I ran combofix and here is the log. can anyone please help me decipher this?
What should i do next. i had Winlogin.exe problem, a Command.exe problem, and webhdll.dll
What should i do?
LOG
--------------------------
Start Time= Sun 07/30/2006 13:28:30.24
Running from: C:\Documents and Settings\Ali\Desktop
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\logons
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\InprocServer32]
@="C:\\WINDOWS\\system32\\mcwsock.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\SYSTEM32\AOME.DLL
C:\WINDOWS\SYSTEM32\cansole.dll
C:\WINDOWS\SYSTEM32\dbsapi.dll
C:\WINDOWS\SYSTEM32\enrml1911.dll
C:\WINDOWS\SYSTEM32\j4l40e3qeh.dll
C:\WINDOWS\SYSTEM32\l20ulcd91f0.dll
C:\WINDOWS\SYSTEM32\mcwsock.dll
C:\WINDOWS\SYSTEM32\mebsync.dll
C:\WINDOWS\SYSTEM32\wphtcpip.dll
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
13:30:16.10
Not all files found by this method are bad. There may be legitimate files found
This log should be examined by a trained analyst
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-05-03 02:56:58 127,078 "C:\WINDOWS\system32\javaws.exe"
2006-05-03 01:19:40 53,346 "C:\WINDOWS\system32\javaw.exe"
2006-07-29 12:41:50 36,864 "C:\WINDOWS\system32\n9nyb.exe"
2006-07-29 12:42:58 48,167 "C:\WINDOWS\system32\VSL05.exe"
2006-07-29 12:44:04 234,272 "C:\WINDOWS\system32\dbsapi.dll"
2006-05-19 07:59:42 148,480 "C:\WINDOWS\system32\dnsapi.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-07-29 12:42:58 159,744 "C:\WINDOWS\system32\redist.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-07-29 12:39:44 14,848 "C:\WINDOWS\system32\BASSMOD.dll"
2006-07-29 17:06:20 235,508 "C:\WINDOWS\system32\cansole.dll"
2006-05-15 18:24:34 466,944 "C:\WINDOWS\system32\capicom.dll"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-07-30 05:04:30 235,508 "C:\WINDOWS\system32\mcwsock.dll"
2006-07-29 16:49:50 234,272 "C:\WINDOWS\system32\mebsync.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-06-22 05:47:18 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
* * * POST-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-05-03 02:56:58 127,078 "C:\WINDOWS\system32\javaws.exe"
2006-05-03 01:19:40 53,346 "C:\WINDOWS\system32\javaw.exe"
2006-07-29 12:41:50 36,864 "C:\WINDOWS\system32\n9nyb.exe"
2006-07-29 12:42:58 48,167 "C:\WINDOWS\system32\VSL05.exe"
2006-07-29 12:39:44 14,848 "C:\WINDOWS\system32\BASSMOD.dll"
2006-05-15 18:24:34 466,944 "C:\WINDOWS\system32\capicom.dll"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-06-22 05:47:18 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-05-19 07:59:42 148,480 "C:\WINDOWS\system32\dnsapi.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-07-29 12:42:58 159,744 "C:\WINDOWS\system32\redist.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\drsmartload.exe
C:\drsmartload45a7i.exe
C:\drsmartload46a7i.exe
C:\drsmartload849a7i.exe
C:\dfndrfg_7.exe
C:\nwnmfg_7.exe
C:\kybrdfg_7.exe
C:\Documents and Settings\Ali\Local Settings\Temp\drsmartload180a.exe
C:\WINDOWS\drsmartload2.dat
C:\MTE3NDI6ODoxNgnew.exe
C:\warebundlenewer.exe
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\WINDOWS\QWxp
What should i do next. i had Winlogin.exe problem, a Command.exe problem, and webhdll.dll
What should i do?
LOG
--------------------------
Start Time= Sun 07/30/2006 13:28:30.24
Running from: C:\Documents and Settings\Ali\Desktop
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\logons
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{182CDB68-9EB4-43EC-8320-BDAC433DD04C}\InprocServer32]
@="C:\\WINDOWS\\system32\\mcwsock.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\SYSTEM32\AOME.DLL
C:\WINDOWS\SYSTEM32\cansole.dll
C:\WINDOWS\SYSTEM32\dbsapi.dll
C:\WINDOWS\SYSTEM32\enrml1911.dll
C:\WINDOWS\SYSTEM32\j4l40e3qeh.dll
C:\WINDOWS\SYSTEM32\l20ulcd91f0.dll
C:\WINDOWS\SYSTEM32\mcwsock.dll
C:\WINDOWS\SYSTEM32\mebsync.dll
C:\WINDOWS\SYSTEM32\wphtcpip.dll
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
13:30:16.10
Not all files found by this method are bad. There may be legitimate files found
This log should be examined by a trained analyst
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-05-03 02:56:58 127,078 "C:\WINDOWS\system32\javaws.exe"
2006-05-03 01:19:40 53,346 "C:\WINDOWS\system32\javaw.exe"
2006-07-29 12:41:50 36,864 "C:\WINDOWS\system32\n9nyb.exe"
2006-07-29 12:42:58 48,167 "C:\WINDOWS\system32\VSL05.exe"
2006-07-29 12:44:04 234,272 "C:\WINDOWS\system32\dbsapi.dll"
2006-05-19 07:59:42 148,480 "C:\WINDOWS\system32\dnsapi.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-07-29 12:42:58 159,744 "C:\WINDOWS\system32\redist.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-07-29 12:39:44 14,848 "C:\WINDOWS\system32\BASSMOD.dll"
2006-07-29 17:06:20 235,508 "C:\WINDOWS\system32\cansole.dll"
2006-05-15 18:24:34 466,944 "C:\WINDOWS\system32\capicom.dll"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-07-30 05:04:30 235,508 "C:\WINDOWS\system32\mcwsock.dll"
2006-07-29 16:49:50 234,272 "C:\WINDOWS\system32\mebsync.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-06-22 05:47:18 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
* * * POST-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-05-03 02:56:58 127,078 "C:\WINDOWS\system32\javaws.exe"
2006-05-03 01:19:40 53,346 "C:\WINDOWS\system32\javaw.exe"
2006-07-29 12:41:50 36,864 "C:\WINDOWS\system32\n9nyb.exe"
2006-07-29 12:42:58 48,167 "C:\WINDOWS\system32\VSL05.exe"
2006-07-29 12:39:44 14,848 "C:\WINDOWS\system32\BASSMOD.dll"
2006-05-15 18:24:34 466,944 "C:\WINDOWS\system32\capicom.dll"
2006-05-10 00:25:20 151,040 "C:\WINDOWS\system32\cdfview.dll"
2006-05-10 00:25:22 357,888 "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 00:25:22 205,312 "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 00:25:22 251,904 "C:\WINDOWS\system32\iepeers.dll"
2006-06-01 13:47:08 163,840 "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 13:47:08 27,648 "C:\WINDOWS\system32\jgpl400.dll"
2006-05-18 00:24:26 450,560 "C:\WINDOWS\system32\jscript.dll"
2006-05-10 00:25:22 15,872 "C:\WINDOWS\system32\jsproxy.dll"
2006-05-10 00:25:22 39,424 "C:\WINDOWS\system32\pngfilt.dll"
2006-06-22 05:47:18 181,248 "C:\WINDOWS\system32\rasmans.dll"
2006-05-29 10:32:10 1,496,576 "C:\WINDOWS\system32\shdocvw.dll"
2006-05-10 00:25:22 474,112 "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 00:25:22 663,552 "C:\WINDOWS\system32\wininet.dll"
2006-05-19 07:59:42 148,480 "C:\WINDOWS\system32\dnsapi.dll"
2006-05-10 00:25:22 55,808 "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 00:25:22 96,256 "C:\WINDOWS\system32\inseng.dll"
2006-05-19 10:06:04 3,055,104 "C:\WINDOWS\system32\mshtml.dll"
2006-05-10 00:25:22 532,480 "C:\WINDOWS\system32\mstime.dll"
2006-07-29 12:42:58 159,744 "C:\WINDOWS\system32\redist.dll"
2006-05-10 00:25:22 615,424 "C:\WINDOWS\system32\urlmon.dll"
2006-05-10 00:25:20 1,054,208 "C:\WINDOWS\system32\danim.dll"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\drsmartload.exe
C:\drsmartload45a7i.exe
C:\drsmartload46a7i.exe
C:\drsmartload849a7i.exe
C:\dfndrfg_7.exe
C:\nwnmfg_7.exe
C:\kybrdfg_7.exe
C:\Documents and Settings\Ali\Local Settings\Temp\drsmartload180a.exe
C:\WINDOWS\drsmartload2.dat
C:\MTE3NDI6ODoxNgnew.exe
C:\warebundlenewer.exe
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\WINDOWS\QWxp