really need your help please read this
what needs to be done to my comp or have I done it wright I have'nt seen combofix open up a box to tell me what needs to be re installed on my machine is there something that i have missed or is this ok.
thanks
hello all.
I ran combo fix on comp and this is what came out of it.
I tried to on line scan with kaspersky but 50% down load in 4hrs I'm on a very slow dial up connection 26.4kps (fun eh)
please tell me what i have to do next..
thanks Keith
ComboFix 08-03-09.1 - Keith 2008-03-10 22:12:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.54 [GMT -4:00]
Running from: C:\Documents and Settings\Keith\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM0777d63f.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ajmeytec.dll
C:\WINDOWS\system32\cetyemja.ini
C:\WINDOWS\system32\fccyvts.dll
C:\WINDOWS\system32\fjphtssr.dll
C:\WINDOWS\system32\gyxqfhmp.ini
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjjlm.ini2
C:\WINDOWS\system32\jkklmlk.dll
C:\WINDOWS\system32\mljjh.dll
C:\WINDOWS\system32\nayoneid.dll
C:\WINDOWS\system32\oamawajn.dll
C:\WINDOWS\system32\pmhfqxyg.dll
C:\WINDOWS\system32\sokbesdq.dll
C:\WINDOWS\system32\vomqspvl.dll
C:\WINDOWS\system32\xslgcpsc.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-11 to 2008-03-11 )))))))))))))))))))))))))))))))
.
2008-03-10 19:46 . 2008-03-10 19:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-10 19:46 . 2008-03-10 19:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-10 17:33 . 2008-03-10 18:40 153 --a------ C:\WINDOWS\wininit.ini
2008-03-09 12:55 . 2008-03-09 16:44 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-03-09 08:52 . 2008-03-09 08:53 51,355 --a------ C:\WINDOWS\system32\muzika.xm
2008-03-09 00:36 . 2008-03-09 20:22 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-08 09:37 . 2008-03-08 09:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-08 00:49 . 2008-03-08 21:59 895 ---hs---- C:\WINDOWS\system32\tccsrtur.ini
2008-03-07 23:40 . 2008-03-07 22:19 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-07 23:40 . 2008-03-07 23:40 2,546 --a------ C:\WINDOWS\unins000.dat
2008-03-07 20:31 . 2008-03-08 00:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-07 20:31 . 2008-03-08 00:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-07 17:46 . 2008-03-08 09:37 <DIR> d-------- C:\Documents and Settings\Keith\Application Data\Ahead
2008-03-07 17:41 . 2008-03-07 17:41 <DIR> d-------- C:\Program Files\Nero
2008-03-07 17:41 . 2008-03-07 17:43 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-07 17:41 . 2008-03-07 17:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-07 16:39 . 2008-03-07 16:39 <DIR> d-------- C:\WINDOWS\SpywarePro
2008-03-06 22:13 . 2008-03-08 00:44 775 ---hs---- C:\WINDOWS\system32\wthwngnf.ini
2008-03-05 10:35 . 1999-09-10 12:06 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-03-05 10:35 . 1999-09-10 12:06 25,244 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-03-05 10:35 . 1999-09-10 12:06 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-03-05 10:35 . 1999-09-10 12:06 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-03-05 09:41 . 2008-03-05 12:08 <DIR> d-------- C:\Program Files\RegCure
2008-02-26 21:46 . 2008-02-26 21:46 244 --ah----- C:\sqmnoopt04.sqm
2008-02-26 21:46 . 2008-02-26 21:46 232 --ah----- C:\sqmdata04.sqm
2008-02-19 21:03 . 2008-02-19 21:03 <DIR> d-------- C:\Documents and Settings\Brad & Hilary\Application Data\FaxCtr
2008-02-12 11:31 . 2008-02-12 11:31 268 --ah----- C:\sqmdata03.sqm
2008-02-12 11:31 . 2008-02-12 11:31 244 --ah----- C:\sqmnoopt03.sqm
2008-02-11 09:40 . 2008-02-11 09:40 2,715,648 --a------ C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 09:39 . 2008-02-11 09:39 253,952 --a------ C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 09:39 . 2008-02-11 09:39 237,568 --a------ C:\WINDOWS\system32\OnlineScannerDLLW.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 02:19 --------- d-----w C:\Program Files\lx_cats
2008-03-07 21:28 --------- d-----w C:\Program Files\Xilisoft
2008-03-07 21:24 --------- d-----w C:\Program Files\Ahead
2008-03-03 15:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-02-20 02:29 --------- d-----w C:\Program Files\XP Smoker
2008-02-18 20:43 --------- d-----w C:\Documents and Settings\Keith\Application Data\MSN6
2008-02-18 16:52 --------- d-----w C:\Program Files\Bezerk
2008-02-18 16:52 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-02-18 16:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-18 16:02 --------- d-----w C:\Documents and Settings\Keith\Application Data\RipIt4Me
2008-02-18 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-13 01:01 --------- d-----w C:\Documents and Settings\Keith\Application Data\Image Zone Express
2008-01-23 22:50 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-23 22:35 --------- d-----w C:\Documents and Settings\Keith\Application Data\AdobeUM
2008-01-20 19:39 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-13 22:47 --------- d-----w C:\Documents and Settings\Keith\Application Data\dvdcss
2008-01-11 00:09 --------- d-----w C:\Program Files\Hasbro
2007-08-26 22:36 87,608 ----a-w C:\Documents and Settings\Keith\Application Data\inst.exe
2007-08-26 22:36 47,360 ----a-w C:\Documents and Settings\Keith\Application Data\pcouffin.sys
2007-04-08 22:18 2,027,029 ----a-w C:\WINDOWS\inf\Rar.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0052fb94-5ea5-4255-a5f9-6125536b8e89}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74088EBA-1811-469E-B2A9-E86D5D10F79D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3ADDB7B-3DF5-4672-82DD-775FFF180134}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b6a9b545-402d-4ece-a16e-efad0a0c0bda}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6E28C7B-0F89-41AD-B984-B3AA2F7EF124}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2008-03-04 20:00 1465280]
"SpywareProMFC"="C:\Program Files\SpywarePro\SpywarePro.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 16:14 147456]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe" [2001-08-16 17:52 74832]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 09:47 57344]
"lxcrmon.exe"="C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" [2007-01-11 14:57 291760]
"EzPrint"="C:\Program Files\Lexmark 2400 Series\ezprint.exe" [2006-12-11 12:11 82864]
"LXCRCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-11-21 13:27 106496]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"0444e5a3"="C:\WINDOWS\system32\rutrscct.dll" [ ]
"BM0777d63f"="C:\WINDOWS\system32\oamawajn.dll" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkklmlk]
jkklmlk.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Dial-up Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dial-up Accelerator.lnk
backup=C:\WINDOWS\pss\Dial-up Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2006-01-12 20:52 483328 C:\Program Files\Adobe\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
--a------ 2006-12-11 12:12 295856 C:\Program Files\Lexmark Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 01:41 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 13:42 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-12-20 19:44 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\lxcrcoms.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-03-10 22:00:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-08 00:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca
"2008-03-07 21:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Common Files\Symantec Shared\NMAIN.EXEK /dat:C:\Program Files\Norton SystemWorks\swplugin.nsi /NSWCMD:OBCSchedule
"2008-03-11 02:18:44 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-06 19:31:46 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-11 02:27:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-10 22:18:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
.
**************************************************************************
.
Completion time: 2008-03-10 22:29:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-11 02:29:43
.
2007-06-29 10:07:59 --- E O F ---