Big_R
Full Member
  

Gender: 
Posts: 156
|
 |
Re: hijack this scan log
« Reply #9 on: May 28th, 2008, 4:55pm » |
Quote Modify
|
combo fix ComboFix 08-05-27.4 - HP_Administrator 2008-05-28 13:12:42.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.428 [GMT -7:00] Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM5c09fe4f.xml C:\WINDOWS\pskt.ini C:\WINDOWS\system32\bmhtooqw.ini C:\WINDOWS\system32\hOpXIkkj.ini C:\WINDOWS\system32\hOpXIkkj.ini2 C:\WINDOWS\system32\jkkIXpOh.dll C:\WINDOWS\system32\lyrapyds.dll C:\WINDOWS\system32\nabfkrdr.exe C:\WINDOWS\system32\pmvfssbo.dll C:\WINDOWS\system32\raoypgux.dll C:\WINDOWS\system32\sdyparyl.ini C:\WINDOWS\system32\wqoothmb.dll D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 ))))))))))))))))))))))))))))))) . 2008-05-28 13:23 . 2008-05-28 13:23372,736--a------C:\WINDOWS\system32\opnnkihh.dll 2008-05-28 13:23 . 2008-05-28 13:23345--ahs----C:\WINDOWS\system32\hhiknnpo.ini2 2008-05-28 13:23 . 2008-05-28 13:26345--ahs----C:\WINDOWS\system32\hhiknnpo.ini 2008-05-27 13:51 . 2008-05-27 13:5158,880--a------C:\WINDOWS\system32\awtsQJCt.dll 2008-05-11 05:28 . 2008-05-11 05:28268--ah-----C:\sqmdata01.sqm 2008-05-11 05:28 . 2008-05-11 05:28244--ah-----C:\sqmnoopt01.sqm 2008-05-11 05:25 . 2008-05-11 05:25268--ah-----C:\sqmdata00.sqm 2008-05-11 05:25 . 2008-05-11 05:25244--ah-----C:\sqmnoopt00.sqm 2008-05-07 21:18 . 2008-05-07 21:18<DIR>dr-h-----C:\Documents and Settings\HP_Administrator\Application Data\SecuROM 2008-05-07 21:18 . 2008-05-07 21:18108,144--a------C:\WINDOWS\system32\CmdLineExt.dll 2008-05-07 21:09 . 2008-05-07 21:09<DIR>d--------C:\Program Files\Atari . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-28 20:25512,032--sha-wC:\WINDOWS\system32\drivers\fidbox2.dat 2008-05-28 20:2539,983,136--sha-wC:\WINDOWS\system32\drivers\fidbox.dat 2008-05-28 20:24---------d-----wC:\Documents and Settings\HP_Administrator\Application Data\AdobeUM 2008-05-28 20:24---------d-----wC:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-05-28 20:21536,492--sha-wC:\WINDOWS\system32\drivers\fidbox.idx 2008-05-28 20:2148,980--sha-wC:\WINDOWS\system32\drivers\fidbox2.idx 2008-05-22 03:55---------d-----wC:\Documents and Settings\HP_Administrator\Application Data\Aim 2008-05-20 21:47---------d-----wC:\Program Files\Java 2008-05-19 16:15---------d-----wC:\Program Files\Winamp 2008-05-11 12:28---------d-----wC:\Program Files\Windows Live 2008-04-25 20:07---------d-----wC:\Program Files\Common Files\AOL 2008-04-20 05:16---------d-----wC:\Documents and Settings\HP_Administrator\Application Data\acccore 2008-04-20 05:15---------d-----wC:\Program Files\AIM6 2008-04-20 05:15---------d-----wC:\Documents and Settings\All Users\Application Data\Viewpoint 2008-04-20 05:15---------d-----wC:\Documents and Settings\All Users\Application Data\AOL 2008-04-20 05:14---------d-----wC:\Documents and Settings\All Users\Application Data\AOL Downloads 2008-04-17 22:51---------d-----wC:\Documents and Settings\HP_Administrator\Application Data\Vso 2008-04-17 20:24---------d-----wC:\Program Files\Replay Converter 2008-04-17 20:21737,280----a-wC:\WINDOWS\iun6002.exe 2008-04-17 20:21---------d-----wC:\Documents and Settings\HP_Administrator\Application Data\GetRightToGo 2008-04-10 04:21---------d-----wC:\Program Files\FlashFXP 2008-04-06 13:43---------d-----wC:\Program Files\HP 2008-04-01 06:51---------d-----wC:\Documents and Settings\All Users\Application Data\FlashFXP 2008-03-27 08:12151,583------wC:\WINDOWS\system32\msjint40.dll 2008-03-27 08:12151,583------wC:\WINDOWS\system32\dllcache\msjint40.dll 2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys 2008-03-19 09:471,845,248------wC:\WINDOWS\system32\dllcache\win32k.sys 2008-03-02 01:363,591,680----a-wC:\WINDOWS\system32\dllcache\mshtml.dll 2008-02-29 08:5570,656----a-wC:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-02-29 08:55625,664----a-wC:\WINDOWS\system32\dllcache\iexplore.exe 2007-12-29 02:170----a-wC:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat 2007-12-06 01:1287,608----a-wC:\Documents and Settings\HP_Administrator\Application Data\inst.exe 2007-12-06 01:1247,360----a-wC:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys 2007-03-09 07:1227,648--sha-wC:\WINDOWS\system32\AVSredirect.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{522E0112-EDD9-413D-A99E-C311A54B6676}] 2008-05-27 13:5158880--a------C:\WINDOWS\system32\awtsQJCt.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{729CD527-2990-4873-9ED3-F018BFAECE15}] 2008-05-28 13:23372736--a------C:\WINDOWS\system32\opnnkihh.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [ ] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 13:32 8699904] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 08:29 50736] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584] "ftutil2"="ftutil2.dll" [2004-06-07 07:05 106496 C:\WINDOWS\system32\ftutil2.dll] "RTHDCPL"="RTHDCPL.EXE" [2006-06-13 13:05 16239616 C:\WINDOWS\RTHDCPL.EXE] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 06:13 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 06:17 118784] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 09:59 143360] "DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 02:05 90112] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 15:14 237568] "PCDrProfiler"="" [] "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 15:34 249856] "Reminder"="C:\Windows\Creator\Remind_XP.exe" [2004-12-13 19:23 663552] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2002-09-12 10:13 1101824] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840] "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 11:49 36352] "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 13:51 218376] "BM5c09fe4f"="C:\WINDOWS\system32\poqbcduv.dll" [2008-05-28 13:27 126464] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 13:32 8699904] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-10-19 23:33:45 36903] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{522E0112-EDD9-413D-A99E-C311A54B6676}"= C:\WINDOWS\system32\awtsQJCt.dll [2008-05-27 13:51 58880] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsQJCt] awtsQJCt.dll 2008-05-27 13:51 58880 C:\WINDOWS\system32\awtsQJCt.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication PackagesREG_MULTI_SZ msv1_0 C:\WINDOWS\system32\opnnkihh [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\DISC\\DISCover.exe"= "C:\\Program Files\\DISC\\DiscStreamHub.exe"= "C:\\Program Files\\DISC\\myFTP.exe"= "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"= "C:\\Program Files\\AIM95\\aim.exe"= "C:\\Documents and Settings\\HP_Administrator\\Application Data\\SopCast\\adv\\SopAdver.exe"= "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= "C:\\Program Files\\FlashFXP\\FlashFXP.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 16:07] R2 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-09-13 05:35] R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 15:58] . ************************************************************************ ** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-28 13:24:22 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\awtsQJCt.dll PROCESS: C:\WINDOWS\explorer.exe -> C:\WINDOWS\system32\poqbcduv.dll -> C:\WINDOWS\system32\opnnkihh.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\ehome\ehrecvr.exe C:\WINDOWS\ehome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\ehome\ehmsas.exe C:\WINDOWS\system32\rundll32.exe C:\hp\KBD\kbd.exe . ************************************************************************ ** . Completion time: 2008-05-28 13:32:41 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-28 20:32:22 Pre-Run: 8,639,696,896 bytes free Post-Run: 11,458,510,848 bytes free 186--- E O F ---2008-05-16 10:01:42
|