Unsolved
This post is more than 5 years old
7 Posts
0
1012
February 8th, 2008 13:00
HiJack This and ComboFix Logs.
I am still seeing packets being sent out of the computer. ComboFix did a lot to solve some of the MalWare stuff, but I have a feeling there si still somethign here. Can someone look at these and let me knwo what else I need to do? Thanks,
-Rick
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:54:24 AM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trillian\trillian.exe
C:\Documents and Settings\rcopes\Desktop\HiJackThis_v2.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182179388984
O16 - DPF: {7BE30DB7-4BB6-41A7-BE9C-EB9EB45725DE} (WebCamX Control) - http://208.42.209.86/WebCamX.cab
O16 - DPF: {F92211F4-3913-4DC2-A275-756374D848B0} (ERViewerOCX Control) - http://66.112.17.174/MP4DVR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D879E850-F59A-4357-8526-139D1D099036}: NameServer = 209.142.136.85,208.42.196.36
O21 - SSODL: BurnWin - {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe
--
End of file - 8119 bytes
---------------------------------------------------------------------------------------------------------
-Rick
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:54:24 AM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trillian\trillian.exe
C:\Documents and Settings\rcopes\Desktop\HiJackThis_v2.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182179388984
O16 - DPF: {7BE30DB7-4BB6-41A7-BE9C-EB9EB45725DE} (WebCamX Control) - http://208.42.209.86/WebCamX.cab
O16 - DPF: {F92211F4-3913-4DC2-A275-756374D848B0} (ERViewerOCX Control) - http://66.112.17.174/MP4DVR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D879E850-F59A-4357-8526-139D1D099036}: NameServer = 209.142.136.85,208.42.196.36
O21 - SSODL: BurnWin - {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe
--
End of file - 8119 bytes
---------------------------------------------------------------------------------------------------------
No Events found!


rickquick
7 Posts
0
February 8th, 2008 13:00
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 14:27 . 2008-02-07 14:33
2008-02-07 12:23 . 2008-02-07 12:23
2008-02-07 11:37 . 2008-02-07 11:37
2008-02-06 22:17 . 2008-02-06 22:17
2008-02-06 22:16 . 2008-02-07 10:37
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 11:05 . 2008-02-06 11:05 0 --a------ C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17
2008-02-06 10:04 . 2008-02-06 10:04 3,791,542 --a------ C:\WINDOWS\pf1rwdL5zk.exe
2008-02-06 10:03 . 2008-02-06 10:03
2008-02-06 10:03 . 2008-02-06 10:03 256,000 --a------ C:\WINDOWS\system32\apiuser32.dll
2008-02-06 10:03 . 2008-02-06 10:03 182,272 --a------ C:\WINDOWS\kjafwdkb.dll
2008-02-06 10:03 . 2008-02-06 10:03 89,617 --------- C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 10:03 . 2008-02-06 10:03 89,617 --a------ C:\WINDOWS\jmjyjids.exe
2008-02-06 10:03 . 2008-02-06 10:03 58,368 --a------ C:\wpohl.exe
2008-02-06 10:03 . 54,764 C:\WINDOWS\system32\jnhjkfrn
2008-02-06 10:03 . 2008-02-06 10:03 32,768 --a------ C:\arbfikac.exe
2008-02-06 10:03 . 2008-02-07 14:32 0 --a------ C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46
2008-01-15 09:03 . 2008-01-15 09:04
2008-01-14 15:21 . 2008-01-14 15:21
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 20:31 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-02-07 20:28 3,116 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-07 20:28 180,256 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-07 20:27 9,472 ----a-w C:\WINDOWS\system32\ESHOPEE.exe
2008-02-07 20:27 9,472 ----a-w C:\WINDOWS\cbinst$.exe
2008-02-07 20:27 8,704 ----a-w C:\WINDOWS\liqad.exe
2008-02-07 20:27 8,448 ----a-w C:\WINDOWS\liqui-Uninstaller.exe
2008-02-07 20:27 8,448 ----a-w C:\WINDOWS\kvnab.dll
2008-02-07 20:27 31,744 ----a-w C:\WINDOWS\daxtime.dll
2008-02-07 20:27 31,232 ----a-w C:\WINDOWS\hotporn.exe
2008-02-07 20:27 30,208 ----a-w C:\WINDOWS\iexplorr23.dll
2008-02-07 20:27 29,440 ----a-w C:\WINDOWS\wbeCheck.exe
2008-02-07 20:27 29,184 ----a-w C:\WINDOWS\fhfmm-Uninstaller.exe
2008-02-07 20:27 28,672 ----a-w C:\WINDOWS\ngd.dll
2008-02-07 20:27 27,136 ----a-w C:\WINDOWS\aconti.exe
2008-02-07 20:27 26,368 ----a-w C:\WINDOWS\eventlowg.dll
2008-02-07 20:27 26,112 ----a-w C:\WINDOWS\hcwprn.exe
2008-02-07 20:27 22,784 ----a-w C:\WINDOWS\dp0.dll
2008-02-07 20:27 22,528 ----a-w C:\WINDOWS\system32\msole32.exe
2008-02-07 20:27 22,528 ----a-w C:\WINDOWS\liqui.exe
2008-02-07 20:27 22,272 ----a-w C:\WINDOWS\xxxvideo.exe
2008-02-07 20:27 20,992 ----a-w C:\WINDOWS\kvnab$.exe
2008-02-07 20:27 20,736 ----a-w C:\WINDOWS\pbsysie.dll
2008-02-07 20:27 20,224 ----a-w C:\WINDOWS\fhfmm.exe
2008-02-07 20:27 19,968 ----a-w C:\WINDOWS\spredirect.dll
2008-02-07 20:27 19,712 ----a-w C:\WINDOWS\liqad.dll
2008-02-07 20:27 16,896 ----a-w C:\WINDOWS\vxddsk.exe
2008-02-07 20:27 16,896 ----a-w C:\WINDOWS\kvnab.exe
2008-02-07 20:27 16,128 ----a-w C:\WINDOWS\xadbrk.dll
2008-02-07 20:27 16,128 ----a-w C:\WINDOWS\adbar.dll
2008-02-07 20:27 15,872 ----a-w C:\WINDOWS\pbar.dll
2008-02-07 20:27 14,848 ----a-w C:\WINDOWS\jd2002.dll
2008-02-07 20:27 14,848 ----a-w C:\WINDOWS\764.exe
2008-02-07 20:27 14,336 ----a-w C:\WINDOWS\7search.dll
2008-02-07 20:27 14,080 ----a-w C:\WINDOWS\liqui.dll
2008-02-07 20:27 13,824 ----a-w C:\WINDOWS\ie_32.exe
2008-02-07 20:27 13,312 ----a-w C:\WINDOWS\wml.exe
2008-02-07 20:27 13,056 ----a-w C:\WINDOWS\xadbrk_.exe
2008-02-07 20:27 13,056 ----a-w C:\WINDOWS\kkcomp.dll
2008-02-07 20:27 12,800 ----a-w C:\WINDOWS\wbeInst$.exe
2008-02-07 20:27 12,032 ----a-w C:\WINDOWS\kkcomp$.exe
2008-02-07 20:27 11,008 ----a-w C:\WINDOWS\xadbrk.exe
2008-02-07 20:27 10,752 ----a-w C:\WINDOWS\settn.dll
2008-02-07 20:27 10,752 ----a-w C:\WINDOWS\flt.dll
2008-02-07 20:27 10,496 ----a-w C:\WINDOWS\system32\ace16win.dll
2008-02-07 20:27 10,496 ----a-w C:\WINDOWS\kkcomp.exe
2008-02-07 20:27 10,240 ----a-w C:\WINDOWS\liqad$.exe
2008-02-07 18:25 20,149,491 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-07 16:30 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 06:03 85,504 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-02-01 22:26 --------- d-----w C:\Program Files\Trillian
2008-01-27 20:37 81,920 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-01-15 15:15 --------- d-----w C:\Program Files\Yahoo!
2007-11-21 00:35 28,032 ----a-w C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-11-14 22:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-01 14:57 2,904,576 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-11-01 14:57 1,302,528 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-07-12 13:00 1,498,624 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-07-12 12:59 1,498,624 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-06-18 19:03 68,489 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_06_18_13_59_26_small.dmp.zip
2007-06-14 04:45 1,568 ----a-w C:\Documents and Settings\rcopes\Application Data\mpauth.dat
2007-06-08 21:34 2,634,752 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-04-03 21:13 1,399,296 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2006-10-09 15:48 2,640,896 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2006-10-09 15:48 1,336,832 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2006-10-03 06:43 2,402,550 ----a-w C:\WINDOWS\inf\SET59.tmp
2006-08-22 18:24 1,307,136 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2006-08-04 12:37 1,296,896 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2006-07-05 21:13 1,264,640 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0000DE80-AEC3-70C3-4176-CE509063E000}]
C:\WINDOWS\System32\mscorews.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"= {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll [2008-02-06 10:03 256000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 20:32:56 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 14:34:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2008-02-07 14:37:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 20:36:51
.
2008-01-24 14:57:27 --- E O F ---
bamajim
10.4K Posts
0
February 11th, 2008 13:00
Looks like we have some work to do.
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\jmjyjids.exe
C:\wpohl.exe
C:\arbfikac.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\daxtime.dll
C:\WINDOWS\hotporn.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\dp0.dll
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\liqui.exe
C:\WINDOWS\xxxvideo.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\spredirect.dll
C:\WINDOWS\liqad.dll
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\kvnab.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\adbar.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\liqui.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\liqad$.exe
Folder::
C:\WINDOWS\system32\acespy
C:\WINDOWS\efmhfrct
C:\WINDOWS\system32\jnhjkfrn
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
"The world is what you make of it"
bamajim
10.4K Posts
0
February 11th, 2008 14:00
Good work. If the CFScript.txt file is still on your desktop, delete it we are going to make another one.
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
C:\WINDOWS\system32\jnhjkfrn
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"=-
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
2. Reboot your PC rerun Hijackthis and post a fresh Hiajckthis log as well
"The world is what you make of it"
rickquick
7 Posts
0
February 11th, 2008 14:00
ComboFix 08-02.05.3 - rdc011307 2008-02-11 9:48:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.295 [GMT -6:00]
Running from: C:\Documents and Settings\rcopes\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rcopes\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\arbfikac.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\jmjyjids.exe
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
C:\wpohl.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\arbfikac.exe
C:\Program Files\3721
C:\Program Files\Accoona
C:\Program Files\akl
C:\Program Files\amsys
C:\Program Files\e-zshopper
C:\Program Files\p2pnetworks
C:\WINDOWS\efmhfrct
C:\WINDOWS\efmhfrct\1.png
C:\WINDOWS\efmhfrct\2.png
C:\WINDOWS\efmhfrct\3.png
C:\WINDOWS\efmhfrct\4.png
C:\WINDOWS\efmhfrct\5.png
C:\WINDOWS\efmhfrct\6.png
C:\WINDOWS\efmhfrct\7.png
C:\WINDOWS\efmhfrct\8.png
C:\WINDOWS\efmhfrct\9.png
C:\WINDOWS\efmhfrct\bottom-rc.gif
C:\WINDOWS\efmhfrct\config.png
C:\WINDOWS\efmhfrct\content.png
C:\WINDOWS\efmhfrct\download.gif
C:\WINDOWS\efmhfrct\frame-bg.gif
C:\WINDOWS\efmhfrct\frame-bottom-left.gif
C:\WINDOWS\efmhfrct\frame-h1bg.gif
C:\WINDOWS\efmhfrct\head.png
C:\WINDOWS\efmhfrct\icon.png
C:\WINDOWS\efmhfrct\indexwp.html
C:\WINDOWS\efmhfrct\main.css
C:\WINDOWS\efmhfrct\memory-prots.png
C:\WINDOWS\efmhfrct\net.png
C:\WINDOWS\efmhfrct\pc-mag.gif
C:\WINDOWS\efmhfrct\pc.gif
C:\WINDOWS\efmhfrct\poloska1.png
C:\WINDOWS\efmhfrct\poloska2.png
C:\WINDOWS\efmhfrct\poloska3.png
C:\WINDOWS\efmhfrct\promowp1.html
C:\WINDOWS\efmhfrct\promowp2.html
C:\WINDOWS\efmhfrct\promowp3.html
C:\WINDOWS\efmhfrct\promowp4.html
C:\WINDOWS\efmhfrct\promowp5.html
C:\WINDOWS\efmhfrct\reg.png
C:\WINDOWS\efmhfrct\repair.png
C:\WINDOWS\efmhfrct\scr-1.png
C:\WINDOWS\efmhfrct\scr-2.png
C:\WINDOWS\efmhfrct\start.png
C:\WINDOWS\efmhfrct\styles.css
C:\WINDOWS\efmhfrct\Thumbs.db
C:\WINDOWS\efmhfrct\top-rc.gif
C:\WINDOWS\efmhfrct\vline.gif
C:\WINDOWS\efmhfrct\wp.png
C:\WINDOWS\jmjyjids.exe
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn\
C:\WINDOWS\system32\rxjddnvj.exe
C:\wpohl.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-11 to 2008-02-11 )))))))))))))))))))))))))))))))
.
2008-02-07 14:18 . 2004-08-03 23:56 388,608 --a------ C:\kmd.exe
2008-02-07 12:23 . 2008-02-07 12:23
2008-02-07 11:37 . 2008-02-07 11:37
2008-02-06 22:17 . 2008-02-06 22:17
2008-02-06 22:16 . 2008-02-07 14:43
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 11:05 . 2008-02-06 11:05 0 --a------ C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17
2008-02-06 10:03 . 54,764 C:\WINDOWS\system32\jnhjkfrn
2008-02-06 10:03 . 2008-02-11 09:49 0 --a------ C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46
2008-01-15 09:03 . 2008-01-15 09:04
2008-01-14 15:21 . 2008-01-14 15:21
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 15:57 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-02-11 15:54 6,548 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-11 15:54 548,864 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-02-11 15:54 471,072 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-11 15:54 1,339,392 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-02-07 18:25 20,149,491 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-07 16:30 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-01 22:26 --------- d-----w C:\Program Files\Trillian
2008-01-15 15:15 --------- d-----w C:\Program Files\Yahoo!
2007-11-21 00:35 28,032 ----a-w C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-11-01 14:57 2,904,576 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-11-01 14:57 1,302,528 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-07-12 13:00 1,498,624 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-07-12 12:59 1,498,624 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-06-18 19:03 68,489 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_06_18_13_59_26_small.dmp.zip
2007-06-14 04:45 1,568 ----a-w C:\Documents and Settings\rcopes\Application Data\mpauth.dat
2007-06-08 21:34 2,634,752 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-04-03 21:13 1,399,296 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2006-10-09 15:48 2,640,896 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2006-10-09 15:48 1,336,832 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2006-10-03 06:43 2,402,550 ----a-w C:\WINDOWS\inf\SET59.tmp
2006-08-22 18:24 1,307,136 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2006-08-04 12:37 1,296,896 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2006-07-05 21:13 1,264,640 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"= {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 15:58:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 09:58:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2008-02-11 10:01:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-11 16:01:40
ComboFix2.txt 2008-02-07 20:37:00
.
2008-01-24 14:57:27 --- E O F ---
rickquick
7 Posts
0
February 11th, 2008 17:00
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:40:26 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\rcopes\Desktop\HiJackThis_v2.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182179388984
O16 - DPF: {7BE30DB7-4BB6-41A7-BE9C-EB9EB45725DE} (WebCamX Control) - http://208.42.209.86/WebCamX.cab
O16 - DPF: {F92211F4-3913-4DC2-A275-756374D848B0} (ERViewerOCX Control) - http://66.112.17.174/MP4DVR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D879E850-F59A-4357-8526-139D1D099036}: NameServer = 209.142.136.85,208.42.196.36
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe
--
End of file - 7605 bytes
rickquick
7 Posts
0
February 11th, 2008 17:00
ComboFix 08-02.05.3 - rdc011307 2008-02-11 11:24:13.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.492 [GMT -6:00]
Running from: C:\Documents and Settings\rcopes\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rcopes\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\system32\jnhjkfrn
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\jnhjkfrn
.
((((((((((((((((((((((((( Files Created from 2008-01-11 to 2008-02-11 )))))))))))))))))))))))))))))))
.
2008-02-11 09:46 . 2004-08-03 23:56 388,608 --a------ C:\kmd.exe
2008-02-07 12:23 . 2008-02-07 12:23
2008-02-07 11:37 . 2008-02-07 11:37
2008-02-06 22:17 . 2008-02-06 22:17
2008-02-06 22:16 . 2008-02-07 14:43
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 22:16 . 2008-02-06 22:16
2008-02-06 11:05 . 2008-02-06 11:05 0 --a------ C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17
2008-02-06 10:03 . 2008-02-11 09:49 0 --a------ C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46
2008-01-15 09:03 . 2008-01-15 09:04
2008-01-14 15:21 . 2008-01-14 15:21
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 17:32 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-02-11 17:29 6,980 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-11 17:29 534,560 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-07 16:30 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-01 22:26 --------- d-----w C:\Program Files\Trillian
2008-01-15 15:15 --------- d-----w C:\Program Files\Yahoo!
2007-11-21 00:35 28,032 ----a-w C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-06-14 04:45 1,568 ----a-w C:\Documents and Settings\rcopes\Application Data\mpauth.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S1 jnhjkfrn;jnhjkfrn;C:\WINDOWS\system32\jnhjkfrn []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 17:33:21 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 11:36:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
.
**************************************************************************
.
Completion time: 2008-02-11 11:39:43 - machine was rebooted [rcopes]
ComboFix-quarantined-files.txt 2008-02-11 17:39:35
ComboFix2.txt 2008-02-11 16:01:51
ComboFix3.txt 2008-02-07 20:37:00
.
2008-01-24 14:57:27 --- E O F ---
rickquick
7 Posts
0
February 11th, 2008 17:00
Internet Explorer cannot display the webpage Most likely causes:
- You are not connected to the Internet.
- The website is encountering problems.
- There might be a typing error in the address.
What you can try:---------------------------------------------------------------------------------------------------------------------------------
Last diagnostic run time: 02/11/08 13:38:33 HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity info HTTP: Successfully connected to www.microsoft.com. info FTP (Passive): Successfully connected to ftp.microsoft.com. info HTTPS: Successfully connected to www.microsoft.com.
bamajim
10.4K Posts
0
February 11th, 2008 17:00
Good work. Since you have CCleaner, go ahead and re - run it.
1. Run an online virus scan called Kaspersky from HERE.
2. A new smaller window will pop up. Press on " Accept". After reading the contents.
3. Now Kaspersky will update the anti-virus database. Let it run.
4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
5. Then click on " My Computer". And the scan will start.
6. When the scan is complete Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan
"The world is what you make of it"
bamajim
10.4K Posts
0
February 11th, 2008 18:00
rickquick
You should be able to run the Kapsersky online using FireFox. Unless it won't allow Active X
You could also reload IE from here
http://www.microsoft.com/windows/products/winfamily/ie/default.mspx
"The world is what you make of it"