivers\nissrkl.sys [2007-02-25 19:13]
S3 nistc2k;nistc2k;C:\WINDOWS\system32\drivers\nistc2kl.sys [2007-02-22 20:17]
S3 nistcrk;nistcrk;C:\WINDOWS\system32\drivers\nistcrkl.sys [2007-02-23 03:14]
S3 niswdk;niswdk;C:\WINDOWS\system32\drivers\niswdkl.sys [2007-02-23 20:44]
S3 nitiork;nitiork;C:\WINDOWS\system32\drivers\nitiorkl.sys [2007-02-23 15:54]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWKl.sys [2007-02-22 10:42]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciKl.sys [2007-02-23 10:25]
S3 niwfrk;niwfrk;C:\WINDOWS\system32\drivers\niwfrkl.sys [2007-02-25 19:13]
S3 nixsrk;nixsrk;C:\WINDOWS\system32\drivers\nixsrkl.sys [2007-02-25 19:13]
S3 TTUSB1;TTUSB1.SYS TechTools USB device driver;C:\WINDOWS\system32\Drivers\TTUSB1.sys [2007-06-25 07:31]
S3 usb6xxxk;usb6xxxk;C:\WINDOWS\system32\drivers\usb6xxxk.sys [2007-02-25 19:11]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 16:50:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-16 16:51:14
ComboFix-quarantined-files.txt 2008-07-16 14:51:07
ComboFix2.txt 2008-07-16 14:29:04
ComboFix3.txt 2008-07-16 13:37:57
Pre-Run: 3,618,713,600 bytes free
Post-Run: 3,608,424,448 bytes free
191 --- E O F --- 2008-07-16 10:23:00
aqua08
8 Posts
0
July 16th, 2008 13:00
ComboFix finished.. there hasn´t been opened a Log as before, but I think it overwrote the ComboFix.txt on C:\ ?
So this would be the result:
ComboFix 08-07-14.2 - Administrator 2008-07-16 16:25:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.704 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\combofix\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\gis63c50
.
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 )))))))))))))))))))))))))))))))
.
2008-07-16 13:43 . 2008-07-16 13:43 36,352 --a------ C:\WINDOWS\system32\drivers\843lozjc.exe
2008-07-16 13:33 . 2008-07-16 13:33
2008-07-16 13:13 . 2008-07-16 13:41 34,468 --a------ C:\WINDOWS\system32\kcopt.dll
2008-07-16 12:47 . 2008-07-16 12:47 29 --a------ C:\WINDOWS\system32\opurerdp.tmp
2008-07-16 12:46 . 2008-07-16 12:46 15,360 --a------ C:\WINDOWS\system32\wpx33.cpx
2008-07-16 12:46 . 2008-07-16 12:46 0 --a------ C:\12.tmp
2008-07-16 12:43 . 2008-07-16 12:43
2008-07-16 12:40 . 2008-07-16 12:41
2008-07-16 12:23 . 2008-07-16 12:23
2008-07-16 12:04 . 2004-08-04 14:00 119,808 --a--c--- C:\WINDOWS\system32\dllcache\winmine.exe
2008-07-16 12:04 . 2004-08-04 14:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-07-16 12:04 . 2004-08-04 14:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2008-07-16 12:04 . 2004-08-04 14:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-07-16 12:04 . 2004-08-04 14:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-07-16 12:04 . 2004-08-04 14:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-07-16 12:04 . 2004-08-04 14:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-07-16 12:04 . 2004-08-04 14:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-07-16 12:04 . 2004-08-04 14:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-07-16 12:02 . 2004-08-04 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-07-16 12:01 . 2004-08-04 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-07-16 12:00 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-16 11:58 . 2004-08-04 14:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-07-16 10:04 . 2008-07-16 10:04 23,484 --a------ C:\WINDOWS\Microsoft Outlook.FAV
2008-07-16 09:48 . 2008-02-12 14:59 1,306,624 --a------ C:\WINDOWS\system32\msxml6.dll
2008-07-16 09:48 . 2008-02-12 02:48 79,872 --a------ C:\WINDOWS\system32\msxml6r.dll
2008-07-16 09:39 . 2008-02-12 03:13 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-07-16 09:38 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\ 003374_.tmp
2008-07-16 08:14 . 2008-07-16 08:14
2008-07-16 07:53 . 2008-07-16 08:30
2008-07-16 07:42 . 2008-07-16 07:43
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 07:05
2008-07-16 07:05 . 2008-07-16 12:43
2008-07-16 07:05 . 2008-07-16 13:42
2008-07-15 16:08 . 2008-07-16 07:05
2008-07-15 13:16 . 2008-07-15 13:16 0 --a------ C:\23990098.$$$
2008-07-15 11:17 . 2008-07-15 11:42 26 --a------ C:\WINDOWS\Lic.xxx
2008-07-15 11:16 . 2008-07-15 13:52
2008-07-15 11:16 . 2004-08-04 01:56 146,432 --a------ C:\WINDOWS\R.COM
2008-07-15 11:16 . 2004-08-04 01:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-07-15 11:09 . 2008-07-15 11:09
2008-07-15 11:03 . 2008-07-15 11:03 300 --a------ C:\WINDOWS\wininit.ini
2008-07-15 10:33 . 2008-07-16 07:08
2008-07-10 16:39 . 2008-07-10 16:39 44 --a------ C:\WINDOWS\73334xxx00_AN.PJT
2008-07-10 16:12 . 2008-07-10 16:12 44 --a------ C:\WINDOWS\73334xxx00_BE.PJT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 10:46 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-07-16 06:29 --------- d-----w C:\Program Files\Google
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 08:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 11:25 493024]
"niDevMon"="C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" [2007-02-24 02:34 92960]
"TPPOLL10"="C:\Program Files\PenScope\PenScope\TPPOLL10.EXE" [2007-05-10 20:57 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\brlabor4\Start Menu\Programs\Startup\
Shortcut to hardcopy.lnk - C:\Program Files\Hardcopy\hardcopy.exe [2004-07-26 18:49:30 1093632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10010:TCP"= 10010:TCP:190.100.0.0/255.255.0.0:Enabled:AdAware
"2868:TCP"= 2868:TCP:190.100.0.0/255.255.0.0:Enabled:NVC
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2007-02-15 22:59]
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\WINDOWS\system32\drivers\nipbcfk.sys [2007-02-15 17:23]
R2 CameraMonitor;FLIR Camera Monitor;C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe [2006-06-08 13:58]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 10:01]
R2 glpntdrv;glpntdrv;C:\WINDOWS\system32\drivers\glpntdrv.sys [1998-11-25 17:48]
R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 02:29]
R2 mxssvr;NI Configuration Manager;C:\Program Files\National Instruments\MAX\nimxs.exe [2007-02-22 08:46]
R2 ni488enumsvc;NI-488.2 Enumeration Service;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nidevldu;NI Device Loader;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nipxirmk;nipxirmk;C:\WINDOWS\system32\drivers\nipxirmkl.sys [2007-02-22 11:18]
R2 NITaggerService;National Instruments Variable Engine;C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2007-02-06 22:47]
R2 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiKl.sys [2007-02-23 10:25]
R3 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimkl.sys [2007-02-21 22:20]
R3 nimdbgk;nimdbgk;C:\WINDOWS\system32\drivers\nimdbgkl.sys [2007-02-21 21:46]
R3 nimru2k;nimru2k;C:\WINDOWS\system32\drivers\nimru2kl.sys [2007-02-21 22:39]
R3 nimstsk;nimstsk;C:\WINDOWS\system32\drivers\nimstskl.sys [2007-02-25 20:12]
R3 nimxdfk;nimxdfk;C:\WINDOWS\system32\drivers\nimxdfkl.sys [2007-02-21 22:10]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);C:\WINDOWS\system32\Drivers\icd2w2k.sys [2004-03-22 02:43]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 02:27]
S3 CA_LIC_SRVR;CA License Server;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 02:41]
S3 DCamUSBTP10;Pen Scope;C:\WINDOWS\system32\Drivers\TP6810.sys [2007-07-26 19:56]
S3 FLIRUSBNET;FLIR USB Network Adapter;C:\WINDOWS\system32\DRIVERS\FLIRUSB.sys [2006-05-05 13:20]
S3 lvalarmk;lvalarmk;C:\WINDOWS\system32\drivers\lvalarmk.sys [2007-01-11 10:18]
S3 ni1006k;NI PXI-1006 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1006k.sys [2007-02-22 11:40]
S3 ni1045k;NI PXI-1045 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1045kl.sys [2007-02-22 11:43]
S3 ni488lock;NI-488.2 Locking Service;C:\WINDOWS\system32\drivers\ni488lock.sys [2007-02-26 12:40]
S3 nicdrk;nicdrk;C:\WINDOWS\system32\drivers\nicdrkl.sys [2007-02-22 18:18]
S3 nidmxfk;nidmxfk;C:\WINDOWS\system32\drivers\nidmxfkl.sys [2007-02-25 20:12]
S3 nidsark;nidsark;C:\WINDOWS\system32\drivers\nidsarkl.sys [2007-02-23 17:43]
S3 niemrk;niemrk;C:\WINDOWS\system32\drivers\niemrkl.sys [2007-02-25 19:13]
S3 niesrk;niesrk;C:\WINDOWS\system32\drivers\niesrkl.sys [2007-02-25 19:13]
S3 nifslk;nifslk;C:\WINDOWS\system32\drivers\nifslkl.sys [2007-02-22 13:21]
S3 nimsdrk;nimsdrk;C:\WINDOWS\system32\drivers\nimsdrkl.sys [2007-02-25 20:10]
S3 nimslk;nimslk;C:\WINDOWS\system32\drivers\nimslk.dll [2006-12-18 12:55]
S3 nimsrlk;nimsrlk;C:\WINDOWS\system32\drivers\nimsrlk.dll [2006-12-18 12:55]
S3 nimxpk;nimxpk;C:\WINDOWS\system32\drivers\nimxpkl.sys [2007-02-22 13:26]
S3 ninshsdk;ninshsdk;C:\WINDOWS\system32\drivers\ninshsdkl.sys [2007-02-23 17:25]
S3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbkl.sys [2007-02-21 21:39]
S3 nipalfwedl;nipalfwedl;C:\WINDOWS\system32\drivers\nipalfwedl.sys [2007-02-15 23:00]
S3 nipalusbedl;nipalusbedl;C:\WINDOWS\system32\drivers\nipalusbedl.sys [2007-02-15 23:00]
S3 nipxigpk;NI PXI Generic Chassis Pilot;C:\WINDOWS\system32\drivers\nipxigpk.sys [2007-02-22 11:45]
S3 niscdk;niscdk;C:\WINDOWS\system32\drivers\niscdkl.sys [2007-02-26 16:31]
S3 nisdigk;nisdigk;C:\WINDOWS\system32\drivers\nisdigkl.sys [2007-02-25 19:11]
S3 nisftk;nisftk;C:\WINDOWS\system32\drivers\nisftkl.sys [2007-02-24 00:17]
S3 nismbusk;nismbusk;C:\WINDOWS\system32\drivers\nismbusk.sys [2007-02-22 11:34]
S3 nispdk;nispdk;C:\WINDOWS\system32\drivers\nispdkl.sys [2007-02-26 16:31]
S3 nissrk;nissrk;C:\WINDOWS\system32\drivers\nissrkl.sys [2007-02-25 19:13]
S3 nistc2k;nistc2k;C:\WINDOWS\system32\drivers\nistc2kl.sys [2007-02-22 20:17]
S3 nistcrk;nistcrk;C:\WINDOWS\system32\drivers\nistcrkl.sys [2007-02-23 03:14]
S3 niswdk;niswdk;C:\WINDOWS\system32\drivers\niswdkl.sys [2007-02-23 20:44]
S3 nitiork;nitiork;C:\WINDOWS\system32\drivers\nitiorkl.sys [2007-02-23 15:54]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWKl.sys [2007-02-22 10:42]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciKl.sys [2007-02-23 10:25]
S3 niwfrk;niwfrk;C:\WINDOWS\system32\drivers\niwfrkl.sys [2007-02-25 19:13]
S3 nixsrk;nixsrk;C:\WINDOWS\system32\drivers\nixsrkl.sys [2007-02-25 19:13]
S3 TTUSB1;TTUSB1.SYS TechTools USB device driver;C:\WINDOWS\system32\Drivers\TTUSB1.sys [2007-06-25 07:31]
S3 usb6xxxk;usb6xxxk;C:\WINDOWS\system32\drivers\usb6xxxk.sys [2007-02-25 19:11]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 16:27:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-16 16:29:03
ComboFix-quarantined-files.txt 2008-07-16 14:28:56
ComboFix2.txt 2008-07-16 13:37:57
Pre-Run: 3,646,394,368 bytes free
Post-Run: 3,635,953,664 bytes free
180 --- E O F --- 2008-07-16 10:23:00
bamajim
10.4K Posts
0
July 16th, 2008 14:00
Better. One more time and I think we are there
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
Folder::
C:\WINDOWS\zts2.exe
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\logo1_.exe
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
2. Rerun Hijackthis and post a fresh Hijackthis log as well
"The world is what you make of it"
aqua08
8 Posts
0
July 16th, 2008 14:00
aqua08
8 Posts
0
July 16th, 2008 14:00
First of all, thank you for your help!!!
I will now go home, because it´s already after five pm and I began at six am today.. So I´ll read your answer tomorrow. But I hope the problem is fixed now
THANK YOU AGAIN AND AGAIN ;)
1st: ComboFix Log
ComboFix 08-07-14.2 - Administrator 2008-07-16 17:05:24.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.695 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\combofix\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\logo1_.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\zts2.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 )))))))))))))))))))))))))))))))
.
2008-07-16 13:33 . 2008-07-16 13:33
2008-07-16 12:46 . 2008-07-16 12:46 0 --a------ C:\12.tmp
2008-07-16 12:43 . 2008-07-16 12:43
2008-07-16 12:40 . 2008-07-16 12:41
2008-07-16 12:23 . 2008-07-16 12:23
2008-07-16 12:04 . 2004-08-04 14:00 119,808 --a--c--- C:\WINDOWS\system32\dllcache\winmine.exe
2008-07-16 12:04 . 2004-08-04 14:00 113,222 --a--c--- C:\WINDOWS\system32\dllcache\zoneclim.dll
2008-07-16 12:04 . 2004-08-04 14:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2008-07-16 12:04 . 2004-08-04 14:00 41,029 --a--c--- C:\WINDOWS\system32\dllcache\zcorem.dll
2008-07-16 12:04 . 2004-08-04 14:00 36,937 --a--c--- C:\WINDOWS\system32\dllcache\zclientm.exe
2008-07-16 12:04 . 2004-08-04 14:00 29,760 --a--c--- C:\WINDOWS\system32\dllcache\znetm.dll
2008-07-16 12:04 . 2004-08-04 14:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-07-16 12:04 . 2004-08-04 14:00 13,894 --a--c--- C:\WINDOWS\system32\dllcache\zonelibm.dll
2008-07-16 12:04 . 2004-08-04 14:00 4,677 --a--c--- C:\WINDOWS\system32\dllcache\zeeverm.dll
2008-07-16 12:02 . 2004-08-04 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-07-16 12:01 . 2004-08-04 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-07-16 12:00 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-16 11:58 . 2004-08-04 14:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-16 11:58 . 2008-07-16 11:58 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-07-16 11:46 . 2004-08-04 14:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-07-16 10:04 . 2008-07-16 10:04 23,484 --a------ C:\WINDOWS\Microsoft Outlook.FAV
2008-07-16 09:48 . 2008-02-12 14:59 1,306,624 --a------ C:\WINDOWS\system32\msxml6.dll
2008-07-16 09:48 . 2008-02-12 02:48 79,872 --a------ C:\WINDOWS\system32\msxml6r.dll
2008-07-16 09:39 . 2008-02-12 03:13 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-07-16 09:38 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\ 003374_.tmp
2008-07-16 08:14 . 2008-07-16 08:14
2008-07-16 07:53 . 2008-07-16 08:30
2008-07-16 07:42 . 2008-07-16 07:43
2008-07-16 07:05 . 2008-07-16 12:43
2008-07-16 07:05 . 2008-07-16 13:42
2008-07-15 16:08 . 2008-07-16 07:05
2008-07-15 13:16 . 2008-07-15 13:16 0 --a------ C:\23990098.$$$
2008-07-15 11:17 . 2008-07-15 11:42 26 --a------ C:\WINDOWS\Lic.xxx
2008-07-15 11:16 . 2008-07-15 13:52
2008-07-15 11:16 . 2004-08-04 01:56 146,432 --a------ C:\WINDOWS\R.COM
2008-07-15 11:16 . 2004-08-04 01:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-07-15 11:09 . 2008-07-15 11:09
2008-07-15 11:03 . 2008-07-15 11:03 300 --a------ C:\WINDOWS\wininit.ini
2008-07-15 10:33 . 2008-07-16 07:08
2008-07-10 16:39 . 2008-07-10 16:39 44 --a------ C:\WINDOWS\73334xxx00_AN.PJT
2008-07-10 16:12 . 2008-07-10 16:12 44 --a------ C:\WINDOWS\73334xxx00_BE.PJT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 10:46 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-07-16 06:29 --------- d-----w C:\Program Files\Google
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 08:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 11:25 493024]
"niDevMon"="C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe" [2007-02-24 02:34 92960]
"TPPOLL10"="C:\Program Files\PenScope\PenScope\TPPOLL10.EXE" [2007-05-10 20:57 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\brlabor4\Start Menu\Programs\Startup\
Shortcut to hardcopy.lnk - C:\Program Files\Hardcopy\hardcopy.exe [2004-07-26 18:49:30 1093632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10010:TCP"= 10010:TCP:190.100.0.0/255.255.0.0:Enabled:AdAware
"2868:TCP"= 2868:TCP:190.100.0.0/255.255.0.0:Enabled:NVC
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2007-02-15 22:59]
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\WINDOWS\system32\drivers\nipbcfk.sys [2007-02-15 17:23]
R2 CameraMonitor;FLIR Camera Monitor;C:\Program Files\FLIR Systems\ThermaCAM QuickView 2\T3Srv.exe [2006-06-08 13:58]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 10:01]
R2 glpntdrv;glpntdrv;C:\WINDOWS\system32\drivers\glpntdrv.sys [1998-11-25 17:48]
R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 02:29]
R2 mxssvr;NI Configuration Manager;C:\Program Files\National Instruments\MAX\nimxs.exe [2007-02-22 08:46]
R2 ni488enumsvc;NI-488.2 Enumeration Service;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nidevldu;NI Device Loader;C:\WINDOWS\system32\nipalsm.exe [2007-02-16 10:21]
R2 nipxirmk;nipxirmk;C:\WINDOWS\system32\drivers\nipxirmkl.sys [2007-02-22 11:18]
R2 NITaggerService;National Instruments Variable Engine;C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2007-02-06 22:47]
R2 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiKl.sys [2007-02-23 10:25]
R3 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimkl.sys [2007-02-21 22:20]
R3 nimdbgk;nimdbgk;C:\WINDOWS\system32\drivers\nimdbgkl.sys [2007-02-21 21:46]
R3 nimru2k;nimru2k;C:\WINDOWS\system32\drivers\nimru2kl.sys [2007-02-21 22:39]
R3 nimstsk;nimstsk;C:\WINDOWS\system32\drivers\nimstskl.sys [2007-02-25 20:12]
R3 nimxdfk;nimxdfk;C:\WINDOWS\system32\drivers\nimxdfkl.sys [2007-02-21 22:10]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);C:\WINDOWS\system32\Drivers\icd2w2k.sys [2004-03-22 02:43]
S3 CA_LIC_CLNT;CA License Client;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 02:27]
S3 CA_LIC_SRVR;CA License Server;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 02:41]
S3 DCamUSBTP10;Pen Scope;C:\WINDOWS\system32\Drivers\TP6810.sys [2007-07-26 19:56]
S3 FLIRUSBNET;FLIR USB Network Adapter;C:\WINDOWS\system32\DRIVERS\FLIRUSB.sys [2006-05-05 13:20]
S3 lvalarmk;lvalarmk;C:\WINDOWS\system32\drivers\lvalarmk.sys [2007-01-11 10:18]
S3 ni1006k;NI PXI-1006 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1006k.sys [2007-02-22 11:40]
S3 ni1045k;NI PXI-1045 Chassis Pilot;C:\WINDOWS\system32\drivers\ni1045kl.sys [2007-02-22 11:43]
S3 ni488lock;NI-488.2 Locking Service;C:\WINDOWS\system32\drivers\ni488lock.sys [2007-02-26 12:40]
S3 nicdrk;nicdrk;C:\WINDOWS\system32\drivers\nicdrkl.sys [2007-02-22 18:18]
S3 nidmxfk;nidmxfk;C:\WINDOWS\system32\drivers\nidmxfkl.sys [2007-02-25 20:12]
S3 nidsark;nidsark;C:\WINDOWS\system32\drivers\nidsarkl.sys [2007-02-23 17:43]
S3 niemrk;niemrk;C:\WINDOWS\system32\drivers\niemrkl.sys [2007-02-25 19:13]
S3 niesrk;niesrk;C:\WINDOWS\system32\drivers\niesrkl.sys [2007-02-25 19:13]
S3 nifslk;nifslk;C:\WINDOWS\system32\drivers\nifslkl.sys [2007-02-22 13:21]
S3 nimsdrk;nimsdrk;C:\WINDOWS\system32\drivers\nimsdrkl.sys [2007-02-25 20:10]
S3 nimslk;nimslk;C:\WINDOWS\system32\drivers\nimslk.dll [2006-12-18 12:55]
S3 nimsrlk;nimsrlk;C:\WINDOWS\system32\drivers\nimsrlk.dll [2006-12-18 12:55]
S3 nimxpk;nimxpk;C:\WINDOWS\system32\drivers\nimxpkl.sys [2007-02-22 13:26]
S3 ninshsdk;ninshsdk;C:\WINDOWS\system32\drivers\ninshsdkl.sys [2007-02-23 17:25]
S3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbkl.sys [2007-02-21 21:39]
S3 nipalfwedl;nipalfwedl;C:\WINDOWS\system32\drivers\nipalfwedl.sys [2007-02-15 23:00]
S3 nipalusbedl;nipalusbedl;C:\WINDOWS\system32\drivers\nipalusbedl.sys [2007-02-15 23:00]
S3 nipxigpk;NI PXI Generic Chassis Pilot;C:\WINDOWS\system32\drivers\nipxigpk.sys [2007-02-22 11:45]
S3 niscdk;niscdk;C:\WINDOWS\system32\drivers\niscdkl.sys [2007-02-26 16:31]
S3 nisdigk;nisdigk;C:\WINDOWS\system32\drivers\nisdigkl.sys [2007-02-25 19:11]
S3 nisftk;nisftk;C:\WINDOWS\system32\drivers\nisftkl.sys [2007-02-24 00:17]
S3 nismbusk;nismbusk;C:\WINDOWS\system32\drivers\nismbusk.sys [2007-02-22 11:34]
S3 nispdk;nispdk;C:\WINDOWS\system32\drivers\nispdkl.sys [2007-02-26 16:31]
S3 nissrk;nissrk;C:\WINDOWS\system32\drivers\nissrkl.sys [2007-02-25 19:13]
S3 nistc2k;nistc2k;C:\WINDOWS\system32\drivers\nistc2kl.sys [2007-02-22 20:17]
S3 nistcrk;nistcrk;C:\WINDOWS\system32\drivers\nistcrkl.sys [2007-02-23 03:14]
S3 niswdk;niswdk;C:\WINDOWS\system32\drivers\niswdkl.sys [2007-02-23 20:44]
S3 nitiork;nitiork;C:\WINDOWS\system32\drivers\nitiorkl.sys [2007-02-23 15:54]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWKl.sys [2007-02-22 10:42]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciKl.sys [2007-02-23 10:25]
S3 niwfrk;niwfrk;C:\WINDOWS\system32\drivers\niwfrkl.sys [2007-02-25 19:13]
S3 nixsrk;nixsrk;C:\WINDOWS\system32\drivers\nixsrkl.sys [2007-02-25 19:13]
S3 TTUSB1;TTUSB1.SYS TechTools USB device driver;C:\WINDOWS\system32\Drivers\TTUSB1.sys [2007-06-25 07:31]
S3 usb6xxxk;usb6xxxk;C:\WINDOWS\system32\drivers\usb6xxxk.sys [2007-02-25 19:11]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 17:07:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-16 17:08:52
ComboFix-quarantined-files.txt 2008-07-16 15:08:44
ComboFix2.txt 2008-07-16 14:51:15
ComboFix3.txt 2008-07-16 14:29:04
ComboFix4.txt 2008-07-16 13:37:57
Pre-Run: 3,592,912,896 bytes free
Post-Run: 3,582,754,816 bytes free
177 --- E O F --- 2008-07-16 10:23:00
bamajim
10.4K Posts
0
July 17th, 2008 11:00
aqua08
You are most welcome.
The last Hijackthis log you posted is unreadable
When you compose and submit your reply, please make sure the box under your text which shows "Automatically convert carriage returns to HTML line breaks" is checked or your reply may not format correctly.
Then repost your Hijackthis log.
And in your reply give me an update on how your PC is running at this point
"The world is what you make of it"
aqua08
8 Posts
0
July 17th, 2008 11:00
Unfortunately I have to say, that the problem still occurred after a reboot.. The taskmanager was disabled again.. As the user immediately needed his computer back, I decided to reinstall it completely...
But thank you anyway for your help. This blog was very useful and I´ll use it again if I have another problem..
Regards