electricsqueak
New member
Logs part 1
Ok, here is the scan log:
"William O'Malley" - 2007-07-07 11:14:50 - ComboFix 07-07-04.4 - Service Pack 2
Command switches used :: C:\Documents and Settings\William O'Malley\Desktop\CFScript.txt
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\7246560CB8.sys
C:\WINDOWS\system32\aaafdbdccedd.dll
C:\WINDOWS\system32\bqncydxs.ini2
C:\WINDOWS\system32\hjkkj.bak2
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\sfsync02.dll
C:\WINDOWS\system32\vnibhijf.ini2
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-05 11:00 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-05 10:34 90,112 --a------ C:\WINDOWS\system32\regdacl.exe
2007-07-05 10:34 53,248 --a------ C:\WINDOWS\system32\process.exe
2007-07-05 10:34 4,096 --a------ C:\WINDOWS\system32\reboot.exe
2007-07-05 10:34 280,022 --a------ C:\win32delfkil.exe
2007-07-05 10:34 16,384 --a------ C:\WINDOWS\system32\restart.exe
2007-07-05 10:34 <DIR> d-------- C:\WINDOWS\system32\regdacl
2007-07-05 10:34 <DIR> d-------- C:\_backupD
2007-06-27 16:01 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-26 21:24 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-06-11 23:21 <DIR> d-------- C:\VundoFix Backups
2007-06-08 10:52 <DIR> d-------- C:\HJT
2007-06-07 12:12 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-06-07 12:12 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-06-07 12:12 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-06-07 12:12 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-06-07 12:12 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-06-07 12:12 <DIR> d-------- C:\Program Files\Spyware Doctor
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-03 21:04:39 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-28 23:32:34 -------- d-----w C:\Program Files\World of Warcraft
2007-06-27 17:42:19 -------- d-----w C:\Program Files\CyberScrub Professional
2007-06-09 09:44:48 -------- d-----w C:\Program Files\LimeWire
2007-06-09 09:08:51 -------- d-----w C:\Program Files\Triga Instant
2007-06-09 09:07:10 -------- d-----w C:\Program Files\Yahoo!
2007-06-09 09:07:09 -------- d-----w C:\Program Files\WinUAE
2007-06-09 09:07:09 -------- d-----w C:\Program Files\WinAce
2007-06-09 09:06:42 -------- d-----w C:\Program Files\QuickTime
2007-06-09 09:06:42 -------- d-----w C:\Program Files\OfficeUpdate11
2007-06-09 09:06:09 -------- d-----w C:\Program Files\DOSBox-0.63
2007-06-09 09:06:09 -------- d-----w C:\Program Files\DivX
2007-06-01 11:09:47 -------- d-----w C:\Program Files\Napster
2007-05-18 13:55:20 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-11 00:28:13 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 21:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 21:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2006-06-16 14:21:40 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
2006-09-06 06:18 93400 -ra------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2006-12-18 05:18 231160 --a------ C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-08-30 12:48 C:\WINDOWS\SOUNDMAN.EXE]
"Norton PasswordManager"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-09-09 11:30]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-06 02:22]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"AcctMgr"="C:\Program Files\Norton Password Manager\AcctMgr.exe" [2004-08-18 12:41]
"@"="" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-06-07 13:16]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"Sonic RecordNow! Deluxe"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NapsterShell"=C:\Program Files\Napster\napster.exe /systray
"nwiz"=nwiz.exe /install
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-07 08:53:14 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-06 19:00:02 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - William O'Malley.job
2007-07-06 16:30:02 C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
2007-07-05 23:00:01 C:\WINDOWS\tasks\Symantec Drmc.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 11:27:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 11:31:05
C:\ComboFix-quarantined-files.txt ... 2007-07-07 11:31
C:\ComboFix2.txt ... 2007-07-05 11:21
--- E O F ---
continues...
Ok, here is the scan log:
"William O'Malley" - 2007-07-07 11:14:50 - ComboFix 07-07-04.4 - Service Pack 2
Command switches used :: C:\Documents and Settings\William O'Malley\Desktop\CFScript.txt
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\7246560CB8.sys
C:\WINDOWS\system32\aaafdbdccedd.dll
C:\WINDOWS\system32\bqncydxs.ini2
C:\WINDOWS\system32\hjkkj.bak2
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\sfsync02.dll
C:\WINDOWS\system32\vnibhijf.ini2
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-05 11:00 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-05 10:34 90,112 --a------ C:\WINDOWS\system32\regdacl.exe
2007-07-05 10:34 53,248 --a------ C:\WINDOWS\system32\process.exe
2007-07-05 10:34 4,096 --a------ C:\WINDOWS\system32\reboot.exe
2007-07-05 10:34 280,022 --a------ C:\win32delfkil.exe
2007-07-05 10:34 16,384 --a------ C:\WINDOWS\system32\restart.exe
2007-07-05 10:34 <DIR> d-------- C:\WINDOWS\system32\regdacl
2007-07-05 10:34 <DIR> d-------- C:\_backupD
2007-06-27 16:01 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-26 21:24 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-06-11 23:21 <DIR> d-------- C:\VundoFix Backups
2007-06-08 10:52 <DIR> d-------- C:\HJT
2007-06-07 12:12 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-06-07 12:12 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-06-07 12:12 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-06-07 12:12 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-06-07 12:12 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-06-07 12:12 <DIR> d-------- C:\Program Files\Spyware Doctor
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-03 21:04:39 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-28 23:32:34 -------- d-----w C:\Program Files\World of Warcraft
2007-06-27 17:42:19 -------- d-----w C:\Program Files\CyberScrub Professional
2007-06-09 09:44:48 -------- d-----w C:\Program Files\LimeWire
2007-06-09 09:08:51 -------- d-----w C:\Program Files\Triga Instant
2007-06-09 09:07:10 -------- d-----w C:\Program Files\Yahoo!
2007-06-09 09:07:09 -------- d-----w C:\Program Files\WinUAE
2007-06-09 09:07:09 -------- d-----w C:\Program Files\WinAce
2007-06-09 09:06:42 -------- d-----w C:\Program Files\QuickTime
2007-06-09 09:06:42 -------- d-----w C:\Program Files\OfficeUpdate11
2007-06-09 09:06:09 -------- d-----w C:\Program Files\DOSBox-0.63
2007-06-09 09:06:09 -------- d-----w C:\Program Files\DivX
2007-06-01 11:09:47 -------- d-----w C:\Program Files\Napster
2007-05-18 13:55:20 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-11 00:28:13 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 21:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 21:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2006-06-16 14:21:40 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
2006-09-06 06:18 93400 -ra------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2006-12-18 05:18 231160 --a------ C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-08-30 12:48 C:\WINDOWS\SOUNDMAN.EXE]
"Norton PasswordManager"="C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" [2003-09-09 11:30]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-06 02:22]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"AcctMgr"="C:\Program Files\Norton Password Manager\AcctMgr.exe" [2004-08-18 12:41]
"@"="" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-06-07 13:16]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"Sonic RecordNow! Deluxe"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wudb]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NapsterShell"=C:\Program Files\Napster\napster.exe /systray
"nwiz"=nwiz.exe /install
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-07 08:53:14 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-06 19:00:02 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - William O'Malley.job
2007-07-06 16:30:02 C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
2007-07-05 23:00:01 C:\WINDOWS\tasks\Symantec Drmc.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 11:27:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 11:31:05
C:\ComboFix-quarantined-files.txt ... 2007-07-07 11:31
C:\ComboFix2.txt ... 2007-07-05 11:21
--- E O F ---
continues...