naanbread
Newbie


Posts: 14
|
 |
Re: winloginhook
« Reply #4 on: Feb 7th, 2008, 12:29pm » |
Quote Modify
|
combofix: ComboFix 08-02.05.3 - user 2008-02-07 17:55:48.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.570 [GMT 0:00] Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\jkkji.dll C:\WINDOWS\system32\ssqqnml.dll C:\Documents and Settings\user\Application Data\ShoppingReport C:\Documents and Settings\user\Application Data\ShoppingReport\cs\Config.xml C:\Documents and Settings\user\Application Data\ShoppingReport\cs\db\Aliases.dbs C:\Documents and Settings\user\Application Data\ShoppingReport\cs\db\Sites.dbs C:\Documents and Settings\user\Application Data\ShoppingReport\cs\dwld\WhiteList.xip C:\Documents and Settings\user\Application Data\ShoppingReport\cs\report\aggr_storage.xml C:\Documents and Settings\user\Application Data\ShoppingReport\cs\report\send_storage.xml C:\Documents and Settings\user\Application Data\ShoppingReport\cs\res1\WhiteList.dbs C:\Program Files\ShoppingReport C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll C:\Program Files\ShoppingReport\Uninst.exe C:\WINDOWS\system32\Cfx32.lic C:\WINDOWS\system32\cfx32.ocx C:\WINDOWS\system32\drivers\sfsync03.sys C:\WINDOWS\system32\drvgopr.dll C:\WINDOWS\system32\drvmajr.dll C:\WINDOWS\system32\drvpujr.dll C:\WINDOWS\system32\ieupdates.exe C:\WINDOWS\system32\ijkkj.ini C:\WINDOWS\system32\ijkkj.ini2 C:\WINDOWS\system32\jkkji.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\ntload.sys C:\WINDOWS\system32\oyaguulk.dll C:\WINDOWS\system32\ssqqnml.dll C:\WINDOWS\system32\update32.exe C:\WINDOWS\system32\vuhgdfvk.dll C:\WINDOWS\system32\winghy32.dll C:\WINDOWS\system32\winsrc.dll C:\WINDOWS\system32\winupdate.exe C:\WINDOWS\system32\wmrrwcby.dll C:\WINDOWS\system32\xpgfhxhl.dll C:\WINDOWS\system32\yvbedujp.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_NTLOAD -------\LEGACY_SFSYNC03 -------\ntload -------\sfsync03 ((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 ))))))))))))))))))))))))))))))) . 2008-02-07 17:51 . 2008-02-07 17:5111,776--a------C:\Program Files\tmp150718.exe 2008-02-07 17:50 . 2008-02-07 17:5010,240--a------C:\Program Files\tmp143265.exe 2008-02-07 16:57 . 2008-02-07 16:570--a------C:\WINDOWS\system32\wscmp.dll.tmp 2008-02-07 16:54 . 2008-02-07 16:54<DIR>d--------C:\Documents and Settings\user\Application Data\report 2008-02-07 16:54 . 2008-02-07 16:54<DIR>d--------C:\Documents and Settings\user\Application Data\Documents and Settings 2008-02-07 16:54 . 2008-02-07 16:5410,240--a------C:\Program Files\tmp145843.exe 2008-02-07 16:50 . 2008-02-07 16:501,355--a------C:\WINDOWS\imsins.BAK 2008-02-07 13:32 . 2008-02-07 14:26<DIR>d--------C:\hijackthis 2008-02-07 13:16 . 2008-02-07 13:16103,936--a------C:\WINDOWS\system32\drvpuj.dll 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\ShoppingReport 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\Documents and Settings\user\user 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\Documents and Settings\user\ShoppingReport 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\Documents and Settings\user\Documents and Settings 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\Documents and Settings\user\cs 2008-02-07 12:30 . 2008-02-07 12:30<DIR>d--------C:\Application Data 2008-02-07 12:25 . 2008-02-07 12:25<DIR>d--------C:\Documents and Settings\user\Application Data\user 2008-02-07 12:25 . 2008-02-07 12:2546,080--a------C:\Program Files\tmp156140.exe 2008-02-07 12:25 . 2008-02-07 12:2511,776--a------C:\Program Files\tmp156328.exe 2008-02-07 12:25 . 2008-02-07 12:2511,776--a------C:\Program Files\tmp154421.exe 2008-02-07 12:25 . 2008-02-07 12:2511,776--a------C:\Program Files\tmp152890.exe 2008-02-07 12:25 . 2008-02-07 12:2510,240--a------C:\Program Files\tmp147281.exe 2008-02-07 12:13 . 2008-02-07 12:134,298--a------C:\WINDOWS\system32\tmp.reg 2008-02-07 12:12 . 2007-09-05 23:22289,144--a------C:\WINDOWS\system32\VCCLSID.exe 2008-02-07 12:12 . 2006-04-27 16:49288,417--a------C:\WINDOWS\system32\SrchSTS.exe 2008-02-07 12:12 . 2008-02-06 00:0385,504--a------C:\WINDOWS\system32\VACFix.exe 2008-02-07 12:12 . 2008-01-27 14:3781,920--a------C:\WINDOWS\system32\IEDFix.exe 2008-02-07 12:12 . 2003-06-05 20:1353,248--a------C:\WINDOWS\system32\Process.exe 2008-02-07 12:12 . 2004-07-31 17:5051,200--a------C:\WINDOWS\system32\dumphive.exe 2008-02-07 12:12 . 2007-10-03 23:3625,600--a------C:\WINDOWS\system32\WS2Fix.exe 2008-02-07 09:48 . 2008-02-07 18:102,364--a------C:\WINDOWS\system32\wpa.dbl 2008-02-06 23:22 . 2008-02-06 23:220--a------C:\WINDOWS\system32\sex1.ico.tmp 2008-02-06 23:21 . 2008-02-06 23:210--a------C:\WINDOWS\system32\sex2.ico.tmp 2008-02-06 22:19 . 2008-02-06 22:19<DIR>d--------C:\user 2008-02-06 22:19 . 2008-02-06 22:19<DIR>d--------C:\Documents and Settings\user\Application Data\Application Data 2008-02-06 20:44 . 2008-02-06 20:4410,240--a------C:\Program Files\tmp17574484.exe 2008-02-06 20:43 . 2008-02-06 20:43103,936--a------C:\WINDOWS\system32\drvgop.dll 2008-02-06 20:43 . 2008-02-06 20:4310,240--a------C:\Program Files\tmp17527765.exe 2008-02-04 22:09 . 2008-02-04 22:22<DIR>d--------C:\Program Files\The All-Seeing Eye 2008-02-04 21:58 . 2008-02-04 21:5822,328--a------C:\Documents and Settings\user\Application Data\PnkBstrK.sys 2008-02-04 18:22 . 2006-12-08 12:02251,672--a------C:\WINDOWS\system32\xactengine2_5.dll 2008-02-04 18:22 . 2006-09-28 16:05237,848--a------C:\WINDOWS\system32\xactengine2_4.dll 2008-02-04 18:21 . 2008-02-04 18:21319--a------C:\WINDOWS\game.ini 2008-02-04 18:11 . 2008-02-04 18:11<DIR>d--------C:\Program Files\Activision 2008-02-04 15:29 . 2008-02-04 15:29103,936--a------C:\WINDOWS\system32\drvmaj.dll 2008-02-04 15:29 . 2008-02-04 15:2915,872--a------C:\WINDOWS\system32\drvkop.dll 2008-02-04 15:26 . 2008-02-04 15:26<DIR>d--hs----C:\WINDOWS\ftpcache 2008-02-01 22:01 . 2008-02-01 22:0115--a------C:\WINDOWS\system32\ioncprv.cna 2008-02-01 21:59 . 2008-02-01 22:18<DIR>d--------C:\My Media 2008-02-01 21:58 . 2008-02-01 22:01<DIR>d--------C:\Program Files\Audio Converter 2008-02-01 21:43 . 2008-02-01 21:43<DIR>d--------C:\Program Files\Audacity 2008-01-31 02:02 . 2008-01-31 02:0254,608--a------C:\WINDOWS\system32\xfcodec.dll 2008-01-25 17:16 . 2008-01-25 17:16<DIR>d--------C:\Program Files\CCleaner 2008-01-19 14:39 . 2008-01-19 14:39<DIR>d--------C:\Documents and Settings\All Users\Application Data\Last.fm 2008-01-19 14:38 . 2008-01-19 14:38<DIR>d--------C:\Program Files\Last.fm 2008-01-14 23:06 . 2008-01-14 23:06<DIR>d--------C:\Documents and Settings\user\dwhelper 2008-01-12 11:45 . 2008-01-12 11:45<DIR>d--------C:\Games 2008-01-09 16:08 . 2008-02-04 21:57<DIR>d--------C:\Documents and Settings\user\Application Data\Azureus 2008-01-09 16:08 . 2008-01-09 16:08<DIR>d--------C:\Documents and Settings\All Users\Application Data\Azureus 2008-01-09 16:06 . 2008-01-09 16:07<DIR>d--------C:\Program Files\Azureus . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-07 18:11---------d-----wC:\Program Files\Common Files\Symantec Shared 2008-02-07 12:46---------d-----wC:\Program Files\Opera 2008-02-06 15:52---------d-s---wC:\Program Files\Xfire 2008-02-05 22:1322,328----a-wC:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-02-05 22:09---------d-----wC:\Documents and Settings\user\Application Data\Xfire 2008-02-05 17:45---------d--h--wC:\Program Files\InstallShield Installation Information 2008-02-04 22:54---------d-----wC:\Program Files\Conquer 2.0 2008-02-01 21:5773,216----a-wC:\WINDOWS\ST6UNST.EXE 2008-02-01 21:57245,760------wC:\WINDOWS\Setup1.exe 2008-01-23 22:4244,568----a-wC:\Documents and Settings\user\Application Data\GDIPFONTCACHEV1.DAT 2008-01-16 18:31---------d-----wC:\Program Files\MSN Messenger 2008-01-16 18:31---------d-----wC:\Program Files\Messenger Plus! Live 2008-01-09 16:21---------d-----wC:\Documents and Settings\user\Application Data\uTorrent 2008-01-08 22:04---------d-----wC:\Program Files\QuickTime 2008-01-07 18:31---------d-----wC:\Program Files\DivX 2008-01-04 15:00---------d-----wC:\Program Files\Norton Security Scan 2007-12-25 21:14---------d-----wC:\Program Files\easetech 2007-12-22 16:25---------d-----wC:\Program Files\ImTOO 2006-06-23 06:4832,768----a-rC:\WINDOWS\inf\UpdateUSB.exe 2006-02-19 03:2812,288----a-wC:\WINDOWS\Fonts\RandFont.dll 2006-09-03 15:2132--sha-wC:\WINDOWS\{0B64A116-C1D7-4C50-AFB5-A1915648B8FB}.dat 2006-09-03 15:2332--sha-wC:\WINDOWS\{CD3E3353-BABA-473B-ABE5-86134DBC5573}.dat 2006-09-03 15:2132--sha-wC:\WINDOWS\system32\{478D9150-1401-44E8-82DC-6048D4411F8C} .dat 2006-09-03 15:2332--sha-wC:\WINDOWS\system32\{A84F0114-C7A2-431C-B8B5-0A9FFA5CC81C} .dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}] C:\Program Files\Outerinfo\Outerinfo.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 17:23 102400] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 12:00 15360] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-09-13 08:22 3054592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 10:07 843776] "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 08:19 729088] "JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 08:45 385024] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008] "nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01 32768] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-09-14 19:21 54976] "ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-09-14 19:22 38592] "Advanced Tools Check"="C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE" [2002-08-26 21:35 79480] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23 75520] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-18 22:23 185784] "YeppStudioAgent"="C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe" [2005-10-11 10:11 40960] "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 16:32 221184] "NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "BootSkin Startup Jobs"="C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 15:21 270336] "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ] "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 11:58 213936] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 12:00 15360] "Symantec NetDriver Warning"="C:\PROGRA~1\SYMNET~1\SNDWarn.exe" [2004-10-29 07:52 218232] C:\Documents and Settings\user\Start Menu\Programs\Startup\ Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-01-01 16:01:28 110592] Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-01-19 14:38:27 106496] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-01-01 16:01:28 110592] Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe [2006-09-01 18:40:07 589824] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "ServiceCheck"= {d6582a8a-fca3-408e-baee-a375276e58af} - C:\WINDOWS\Installer\{d6582a8a-fca3-408e-baee-a375276e58af}\ServiceCheck .dll [2008-02-06 20:43 14374] "zip"= {25a7492e-2069-4cde-96b8-03e88fe7017f} - C:\WINDOWS\Installer\{25a7492e-2069-4cde-96b8-03e88fe7017f}\zip.dll [2008-02-07 12:25 39462] "ServiceSetup"= {c450cddb-4f73-466b-b106-140684e84824} - C:\WINDOWS\Installer\{c450cddb-4f73-466b-b106-140684e84824}\ServiceSetup .dll [2008-02-07 13:16 14374] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient] C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll 2005-01-31 14:13 49152 C:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv] C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 15:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=wbsys.dll R3 NPDriver;Norton Unerase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2002-08-14 05:03] S3 jnv4_mib;jnv4_mib;C:\DOCUME~1\user\LOCALS~1\Temp\jnv4_mib.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - H:\Autorun.exe . Contents of the 'Scheduled Tasks' folder "2008-02-01 17:52:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-01-04 15:00:12 C:\WINDOWS\Tasks\Norton Security Scan.job" - C:\Program Files\Norton Security Scan\Nss.exe "2008-02-07 18:10:29 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************ ** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-07 18:11:08 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\WINDOWS\Installer\{d6582a8a-fca3-408e-baee-a375276e58af}\ServiceCheck .dll -> C:\WINDOWS\Installer\{c450cddb-4f73-466b-b106-140684e84824}\ServiceSetup .dll . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Personal Firewall\NISUM.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe C:\Program Files\Norton Personal Firewall\ccPxySvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\system32\imapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\cscript.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\taskmgr.exe . ************************************************************************ ** . Completion time: 2008-02-07 18:23:00 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-07 18:22:57 . 2008-01-25 17:29:00--- E O F ---
|