INEEDMAJORHELP
Newbie


Posts: 11
|
 |
Re: I'm another winlogonhook victim please help me
« Reply #7 on: Jan 6th, 2008, 12:15pm » |
Quote Modify
|
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-06 17:49---------d-----wC:\Program Files\iTunes 2008-01-06 17:48---------d-----wC:\Program Files\SymNetDrv 2008-01-06 17:48---------d-----wC:\Program Files\Common Files\Symantec Shared 2008-01-06 17:48---------d-----wC:\Program Files\Apoint 2008-01-06 17:47---------d-----wC:\Program Files\RegistryBooster 2 2008-01-06 17:47---------d-----wC:\Program Files\MSN Messenger 2008-01-06 17:47---------d-----wC:\Program Files\AIM6 2008-01-06 05:27---------d-----wC:\Program Files\QuickTime 2008-01-04 03:31---------d-----wC:\Documents and Settings\Owner\Application Data\uTorrent 2008-01-03 23:45---------d-----wC:\Program Files\Common Files\Adobe 2007-12-29 05:34---------d-----wC:\Program Files\XBC 2007-12-27 07:42---------d-----wC:\Program Files\XLink Kai Evolution VII 2007-12-18 22:06---------d--h--wC:\Program Files\InstallShield Installation Information 2007-12-18 22:06---------d-----wC:\Program Files\Hewlett-Packard 2007-12-15 11:06---------d-----wC:\Program Files\BitComet 2007-12-14 20:18---------d-----wC:\Program Files\Sony 2007-12-07 20:12108,144----a-wC:\WINDOWS\system32\CmdLineExt.dll 2007-12-07 11:59---------d-----wC:\Program Files\CAPCOM 2007-12-01 04:16---------d-----wC:\Program Files\Handbrake 2007-12-01 03:45---------d-----wC:\Program Files\Common Files\DirectX 2007-12-01 03:37225,280----a-wC:\WINDOWS\system32\UAService7.exe 2007-11-29 22:05---------d-----wC:\Documents and Settings\Owner\Application Data\Pegasys Inc 2007-11-29 03:3056,976----a-wC:\WINDOWS\system32\GenSvcInst.exe 2007-11-29 03:3033,408----a-wC:\WINDOWS\system32\drivers\CDRBSDRV.SYS 2007-11-29 03:30122,512----a-wC:\WINDOWS\system32\bgsvcgen.exe 2007-11-29 02:28---------d-----wC:\Documents and Settings\All Users\Application Data\DVD Shrink 2007-11-29 02:21---------d-----wC:\Program Files\PIXELA 2007-11-29 02:16---------d-----wC:\Program Files\Sony Corporation 2007-11-29 02:16---------d-----wC:\Program Files\Common Files\muvee Technologies 2007-11-27 23:52---------d-----wC:\Program Files\Java 2007-11-27 02:38---------d-----wC:\Documents and Settings\Owner\Application Data\dvdcss 2007-11-27 00:22359,808----a-wC:\WINDOWS\system32\drivers\tcpip.sys 2007-11-22 16:37---------d-----wC:\Program Files\iPod 2007-11-18 16:24---------d-----wC:\Program Files\Common Files\Stardock 2007-11-18 09:14---------d-----wC:\Program Files\Stardock 2007-11-18 08:26---------d-----wC:\Program Files\YzShadow 2007-11-17 20:1892,160----a-wC:\WINDOWS\system32\cabview.dll 2007-11-17 20:1883,456----a-wC:\WINDOWS\system32\charmap.exe 2007-11-17 20:1880,896----a-wC:\WINDOWS\system32\mydocs.dll 2007-11-17 20:1880,896----a-wC:\WINDOWS\system32\dfrgres.dll 2007-11-17 20:1880,216----a-wC:\WINDOWS\system32\wuauclt.exe 2007-11-17 20:188,192----a-wC:\WINDOWS\system32\wpabaln.exe 2007-11-17 20:1878,848----a-wC:\WINDOWS\system32\rtcshare.exe 2007-11-17 20:18750,080----a-wC:\WINDOWS\system32\wiashext.dll 2007-11-17 20:1875,776----a-wC:\WINDOWS\system32\magnify.exe 2007-11-17 20:18734,208----a-wC:\WINDOWS\system32\mstsc.exe 2007-11-17 20:1872,704----a-wC:\WINDOWS\system32\winchat.exe 2007-11-17 20:1870,656----a-wC:\WINDOWS\notepad.exe 2007-11-17 20:1867,584----a-wC:\WINDOWS\system32\batmeter.dll 2007-11-17 20:18587,776----a-wC:\WINDOWS\system32\shimgvw.dll 2007-11-17 20:1857,344----a-wC:\WINDOWS\system32\narrator.exe 2007-11-17 20:1855,296----a-wC:\WINDOWS\system32\migpwd.exe 2007-11-17 20:1853,248----a-wC:\WINDOWS\system32\utilman.exe 2007-11-17 20:1852,224----a-wC:\WINDOWS\system32\syncapp.exe 2007-11-17 20:18492,032----a-wC:\WINDOWS\system32\wiaacmgr.exe 2007-11-17 20:18473,600----a-wC:\WINDOWS\system32\zipfldr.dll 2007-11-17 20:1845,056----a-wC:\WINDOWS\system32\rcimlby.exe 2007-11-17 20:18441,856----a-wC:\WINDOWS\system32\sol.exe 2007-11-17 20:18440,320----a-wC:\WINDOWS\system32\freecell.exe 2007-11-17 20:18402,944----a-wC:\WINDOWS\system32\fontext.dll 2007-11-17 20:184,408,320----a-wC:\WINDOWS\system32\xpsp2res.dll 2007-11-17 20:18391,680----a-wC:\WINDOWS\system32\cmd.exe 2007-11-17 20:18360,960----a-wC:\WINDOWS\system32\mspaint.exe 2007-11-17 20:18331,776----a-wC:\WINDOWS\system32\mstask.dll 2007-11-17 20:1832,256----a-wC:\WINDOWS\system32\wupdmgr.exe 2007-11-17 20:18292,864----a-wC:\WINDOWS\system32\osk.exe 2007-11-17 20:18260,096----a-wC:\WINDOWS\system32\sndrec32.exe 2007-11-17 20:18224,256----a-wC:\WINDOWS\regedit.exe 2007-11-17 20:18218,624----a-wC:\WINDOWS\system32\syncui.dll 2007-11-17 20:18200,192----a-wC:\WINDOWS\system32\moricons.dll 2007-11-17 20:182,263,040----a-wC:\WINDOWS\system32\netshell.dll 2007-11-17 20:18194,048----a-wC:\WINDOWS\system32\photowiz.dll 2007-11-17 20:18186,368----a-wC:\WINDOWS\system32\accwiz.exe 2007-11-17 20:18168,960----a-wC:\WINDOWS\system32\mobsync.exe 2007-11-17 20:18158,720----a-wC:\WINDOWS\system32\sndvol32.exe 2007-11-17 20:18151,552----a-wC:\WINDOWS\system32\wscript.exe 2007-11-17 20:18139,264----a-wC:\WINDOWS\system32\stobject.dll 2007-11-17 20:18131,072----a-wC:\WINDOWS\system32\mycomput.dll 2007-11-17 20:18130,560----a-wC:\WINDOWS\system32\mshearts.exe 2007-11-17 20:18128,512----a-wC:\WINDOWS\system32\msiexec.exe 2007-11-17 20:18122,880----a-wC:\WINDOWS\system32\winmine.exe 2007-11-17 20:18117,760----a-wC:\WINDOWS\system32\calc.exe 2007-11-17 20:18100,864----a-wC:\WINDOWS\system32\ahui.exe 2007-11-17 20:181,978,880----a-wC:\WINDOWS\system32\spider.exe 2007-11-17 20:181,656,832----a-wC:\WINDOWS\explorer.exe 2007-11-17 20:181,477,120----a-wC:\WINDOWS\system32\msgina.dll 2007-11-17 20:181,404,416----a-wC:\WINDOWS\system32\cards.dll 2007-11-17 20:181,108,480----a-wC:\WINDOWS\system32\setupapi.dll 2007-11-17 20:17840,192----a-wC:\WINDOWS\system32\rasdlg.dll 2007-11-17 20:1780,896----a-wC:\WINDOWS\system32\icmui.dll 2007-11-17 20:17744,448----a-wC:\WINDOWS\system32\comctl32.dll 2007-11-17 20:1759,392----a-wC:\WINDOWS\system32\sendmail.dll 2007-11-17 20:17500,224----a-wC:\WINDOWS\system32\cmdial32.dll 2007-11-17 20:17488,280----a-wC:\WINDOWS\system32\wuapi.dll 2007-11-17 20:17390,144----a-wC:\WINDOWS\system32\themeui.dll 2007-11-17 20:17347,136----a-wC:\WINDOWS\system32\tourstart.exe 2007-11-17 20:1732,768----a-wC:\WINDOWS\hh.exe 2007-11-17 20:1731,744----a-wC:\WINDOWS\system32\stimon.exe 2007-11-17 20:17218,624----a-wC:\WINDOWS\system32\taskmgr.exe 2007-11-17 20:17189,952----a-wC:\WINDOWS\system32\credui.dll 2004-08-04 12:0094,784--sh--wC:\WINDOWS\twain.dll 2004-08-04 12:0050,688--sh--wC:\WINDOWS\twain_32.dll 2004-08-20 03:261,216--sh--wC:\WINDOWS\Twunk_16.dll 2004-08-20 03:261,216--sh--wC:\WINDOWS\Twunk_32.dll 2004-08-04 12:001,028,096--sha-wC:\WINDOWS\system32\mfc42.dll 2004-08-04 12:0054,784--sha-wC:\WINDOWS\system32\msvcirt.dll 2004-08-04 12:00413,696--sha-wC:\WINDOWS\system32\msvcp60.dll 2004-08-04 12:00343,040--sha-wC:\WINDOWS\system32\msvcrt.dll 2007-05-17 11:28549,376--sha-wC:\WINDOWS\system32\oleaut32.dll 2004-08-04 12:0083,456--sha-wC:\WINDOWS\system32\olepro32.dll 2004-08-04 12:0011,776--sha-wC:\WINDOWS\system32\regsvr32.exe . Code:<pre> ----a-w 2,241,024 2008-01-06 17:47:20 C:\Program Files\RegistryBooster 2\RegistryBooster .exe ----a-w 29,824 2008-01-05 04:03:21 C:\WINDOWS\system32\ctfmona .exe </pre> |
| ((((((((((((((((((((((((((((( snapshot@2008-01-06_ 0.41.30.65 ))))))))))))))))))))))))))))))))))))))))) . + 2008-01-06 17:45:3916,384----atwC:\WINDOWS\Temp\Perflib_Perfdata_32c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48284F34-F1E8-4439-8512-B18CB54CD4D0}] 2008-01-06 12:47328192---------C:\WINDOWS\system32\vtstr.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\Ahead\data\Xtras\MS28C2~1.EXE" [ ] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "Uniblue RegistryBooster 2"="C:\Program Files\RegistryBooster 2\RegistryBooster .exe" [2008-01-06 12:47 2241024] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-06 12:47 407552] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-06 12:47 630784] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2008-01-06 12:47 6037504] "Steam"="C:\Program Files\Valve\Steam\\Steam.exe" [2008-01-06 12:48 1611776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Hcontrol"="C:\WINDOWS\ATK0100\Hcontrol.exe" [2008-01-06 12:48 396800] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2008-01-06 12:48 456192] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-01-06 12:48 742400] "CreateCD_Reminder"="C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe" [2008-01-06 12:48 396288] "VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2008-01-06 12:48 362496] "TVTunerLib"="C:\Program Files\Common Files\Sony Shared\TVTunerLib\TVTLInstTool.exe" [2008-01-06 12:48 600576] "SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2008-01-06 12:48 627712] "ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2008-01-06 12:48 365568] "VZRemoteCommander"="C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe" [2008-01-06 12:48 570880] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-06 12:48 396800] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-01-06 12:48 437760] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-06 12:49 468480] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-01-06 12:49 382976] "Logitech Utility"="Logi_MwX.Exe" [2003-12-17 04:50 19968 C:\WINDOWS\LOGI_MWX.EXE] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-01-06 12:49 488448] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-06 12:49 513024] "VAIO Update 3"="C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" [2008-01-06 12:49 1252352] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-06 12:49 372736] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2008-01-06 12:49 425472] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-06 12:49 690176] "Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2008-01-06 12:49 390144] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "VMConsole.exe"="C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" [2008-01-06 12:49 732672] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-26 18:31:21] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04] Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 20:23:32] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="C:\\WINDOWS\\system32\\logonui.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] VESWinlogon.dll 2005-01-18 15:48 73728 C:\WINDOWS\system32\VESWinlogon.dll [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows] "load"=C:\WINDOWS\system32\vtstr.exe [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication PackagesREG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtstr [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, R0 sonypvl3;sonypvl3;C:\WINDOWS\system32\drivers\sonypvl3.sys [2004-09-22 11:55] R0 SSI;SSI;C:\WINDOWS\system32\Drivers\SSI.SYS [2006-01-25 10:54] R1 sonypvf3;sonypvf3;C:\WINDOWS\system32\drivers\sonypvf3.sys [2004-11-15 13:55] R1 sonypvt3;sonypvt3;C:\WINDOWS\system32\drivers\sonypvt3.sys [2004-12-06 14:26] R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 20:26] R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2003-06-18 19:12] S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;C:\WINDOWS\system32\DRIVERS\fa410nd5.sys [2001-08-17 07:12] S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-02-15 00:30] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 20:23] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\AutoRun\command - F:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder "2007-12-13 14:33:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-12-22 04:01:20 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Owner.job" - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task: . ************************************************************************ ** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-06 12:49:47 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\system32\rtstv.ini 391 bytes C:\WINDOWS\system32\rtstv.ini2 391 bytes scan completed successfully hidden files: 2 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\WINDOWS\system32\vtstr.dll . Completion time: 2008-01-06 12:55:09 - machine was rebooted [Owner] ComboFix-quarantined-files.txt 2008-01-06 17:54:59 . 2007-12-18 08:09:52--- E O F ---
|