|
|
|||||||
| Register | Projects | Blogs | FAQ | Search | Today's Posts | Mark Forums Read |
|
|
#1 |
|
Junior Member
Join Date: May 2008
Posts: 6
|
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:27:38 PM, on 5/24/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Opera 9\Opera.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [a4b48bbb] rundll32.exe "C:\WINDOWS\system32\fgcuhmvp.dll",b O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\vpvpylcq.dll",s O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe O4 - HKCU\..\Policies\Explorer\Run: [Windows Printing Driver] WinSpooler.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary...s.cab57176.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1190841120937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1190841098843 O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames...e.cab60231.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab O16 - DPF: {E2E799BB-0285-4F31-9AE9-F21B4430A775} (EngOrkaWebCtrl Class) - http://orka.gamengame.com/Game_Exe/EngOrkaWeb.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CD55ABFE-609D-45C8-9FBA-4199E6ECF5B3}: NameServer = 192.168.1.1 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: npkcmsvc - Unknown owner - C:\Nexon\Mabinogi\npkcmsvc.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 8578 bytes ---------------------------------------------------------------------- Kaspersky Log: ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Saturday, May 24, 2008 2:02:31 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 24/05/2008 Kaspersky Anti-Virus database records: 799624 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ G:\ Scan Statistics: Total number of scanned objects: 114034 Number of viruses found: 11 Number of infected objects: 1213 Number of suspicious objects: 0 Duration of the scan process: 01:18:45 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Alex\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Alex\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\Temp\eraseme_53621.exe Infected: Trojan.Win32.Agent.giv skipped C:\Documents and Settings\Alex\Local Settings\Temp\Setup+Patch.exe Infected: P2P-Worm.Win32.Agent.bq skipped C:\Documents and Settings\Alex\Local Settings\Temp\TEMP01.RAR/Setup+Patch.exe Infected: P2P-Worm.Win32.Agent.bq skipped C:\Documents and Settings\Alex\Local Settings\Temp\TEMP01.RAR CAB: infected - 1 skipped C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Alex\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Alex\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Black Isle\BGII - SoA\Baldur.err Object is locked skipped C:\Program Files\Black Isle\BGII - SoA\Baldur.log Object is locked skipped C:\Program Files\Black Isle\BGII - SoA\temp\default.toh Object is locked skipped C:\Program Files\Black Isle\BGII - SoA\temp\default.tot Object is locked skipped C:\Program Files\Eset\cache\CACHE.NDB Object is locked skipped C:\Program Files\Eset\logs\virlog.dat Object is locked skipped C:\Program Files\Eset\logs\warnlog.dat Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP257\A0097162.exe Infected: Trojan.Win32.Agent.jyc skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP257\A0097186.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sbz skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP259\A0097302.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sbz skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP270\A0103929.dll Infected: Backdoor.Win32.Agent.gwu skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP273\A0105236.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP283\A0107773.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trl skipped C:\System Volume Information\_restore{8DAB621C-A865-42DF-A6F6-FBB77F2D292B}\RP284\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\system32\agafdhwq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tbs skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\fxrkudgd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tbs skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\hjjsceap.dll Infected: Trojan.Win32.Monder.gen skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\uvavujti.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tbs skipped C:\WINDOWS\system32\vtUmJArs.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trk skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\WinSpooler.exe Infected: P2P-Worm.Win32.Agent.bq skipped C:\WINDOWS\system32\WinUpdating.exe Infected: Trojan.Win32.Agent.giv skipped C:\WINDOWS\system32\yioomqsd.dll Infected: Trojan.Win32.Monder.gen skipped C:\WINDOWS\Temp\ho2012.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tmj skipped C:\WINDOWS\Temp\lk2009.exe Infected: Trojan-Downloader.Win32.Agent.pwa skipped C:\WINDOWS\Temp\lk2010.exe Infected: Trojan-Downloader.Win32.Agent.pwa skipped C:\WINDOWS\Temp\Perflib_Perfdata_14c.dat Object is locked skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed. |
|
|
|
|
#2 |
|
Visiting Staff
Join Date: Sep 2007
Location: Ireland
Posts: 1,624
|
You got infected because you downloaded cracks
Please download the OTMoveIt2 by OldTimer.
Please visit this web page for instructions for downloading and running ComboFix http://www.bleepingcomputer.com/comb...o-use-combofix This includes installing the Windows XP Recovery Console in case you have not installed it yet. For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058. Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal. Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
__________________
Who watches The Watchmen? It's like you said. All I am is what I'm going after. ~Scratch~ |
|
|
|
|
#3 |
|
Junior Member
Join Date: May 2008
Posts: 6
|
Thank you for replying. I appreciate your help.
MoveIt Log: Explorer killed successfully C:\Documents and Settings\Alex\Local Settings\Temp\eraseme_53621.exe moved successfully. C:\Documents and Settings\Alex\Local Settings\Temp\Setup+Patch.exe moved successfully. C:\Documents and Settings\Alex\Local Settings\Temp\TEMP01.RAR moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\agafdhwq.dll C:\WINDOWS\system32\agafdhwq.dll NOT unregistered. C:\WINDOWS\system32\agafdhwq.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\fxrkudgd.dll C:\WINDOWS\system32\fxrkudgd.dll NOT unregistered. C:\WINDOWS\system32\fxrkudgd.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\hjjsceap.dll C:\WINDOWS\system32\hjjsceap.dll NOT unregistered. C:\WINDOWS\system32\hjjsceap.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\uvavujti.dll C:\WINDOWS\system32\uvavujti.dll NOT unregistered. C:\WINDOWS\system32\uvavujti.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtUmJArs.dll C:\WINDOWS\system32\vtUmJArs.dll NOT unregistered. C:\WINDOWS\system32\vtUmJArs.dll moved successfully. C:\WINDOWS\system32\WinSpooler.exe moved successfully. C:\WINDOWS\system32\WinUpdating.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\yioomqsd.dll C:\WINDOWS\system32\yioomqsd.dll NOT unregistered. C:\WINDOWS\system32\yioomqsd.dll moved successfully. Folder move failed. C:\WINDOWS\Temp scheduled to be moved on reboot. < purity > Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05242008_201322 Files moved on Reboot... C:\WINDOWS\Temp moved successfully. ----------------------------------------------------------------------- ComboFix Log: ComboFix 08-05-21.3 - Alex 2008-05-24 20:58:38.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1567 [GMT -4:00] Running from: C:\Documents and Settings\Alex\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BMa787b827.xml C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\adnmoery.exe C:\WINDOWS\system32\cgemfbdp.ini C:\WINDOWS\system32\CIlSBJlm.ini C:\WINDOWS\system32\CIlSBJlm.ini2 C:\WINDOWS\system32\cpbubtlh.exe C:\WINDOWS\system32\djdtaxss.dll C:\WINDOWS\system32\docqxtts.dll C:\WINDOWS\system32\experyjw.exe C:\WINDOWS\system32\fyydootd.dll C:\WINDOWS\system32\ijgeddkq.exe C:\WINDOWS\system32\jrfwkpes.exe C:\WINDOWS\system32\knqsYJlm.ini C:\WINDOWS\system32\knqsYJlm.ini2 C:\WINDOWS\system32\kobprfxn.dll C:\WINDOWS\system32\lgqhuppa.dll C:\WINDOWS\system32\lpxrpgvl.exe C:\WINDOWS\system32\mfinkjnh.ini C:\WINDOWS\system32\mkhjauce.exe C:\WINDOWS\system32\mscdyoko.exe C:\WINDOWS\system32\nbndabbq.dll C:\WINDOWS\system32\nongdapd.exe C:\WINDOWS\system32\nVFhQqru.ini C:\WINDOWS\system32\nVFhQqru.ini2 C:\WINDOWS\system32\obahvnfl.ini C:\WINDOWS\system32\pmdeefgr.ini C:\WINDOWS\system32\pvmhucgf.ini C:\WINDOWS\system32\qggesrlp.ini C:\WINDOWS\system32\quypxrsa.exe C:\WINDOWS\system32\tlqvvdgo.dll C:\WINDOWS\system32\urqQhFVn.dll C:\WINDOWS\system32\UtENVvut.ini C:\WINDOWS\system32\UtENVvut.ini2 C:\WINDOWS\system32\uxEhiRqr.ini C:\WINDOWS\system32\uxEhiRqr.ini2 C:\WINDOWS\system32\wdlbpeuv.exe C:\WINDOWS\system32\xkfriodp.exe C:\WINDOWS\system32\xwkvfrus.exe C:\WINDOWS\system32\xxklkvni.ini C:\WINDOWS\system32\yhwiextk.exe C:\WINDOWS\system32\yufbomcd.exe C:\WINDOWS\system32\ywvibbyt.exe . ((((((((((((((((((((((((( Files Created from 2008-04-25 to 2008-05-25 ))))))))))))))))))))))))))))))) . 2008-05-24 21:01 . 2008-05-24 21:01 294 ---hs---- C:\WINDOWS\system32\qggesrlp.ini 2008-05-24 20:13 . 2008-05-24 20:13 <DIR> d-------- C:\_OTMoveIt 2008-05-24 16:33 . 2008-05-24 16:33 136,192 --a------ C:\WINDOWS\system32\xnqygflo.dll 2008-05-24 16:30 . 2008-05-24 16:30 115,200 --a------ C:\WINDOWS\system32\plrseggq.dll 2008-05-24 16:25 . 2008-05-24 16:25 126,464 --a------ C:\WINDOWS\system32\vpvpylcq.dll 2008-05-24 14:43 . 2008-05-24 14:43 126,464 --a------ C:\WINDOWS\system32\ytlmjpdq.dll 2008-05-24 14:04 . 2008-05-24 14:04 268 --ah----- C:\sqmdata00.sqm 2008-05-24 14:04 . 2008-05-24 14:04 244 --ah----- C:\sqmnoopt00.sqm 2008-05-24 13:03 . 2008-05-24 13:03 136,192 --a------ C:\WINDOWS\system32\nkyllgwq.dll 2008-05-24 13:01 . 2008-05-24 13:01 126,464 --a------ C:\WINDOWS\system32\pjvwkuwp.dll 2008-05-24 07:41 . 2008-05-24 07:41 136,192 --a------ C:\WINDOWS\system32\ryiyukar.dll 2008-05-23 22:52 . 2008-05-23 22:52 126,464 --a------ C:\WINDOWS\system32\yubdgncc.dll 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-05-23 21:53 . 2008-05-23 21:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-05-23 16:28 . 2008-05-23 16:28 133,632 --a------ C:\WINDOWS\system32\spcirjaf.dll 2008-05-23 16:23 . 2008-05-23 16:23 126,464 --a------ C:\WINDOWS\system32\aprfmsvp.dll 2008-05-22 19:26 . 2008-05-22 19:26 134,144 --a------ C:\WINDOWS\system32\wblhrxlr.dll 2008-05-22 16:01 . 2008-05-22 16:01 134,144 --a------ C:\WINDOWS\system32\svfkollg.dll 2008-05-21 17:24 . 2008-05-21 17:24 58,880 --a------ C:\WINDOWS\system32\vtUnmMcA.dll 2008-05-21 16:02 . 2008-05-21 16:02 <DIR> d-------- C:\Program Files\Black Isle 2008-05-21 15:58 . 2008-05-21 15:58 <DIR> d-------- C:\Program Files\PowerISO 2008-05-18 13:19 . 2008-05-18 13:19 57,344 --a------ C:\WINDOWS\system32\efcYSmKb.dll.vir 2008-05-18 12:47 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-05-18 12:46 . 2008-05-18 12:47 <DIR> d-------- C:\Program Files\Java 2008-05-18 12:46 . 2008-05-18 12:46 <DIR> d-------- C:\Program Files\Common Files\Java 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-05-18 11:16 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-05-17 22:42 . 2008-05-24 16:18 558 --a------ C:\WINDOWS\wininit.ini 2008-05-17 22:22 . 2008-05-17 22:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-05-11 08:37 . 2008-05-11 08:37 37,888 --a------ C:\WINDOWS\system32\rar.exe 2008-04-25 15:31 . 2008-04-26 17:54 <DIR> d-------- C:\Program Files\Neffy . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-25 00:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-24 14:10 --------- d-----w C:\Documents and Settings\Alex\Application Data\OpenOffice.org2 2008-05-21 20:15 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-21 20:02 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-05-18 20:56 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft 2008-05-18 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-16 23:24 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-05-16 23:23 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-05-11 12:50 --------- d-----w C:\Documents and Settings\Alex\Application Data\LimeWire 2008-05-04 18:05 --------- d-----w C:\Program Files\DivX 2008-04-19 16:03 0 ----a-r C:\logwmemory.bin 2008-04-19 16:01 --------- d-----w C:\Documents and Settings\Alex\Application Data\Soldat 2008-04-18 22:40 --------- d-----w C:\Documents and Settings\Alex\Application Data\Megaupload 2008-04-15 00:52 --------- d-----w C:\Program Files\Google 2008-04-15 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft 2008-04-15 00:48 22,328 ----a-w C:\Documents and Settings\Alex\Application Data\PnkBstrK.sys 2008-04-15 00:48 2,337,865 ----a-w C:\WINDOWS\system32\pbsvc.exe 2008-04-15 00:35 --------- d-----w C:\Program Files\Ubisoft 2008-03-29 00:19 --------- d-----w C:\Documents and Settings\Alex\Application Data\Leadertech . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CCB7673-04D5-4DE7-916B-384A3642BAF4}] 2008-05-21 17:24 58880 --a------ C:\WINDOWS\system32\vtUnmMcA.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42890DB3-104C-4BE2-8EDB-2722790215D9}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F88D332-F0A6-4600-8106-6C2471CDC156}] C:\WINDOWS\system32\tuvVNEtU.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53763DB0-E0DA-4CA0-9BA5-B4107150B42F}] C:\WINDOWS\system32\rqRihExu.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5460F768-5AE2-4EAC-ABB8-8CCF29E0443A}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E4FBF7E-E70D-4F19-ABB9-68118D9AAAAE}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8259E021-82F4-4708-81FC-6AF66F082CE4}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E19A07-5728-42A9-9695-1363CC2D0974}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c565c75-34a5-4ab1-bdc4-d02f205d9645}] 2008-05-24 16:33 136192 --a------ C:\WINDOWS\system32\xnqygflo.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102}] C:\WINDOWS\system32\mlJBSlIC.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCBA4416-0D03-4848-9B1E-D73FF1224557}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e6f57955-adbf-48c4-bd9f-5e0b4759b760}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA141A9B-2D3B-4862-AB06-F59A725EFCCF}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCCF689E-317A-4CAE-98D4-9F203E10990F}] C:\WINDOWS\system32\mlJYsqnk.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 14:20 81920] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 19:56 15360] "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 09:08 136136] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-03 18:55 949376] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-28 17:52 8531968] "nwiz"="nwiz.exe" [2007-10-28 17:52 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-28 17:52 81920] "RTHDCPL"="RTHDCPL.EXE" [2007-11-06 11:50 16855552 C:\WINDOWS\RTHDCPL.exe] "ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [ ] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 19:50 233472] "a4b48bbb"="C:\WINDOWS\system32\plrseggq.dll" [2008-05-24 16:30 115200] "BMa787b827"="C:\WINDOWS\system32\vpvpylcq.dll" [2008-05-24 16:25 126464] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-03 19:15:58 692224] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{0CCB7673-04D5-4DE7-916B-384A3642BAF4}"= C:\WINDOWS\system32\vtUnmMcA.dll [2008-05-21 17:24 58880] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrQHyA] awtrQHyA.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcYSmKb] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRJArSk] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnmMcA] vtUnmMcA.dll 2008-05-21 17:24 58880 C:\WINDOWS\system32\vtUnmMcA.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i420vfw.dll "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= R2 SocketLock;Raw Socket Lock Driver;C:\WINDOWS\system32\socketlock.sys [2007-06-01 21:13] R3 IPN2120;Instant Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys [2003-07-10 10:09] R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2003-05-14 16:01] S2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [] S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\CBTNDIS5.SYS [2003-07-16 22:28] S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys [] S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys [] S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys [] S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys [] S3 XDva076;XDva076;C:\WINDOWS\system32\XDva076.sys [] S3 XDva132;XDva132;C:\WINDOWS\system32\XDva132.sys [] S4 Srvwdiss;Srvwdiss;C:\WINDOWS\system32\drivers\null.sys [2001-08-23 08:00] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23adc0f8-10d7-11dc-9e73-806d6172696f}] \Shell\AutoRun\command - D:\setup.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-24 21:01:25 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... folder error: C:\WINDOWS\TEMP\ scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\vtUnmMcA.dll . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe . ************************************************************************** . Completion time: 2008-05-24 21:10:40 - machine was rebooted [Alex] ComboFix-quarantined-files.txt 2008-05-25 01:10:36 Pre-Run: 51,554,406,400 bytes free Post-Run: 54,032,904,192 bytes free 229 ----------------------------------------------------------------------- HJT Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:11:50 PM, on 5/24/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\Program Files\EditPlus 2\editplus.exe C:\Program Files\Opera 9\Opera.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {0CCB7673-04D5-4DE7-916B-384A3642BAF4} - C:\WINDOWS\system32\vtUnmMcA.dll O2 - BHO: (no name) - {4F88D332-F0A6-4600-8106-6C2471CDC156} - C:\WINDOWS\system32\tuvVNEtU.dll (file missing) O2 - BHO: (no name) - {53763DB0-E0DA-4CA0-9BA5-B4107150B42F} - C:\WINDOWS\system32\rqRihExu.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: {5469d502-f20d-4cdb-1ba4-5a4357c565c9} - {9c565c75-34a5-4ab1-bdc4-d02f205d9645} - C:\WINDOWS\system32\xnqygflo.dll O2 - BHO: (no name) - {C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102} - C:\WINDOWS\system32\mlJBSlIC.dll (file missing) O2 - BHO: (no name) - {FCCF689E-317A-4CAE-98D4-9F203E10990F} - C:\WINDOWS\system32\mlJYsqnk.dll (file missing) O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [a4b48bbb] rundll32.exe "C:\WINDOWS\system32\plrseggq.dll",b O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\vpvpylcq.dll",s O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary...s.cab57176.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1190841120937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1190841098843 O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames...e.cab60231.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab O16 - DPF: {E2E799BB-0285-4F31-9AE9-F21B4430A775} (EngOrkaWebCtrl Class) - http://orka.gamengame.com/Game_Exe/EngOrkaWeb.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CD55ABFE-609D-45C8-9FBA-4199E6ECF5B3}: NameServer = 192.168.1.1 O20 - Winlogon Notify: awtrQHyA - awtrQHyA.dll (file missing) O20 - Winlogon Notify: efcYSmKb - C:\WINDOWS\ O20 - Winlogon Notify: rqRJArSk - C:\WINDOWS\ O20 - Winlogon Notify: vtUnmMcA - C:\WINDOWS\SYSTEM32\vtUnmMcA.dll O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: npkcmsvc - Unknown owner - C:\Nexon\Mabinogi\npkcmsvc.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 9520 bytes |
|
|
|
|
#4 | |
|
Visiting Staff
Join Date: Sep 2007
Location: Ireland
Posts: 1,624
|
Hello
1. Close any open browsers. 2. Open notepad and copy/paste the text in the quotebox below into it: Quote:
![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at "C:\ComboFix.txt" Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall Go to this site: http://www.virustotal.com/ On top you'll find 'Browse' Click the browse button and browse to the file: C:\WINDOWS\system32\rar.exe Click open. Then click the 'Send' button next to it. This will scan the file. Please be patient. Once scanned, copy and paste the results as well in your next reply. Also post a new HijackThis log
__________________
Who watches The Watchmen? It's like you said. All I am is what I'm going after. ~Scratch~ |
|
|
|
|
|
#5 |
|
Junior Member
Join Date: May 2008
Posts: 6
|
ComboFix Log:
ComboFix 08-05-21.3 - Alex 2008-05-25 9:40:22.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1497 [GMT -4:00] Running from: C:\Documents and Settings\Alex\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Alex\Desktop\CFScript.txt * Created a new restore point * Resident AV is active FILE :: C:\WINDOWS\system32\aprfmsvp.dll C:\WINDOWS\system32\efcYSmKb.dll.vir C:\WINDOWS\system32\nkyllgwq.dll C:\WINDOWS\system32\pjvwkuwp.dll C:\WINDOWS\system32\plrseggq.dll C:\WINDOWS\system32\qggesrlp.ini C:\WINDOWS\system32\ryiyukar.dll C:\WINDOWS\system32\spcirjaf.dll C:\WINDOWS\system32\svfkollg.dll C:\WINDOWS\system32\vpvpylcq.dll C:\WINDOWS\system32\vtUnmMcA.dll C:\WINDOWS\system32\wblhrxlr.dll C:\WINDOWS\system32\xnqygflo.dll C:\WINDOWS\system32\ytlmjpdq.dll C:\WINDOWS\system32\yubdgncc.dll D:\setup.exe D:\SETUP.EXE . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\abHNoXbc.ini C:\WINDOWS\system32\abHNoXbc.ini2 C:\WINDOWS\system32\aprfmsvp.dll C:\WINDOWS\system32\cbXoNHba.dll C:\WINDOWS\system32\efcYSmKb.dll.vir C:\WINDOWS\system32\nkyllgwq.dll C:\WINDOWS\system32\pjvwkuwp.dll C:\WINDOWS\system32\plrseggq.dll C:\WINDOWS\system32\qggesrlp.ini C:\WINDOWS\system32\ryiyukar.dll C:\WINDOWS\system32\spcirjaf.dll C:\WINDOWS\system32\svfkollg.dll C:\WINDOWS\system32\vpvpylcq.dll C:\WINDOWS\system32\vtUnmMcA.dll C:\WINDOWS\system32\wblhrxlr.dll C:\WINDOWS\system32\xnqygflo.dll C:\WINDOWS\system32\yfxbqqas.ini C:\WINDOWS\system32\ytlmjpdq.dll C:\WINDOWS\system32\yubdgncc.dll C:\WINDOWS\system32\yuhtowni.exe D:\SETUP.EXE . . . . failed to delete . ((((((((((((((((((((((((( Files Created from 2008-04-25 to 2008-05-25 ))))))))))))))))))))))))))))))) . 2008-05-25 09:45 . 2008-05-25 09:45 294 ---hs---- C:\WINDOWS\system32\yfxbqqas.ini 2008-05-25 06:57 . 2008-05-25 06:57 115,712 --a------ C:\WINDOWS\system32\saqqbxfy.dll 2008-05-24 21:16 . 2008-05-24 21:17 136,192 --a------ C:\WINDOWS\system32\fgbixbph.dll 2008-05-24 21:16 . 2008-05-24 21:16 126,464 --a------ C:\WINDOWS\system32\wceynhmv.dll 2008-05-24 21:10 . 2008-05-24 21:10 0 --a------ C:\WINDOWS\BMa787b827.xml 2008-05-24 20:13 . 2008-05-24 20:13 <DIR> d-------- C:\_OTMoveIt 2008-05-24 14:04 . 2008-05-24 14:04 268 --ah----- C:\sqmdata00.sqm 2008-05-24 14:04 . 2008-05-24 14:04 244 --ah----- C:\sqmnoopt00.sqm 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-05-23 21:53 . 2008-05-23 21:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-05-21 16:02 . 2008-05-21 16:02 <DIR> d-------- C:\Program Files\Black Isle 2008-05-21 15:58 . 2008-05-21 15:58 <DIR> d-------- C:\Program Files\PowerISO 2008-05-18 12:47 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-05-18 12:46 . 2008-05-18 12:47 <DIR> d-------- C:\Program Files\Java 2008-05-18 12:46 . 2008-05-18 12:46 <DIR> d-------- C:\Program Files\Common Files\Java 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-05-18 11:16 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-05-17 22:42 . 2008-05-24 16:18 558 --a------ C:\WINDOWS\wininit.ini 2008-05-17 22:22 . 2008-05-17 22:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-05-11 08:37 . 2008-05-11 08:37 37,888 --a------ C:\WINDOWS\system32\rar.exe 2008-04-25 15:31 . 2008-04-26 17:54 <DIR> d-------- C:\Program Files\Neffy . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-25 00:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-24 14:10 --------- d-----w C:\Documents and Settings\Alex\Application Data\OpenOffice.org2 2008-05-21 20:15 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-21 20:02 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-05-18 20:56 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft 2008-05-18 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-16 23:24 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-05-16 23:23 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-05-11 12:50 --------- d-----w C:\Documents and Settings\Alex\Application Data\LimeWire 2008-05-04 18:05 --------- d-----w C:\Program Files\DivX 2008-04-19 16:03 0 ----a-r C:\logwmemory.bin 2008-04-19 16:01 --------- d-----w C:\Documents and Settings\Alex\Application Data\Soldat 2008-04-18 22:40 --------- d-----w C:\Documents and Settings\Alex\Application Data\Megaupload 2008-04-15 00:52 --------- d-----w C:\Program Files\Google 2008-04-15 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft 2008-04-15 00:48 22,328 ----a-w C:\Documents and Settings\Alex\Application Data\PnkBstrK.sys 2008-04-15 00:48 2,337,865 ----a-w C:\WINDOWS\system32\pbsvc.exe 2008-04-15 00:35 --------- d-----w C:\Program Files\Ubisoft 2008-03-29 00:19 --------- d-----w C:\Documents and Settings\Alex\Application Data\Leadertech . ((((((((((((((((((((((((((((( snapshot@2008-05-24_21.10.20.68 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-25 01:01:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-25 13:44:29 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-03-09 12:13:13 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-05-25 01:05:27 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-03-09 12:13:13 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-05-25 01:05:28 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CCB7673-04D5-4DE7-916B-384A3642BAF4}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42890DB3-104C-4BE2-8EDB-2722790215D9}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F88D332-F0A6-4600-8106-6C2471CDC156}] C:\WINDOWS\system32\tuvVNEtU.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53763DB0-E0DA-4CA0-9BA5-B4107150B42F}] C:\WINDOWS\system32\rqRihExu.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5460F768-5AE2-4EAC-ABB8-8CCF29E0443A}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E4FBF7E-E70D-4F19-ABB9-68118D9AAAAE}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8259E021-82F4-4708-81FC-6AF66F082CE4}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97E19A07-5728-42A9-9695-1363CC2D0974}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c565c75-34a5-4ab1-bdc4-d02f205d9645}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102}] C:\WINDOWS\system32\mlJBSlIC.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C59B0C61-C56C-43D4-9684-52802A9DD2ED}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCBA4416-0D03-4848-9B1E-D73FF1224557}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e6f57955-adbf-48c4-bd9f-5e0b4759b760}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e718d4ee-387c-47bd-9678-edd25815beda}] 2008-05-24 21:17 136192 --a------ C:\WINDOWS\system32\fgbixbph.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA141A9B-2D3B-4862-AB06-F59A725EFCCF}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCCF689E-317A-4CAE-98D4-9F203E10990F}] C:\WINDOWS\system32\mlJYsqnk.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 14:20 81920] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 19:56 15360] "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 09:08 136136] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-03 18:55 949376] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-28 17:52 8531968] "nwiz"="nwiz.exe" [2007-10-28 17:52 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-28 17:52 81920] "RTHDCPL"="RTHDCPL.EXE" [2007-11-06 11:50 16855552 C:\WINDOWS\RTHDCPL.exe] "ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [ ] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 19:50 233472] "a4b48bbb"="C:\WINDOWS\system32\saqqbxfy.dll" [2008-05-25 06:57 115712] "BMa787b827"="C:\WINDOWS\system32\wceynhmv.dll" [2008-05-24 21:16 126464] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-03 19:15:58 692224] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrQHyA] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcYSmKb] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRJArSk] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnmMcA] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i420vfw.dll "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= R2 SocketLock;Raw Socket Lock Driver;C:\WINDOWS\system32\socketlock.sys [2007-06-01 21:13] R3 IPN2120;Instant Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys [2003-07-10 10:09] R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2003-05-14 16:01] S2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [] S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\CBTNDIS5.SYS [2003-07-16 22:28] S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys [] S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys [] S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys [] S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys [] S3 XDva076;XDva076;C:\WINDOWS\system32\XDva076.sys [] S3 XDva132;XDva132;C:\WINDOWS\system32\XDva132.sys [] S4 Srvwdiss;Srvwdiss;C:\WINDOWS\system32\drivers\null.sys [2001-08-23 08:00] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-25 09:44:56 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... folder error: C:\WINDOWS\TEMP\ C:\WINDOWS\system32\yfxbqqas.ini 294 bytes scan completed successfully hidden files: 1 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe . ************************************************************************** . Completion time: 2008-05-25 9:52:23 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-25 13:52:20 ComboFix2.txt 2008-05-25 01:10:41 Pre-Run: 54,034,038,784 bytes free Post-Run: 54,020,136,960 bytes free 221 ------------------------------------------------------------------ VirusTotal Log: MD5: 1d5a7020465c89a816a7510ed6db1c9c First received: 12.08.2007 17:50:53 (CET) Date: 05.13.2008 09:10:17 (CET) [>12D] Results: 2/31 Permalink: analisis/cd684fd471d5bef30d93b85110a5e528 ------------------------------------------------------------------ HJT Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:22:12 PM, on 5/25/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Opera 9\Opera.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {4F88D332-F0A6-4600-8106-6C2471CDC156} - C:\WINDOWS\system32\tuvVNEtU.dll (file missing) O2 - BHO: (no name) - {53763DB0-E0DA-4CA0-9BA5-B4107150B42F} - C:\WINDOWS\system32\rqRihExu.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102} - C:\WINDOWS\system32\mlJBSlIC.dll (file missing) O2 - BHO: {adeb5185-2dde-8769-db74-c783ee4d817e} - {e718d4ee-387c-47bd-9678-edd25815beda} - C:\WINDOWS\system32\fgbixbph.dll O2 - BHO: (no name) - {FCCF689E-317A-4CAE-98D4-9F203E10990F} - C:\WINDOWS\system32\mlJYsqnk.dll (file missing) O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [a4b48bbb] rundll32.exe "C:\WINDOWS\system32\saqqbxfy.dll",b O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\wceynhmv.dll",s O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary...s.cab57176.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1190841120937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1190841098843 O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames...e.cab60231.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab O16 - DPF: {E2E799BB-0285-4F31-9AE9-F21B4430A775} (EngOrkaWebCtrl Class) - http://orka.gamengame.com/Game_Exe/EngOrkaWeb.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CD55ABFE-609D-45C8-9FBA-4199E6ECF5B3}: NameServer = 192.168.1.1 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: npkcmsvc - Unknown owner - C:\Nexon\Mabinogi\npkcmsvc.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 9213 bytes |
|
|
|
|
#6 | |
|
Visiting Staff
Join Date: Sep 2007
Location: Ireland
Posts: 1,624
|
Hello
1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present): R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: (no name) - {4F88D332-F0A6-4600-8106-6C2471CDC156} - C:\WINDOWS\system32\tuvVNEtU.dll (file missing) O2 - BHO: (no name) - {53763DB0-E0DA-4CA0-9BA5-B4107150B42F} - C:\WINDOWS\system32\rqRihExu.dll (file missing) O2 - BHO: (no name) - {C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102} - C:\WINDOWS\system32\mlJBSlIC.dll (file missing) O2 - BHO: {adeb5185-2dde-8769-db74-c783ee4d817e} - {e718d4ee-387c-47bd-9678-edd25815beda} - C:\WINDOWS\system32\fgbixbph.dll O2 - BHO: (no name) - {FCCF689E-317A-4CAE-98D4-9F203E10990F} - C:\WINDOWS\system32\mlJYsqnk.dll (file missing) O4 - HKLM\..\Run: [a4b48bbb] rundll32.exe "C:\WINDOWS\system32\saqqbxfy.dll",b O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\wceynhmv.dll",s 2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. 1. Close any open browsers. 2. Open notepad and copy/paste the text in the quotebox below into it: Quote:
![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at "C:\ComboFix.txt" Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall Also post a new HijackThis log
__________________
Who watches The Watchmen? It's like you said. All I am is what I'm going after. ~Scratch~ |
|
|
|
|
|
#7 |
|
Junior Member
Join Date: May 2008
Posts: 6
|
ComboFix Log:
ComboFix 08-05-21.3 - Alex 2008-05-25 17:59:19.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1560 [GMT -4:00] Running from: C:\Documents and Settings\Alex\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Alex\Desktop\CFScript.txt * Created a new restore point * Resident AV is active FILE :: C:\WINDOWS\BMa787b827.xml C:\WINDOWS\system32\fgbixbph.dll C:\WINDOWS\system32\rar.exe C:\WINDOWS\system32\saqqbxfy.dll C:\WINDOWS\system32\wceynhmv.dll C:\WINDOWS\system32\yfxbqqas.ini . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BMa787b827.xml C:\WINDOWS\pskt.ini C:\WINDOWS\system32\fgbixbph.dll C:\WINDOWS\system32\rar.exe C:\WINDOWS\system32\saqqbxfy.dll C:\WINDOWS\system32\wceynhmv.dll C:\WINDOWS\system32\yfxbqqas.ini . ((((((((((((((((((((((((( Files Created from 2008-04-25 to 2008-05-25 ))))))))))))))))))))))))))))))) . 2008-05-24 20:13 . 2008-05-24 20:13 <DIR> d-------- C:\_OTMoveIt 2008-05-24 14:04 . 2008-05-24 14:04 268 --ah----- C:\sqmdata00.sqm 2008-05-24 14:04 . 2008-05-24 14:04 244 --ah----- C:\sqmnoopt00.sqm 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-05-23 22:05 . 2008-05-23 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-05-23 21:53 . 2008-05-23 21:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-05-21 16:02 . 2008-05-21 16:02 <DIR> d-------- C:\Program Files\Black Isle 2008-05-21 15:58 . 2008-05-21 15:58 <DIR> d-------- C:\Program Files\PowerISO 2008-05-18 12:47 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-05-18 12:46 . 2008-05-18 12:47 <DIR> d-------- C:\Program Files\Java 2008-05-18 12:46 . 2008-05-18 12:46 <DIR> d-------- C:\Program Files\Common Files\Java 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-18 11:16 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes 2008-05-18 11:16 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-05-18 11:16 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-05-17 22:42 . 2008-05-24 16:18 558 --a------ C:\WINDOWS\wininit.ini 2008-05-17 22:22 . 2008-05-17 22:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-04-25 15:31 . 2008-04-26 17:54 <DIR> d-------- C:\Program Files\Neffy . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-25 00:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-24 14:10 --------- d-----w C:\Documents and Settings\Alex\Application Data\OpenOffice.org2 2008-05-21 20:15 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-21 20:02 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-05-18 20:56 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft 2008-05-18 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-16 23:24 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-05-11 12:50 --------- d-----w C:\Documents and Settings\Alex\Application Data\LimeWire 2008-05-04 18:05 --------- d-----w C:\Program Files\DivX 2008-04-19 16:03 0 ----a-r C:\logwmemory.bin 2008-04-19 16:01 --------- d-----w C:\Documents and Settings\Alex\Application Data\Soldat 2008-04-18 22:40 --------- d-----w C:\Documents and Settings\Alex\Application Data\Megaupload 2008-04-15 00:52 --------- d-----w C:\Program Files\Google 2008-04-15 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft 2008-04-15 00:48 22,328 ----a-w C:\Documents and Settings\Alex\Application Data\PnkBstrK.sys 2008-04-15 00:35 --------- d-----w C:\Program Files\Ubisoft 2008-03-29 00:19 --------- d-----w C:\Documents and Settings\Alex\Application Data\Leadertech . ((((((((((((((((((((((((((((( snapshot@2008-05-24_21.10.20.68 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-25 01:01:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-25 22:02:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-03-09 12:13:13 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-05-25 01:05:27 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-03-09 12:13:13 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-05-25 01:05:28 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102}] C:\WINDOWS\system32\mlJBSlIC.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 14:20 81920] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 19:56 15360] "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 09:08 136136] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-03 18:55 949376] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-28 17:52 8531968] "nwiz"="nwiz.exe" [2007-10-28 17:52 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-28 17:52 81920] "RTHDCPL"="RTHDCPL.EXE" [2007-11-06 11:50 16855552 C:\WINDOWS\RTHDCPL.exe] "ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [ ] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 19:50 233472] "BMa787b827"="C:\WINDOWS\system32\wceynhmv.dll" [ ] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-03 19:15:58 692224] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i420vfw.dll "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= R2 SocketLock;Raw Socket Lock Driver;C:\WINDOWS\system32\socketlock.sys [2007-06-01 21:13] R3 IPN2120;Instant Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys [2003-07-10 10:09] R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2003-05-14 16:01] S2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [] S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\CBTNDIS5.SYS [2003-07-16 22:28] S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys [] S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys [] S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys [] S3 XDva039;XDva039;C:\WINDOWS\system32\XDva039.sys [] S3 XDva076;XDva076;C:\WINDOWS\system32\XDva076.sys [] S3 XDva132;XDva132;C:\WINDOWS\system32\XDva132.sys [] S4 Srvwdiss;Srvwdiss;C:\WINDOWS\system32\drivers\null.sys [2001-08-23 08:00] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-25 18:03:17 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... folder error: C:\WINDOWS\TEMP\ scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe . ************************************************************************** . Completion time: 2008-05-25 18:10:37 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-25 22:10:31 ComboFix2.txt 2008-05-25 13:52:23 ComboFix3.txt 2008-05-25 01:10:41 Pre-Run: 54,118,494,208 bytes free Post-Run: 54,104,629,248 bytes free 160 --------------------------------------------------------------------- HJT Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:11:06 PM, on 5/25/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102} - C:\WINDOWS\system32\mlJBSlIC.dll (file missing) O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\wceynhmv.dll",s O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary...s.cab57176.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1190841120937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1190841098843 O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames...e.cab60231.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab O16 - DPF: {E2E799BB-0285-4F31-9AE9-F21B4430A775} (EngOrkaWebCtrl Class) - http://orka.gamengame.com/Game_Exe/EngOrkaWeb.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CD55ABFE-609D-45C8-9FBA-4199E6ECF5B3}: NameServer = 192.168.1.1 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: npkcmsvc - Unknown owner - C:\Nexon\Mabinogi\npkcmsvc.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 8522 bytes |
|
|
|
|
#8 |
|
Visiting Staff
Join Date: Sep 2007
Location: Ireland
Posts: 1,624
|
Hello
1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present): O2 - BHO: (no name) - {C4A34A66-E0FE-4F30-BC6E-FCBBF2DDB102} - C:\WINDOWS\system32\mlJBSlIC.dll (file missing) O4 - HKLM\..\Run: [BMa787b827] Rundll32.exe "C:\WINDOWS\system32\wceynhmv.dll",s 2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Reboot and post a new HijackThis log and tell me how your PC is running
__________________
Who watches The Watchmen? It's like you said. All I am is what I'm going after. ~Scratch~ |
|
|
|
|
#9 |
|
Junior Member
Join Date: May 2008
Posts: 6
|
My computer is working as it normally was. When the trojan was active, I had connection speed issues, but those seemed to have cleared up.
Malwarebytes Log: Malwarebytes' Anti-Malware 1.12 Database version: 786 Scan type: Quick Scan Objects scanned: 35154 Time elapsed: 2 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ------------------------------------------------------------------- HJT Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:47:19 PM, on 5/25/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\Raxco\PerfectDisk\PDEngine.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary...s.cab57176.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1190841120937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1190841098843 O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames...e.cab60231.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab O16 - DPF: {E2E799BB-0285-4F31-9AE9-F21B4430A775} (EngOrkaWebCtrl Class) - http://orka.gamengame.com/Game_Exe/EngOrkaWeb.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CD55ABFE-609D-45C8-9FBA-4199E6ECF5B3}: NameServer = 192.168.1.1 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: npkcmsvc - Unknown owner - C:\Nexon\Mabinogi\npkcmsvc.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 8261 bytes |
|
|
|
|
#10 |
|
Visiting Staff
Join Date: Sep 2007
Location: Ireland
Posts: 1,624
|
Your logs are clean
Follow these steps to uninstall Combofix and tools used in the removal of malware
Below I have included a number of recommendations for how to protect your computer against malware infections. * Keep Windows updated by regularly checking their website at : http://windowsupdate.microsoft.com/ This will ensure your computer has always the latest security updates available installed on your computer. * To reduce re-infection for malware in the future, I strongly recommend installing these free programs: SpywareBlaster protects against bad ActiveX IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all Have a look at this tutorial for IE-Spyad here * SpywareGuard offers realtime protection from spyware installation attempts. Make Internet Explorer more secure
* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future. * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place' Here
__________________
Who watches The Watchmen? It's like you said. All I am is what I'm going after. ~Scratch~ |
|
|
| Thread Tools | |
| Display Modes | |
|
|