Thomas
Full Member
  

Gender: 
Posts: 233
|
 |
Re: help please
« Reply #12 on: Nov 8th, 2008, 10:56am » |
Quote Modify
|
here is my combofix log for my pc ComboFix 08-11-07.01 - Compaq_Owner 2008-11-08 11:22:58.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.51 [GMT -5:00] Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\brreukis.ini c:\windows\system32\dfeKlnpo.ini c:\windows\system32\dfeKlnpo.ini2 c:\windows\system32\efcBTLfE.dll c:\windows\system32\EfLTBcfe.ini c:\windows\system32\EfLTBcfe.ini2 c:\windows\system32\eyqrolgk.dll c:\windows\system32\gmoypd.dll c:\windows\system32\jclhwvrc.dll c:\windows\system32\jxnutq.dll c:\windows\system32\kglorqye.ini c:\windows\system32\mtcunz.dll c:\windows\system32\pmnnmkLe.dll c:\windows\system32\sikuerrb.dll c:\windows\system32\srglvlfq.ini c:\windows\system32\ssqPjgFu.dll c:\windows\system32\tacgitof.dll c:\windows\system32\tlchcrvf.dll c:\windows\system32\tuvUKCTN.dll . ((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 ))))))))))))))))))))))))))))))) . 2008-11-02 20:21 . 2008-11-02 20:24273--ah-----c:\windows\sysdata.dat 2008-11-02 20:17 . 2008-11-02 20:20289--ah-----c:\windows\winshell.dat 2008-11-02 20:14 . 2008-11-02 20:17315--ah-----c:\windows\wininf.dat 2008-11-02 20:10 . 2008-11-02 20:13268--ah-----c:\windows\sysreg.dat 2008-11-01 09:49 . 2008-11-01 09:49<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\DivX 2008-11-01 09:18 . 2008-11-01 09:41<DIR>d--------c:\program files\DivX 2008-11-01 09:17 . 2008-11-01 09:17<DIR>d--------c:\program files\AC3Filter 2008-11-01 09:17 . 2008-07-09 03:05421,888--a------c:\windows\system32\ac3filter.acm 2008-10-30 20:20 . 2008-10-30 20:20<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Windows Search 2008-10-24 23:38 . 2008-10-24 23:38<DIR>d--------c:\windows\Sun 2008-10-24 07:01 . 2008-10-24 07:01<DIR>d--------c:\program files\Common Files\Adobe Systems Shared 2008-10-23 22:20 . 2008-10-15 11:34337,408--a------c:\windows\system32\dllcache\netapi32.dll 2008-10-23 22:16 . 2007-07-30 18:19271,224--a------c:\windows\system32\mucltui.dll 2008-10-23 22:16 . 2007-07-30 18:1930,072--a------c:\windows\system32\mucltui.dll.mui 2008-10-23 06:42 . 2008-10-23 06:42<DIR>d--------c:\program files\Yahoo! 2008-10-23 06:42 . 2008-10-23 06:44<DIR>d--------c:\documents and settings\All Users\Application Data\Yahoo! 2008-10-23 06:41 . 2008-10-23 06:41<DIR>d--------c:\program files\Trend Micro 2008-10-23 06:15 . 2008-10-23 06:15<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Digital Asphyxia 2008-10-23 06:15 . 2008-10-23 06:15<DIR>d--------c:\documents and settings\All Users\Application Data\Digital Asphyxia 2008-10-23 06:14 . 2008-10-23 06:14<DIR>d--------c:\program files\Digital Asphyxia 2008-10-23 06:14 . 2008-10-23 06:14<DIR>d--------c:\documents and settings\All Users\Application Data\Tarma Installer 2008-10-23 06:10 . 2008-10-23 06:10<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\TrojanHunter 2008-10-23 06:09 . 2008-10-23 06:10<DIR>d--------c:\program files\TrojanHunter 5.0 2008-10-23 05:39 . 2008-10-23 05:39<DIR>d--------c:\windows\system32\scripting 2008-10-23 05:39 . 2008-10-23 05:39<DIR>d--------c:\windows\system32\en 2008-10-23 05:39 . 2008-10-23 05:39<DIR>d--------c:\windows\system32\bits 2008-10-23 05:39 . 2008-10-23 05:39<DIR>d--------c:\windows\l2schemas 2008-10-23 05:36 . 2008-10-23 05:39<DIR>d--------c:\windows\ServicePackFiles 2008-10-23 05:28 . 2008-10-23 05:28<DIR>d--------c:\windows\EHome 2008-10-23 03:16 . 2008-10-23 03:16<DIR>d--------c:\program files\Microsoft Silverlight 2008-10-23 03:16 . 2008-10-23 03:16<DIR>d--------c:\program files\Microsoft CAPICOM 2.1.0.2 2008-10-23 03:01 . 2008-10-23 03:01<DIR>d--------c:\program files\MSXML 6.0 2008-10-23 02:54 . 2008-10-23 02:54<DIR>d--------c:\program files\MSBuild 2008-10-23 02:52 . 2008-10-23 03:02<DIR>d--------c:\windows\system32\XPSViewer 2008-10-23 02:51 . 2008-10-23 02:51<DIR>d--------c:\program files\Reference Assemblies 2008-10-23 02:50 . 2006-06-29 12:0714,048--a------c:\windows\system32\spmsg2.dll 2008-10-23 02:49 . 2008-10-23 02:49<DIR>d--------C:\4486b72b3237250b4026cbb32d 2008-10-23 02:31 . 2008-10-23 02:31<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Windows Desktop Search 2008-10-23 02:30 . 2008-10-23 02:30<DIR>d--------c:\windows\system32\GroupPolicy 2008-10-23 02:30 . 2008-10-23 02:30<DIR>d--------c:\program files\Windows Desktop Search 2008-10-23 02:28 . 2008-10-23 02:28<DIR>d--------c:\program files\Windows Media Connect 2 2008-10-23 02:25 . 2008-10-23 02:25<DIR>d--------c:\windows\system32\LogFiles 2008-10-23 02:25 . 2008-10-23 02:27<DIR>d--------c:\windows\system32\drivers\UMDF 2008-10-23 02:14 . 2008-04-13 19:12290,304--a------c:\windows\system32\rhttpaa.dll 2008-10-23 02:14 . 2008-04-13 19:11136,192--a------c:\windows\system32\aaclient.dll 2008-10-23 02:14 . 2008-04-13 19:1253,248--a------c:\windows\system32\tsgqec.dll 2008-10-23 02:02 . 2008-04-13 19:124,274,816--a------c:\windows\system32\nv4_disp.dll 2008-10-23 02:01 . 2008-04-13 19:11870,784--a------c:\windows\system32\ati3d1ag.dll 2008-10-23 01:32 . 2008-10-03 12:416,066,176--a------c:\windows\system32\dllcache\ieframe.dll 2008-10-23 01:32 . 2007-04-17 04:322,455,488--a------c:\windows\system32\dllcache\ieapfltr.dat 2008-10-23 01:32 . 2007-03-08 00:10991,232--a------c:\windows\system32\dllcache\ieframe.dll.mui 2008-10-23 01:32 . 2008-08-26 02:24459,264--a------c:\windows\system32\dllcache\msfeeds.dll 2008-10-23 01:32 . 2008-08-26 02:24383,488--a------c:\windows\system32\dllcache\ieapfltr.dll 2008-10-23 01:32 . 2008-08-26 02:24267,776--a------c:\windows\system32\dllcache\iertutil.dll 2008-10-23 01:32 . 2008-08-26 02:2463,488--a------c:\windows\system32\dllcache\icardie.dll 2008-10-23 01:32 . 2008-08-26 02:2452,224--a------c:\windows\system32\dllcache\msfeedsbs.dll 2008-10-23 01:32 . 2008-08-25 03:3813,824--a------c:\windows\system32\dllcache\ieudinit.exe 2008-10-23 00:49 . 2008-10-23 00:49<DIR>d--------c:\program files\uTorrent 2008-10-23 00:49 . 2008-11-08 02:09<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\uTorrent 2008-10-23 00:48 . 2008-10-23 00:21246--a------c:\windows\system\hpsysdrv.dat 2008-10-23 00:45 . 2008-10-22 23:21<DIR>d--------c:\windows\I386 2008-10-23 00:35 . 2008-06-13 06:05272,128--a------c:\windows\system32\drivers\bthport.sys 2008-10-23 00:35 . 2008-06-13 06:05272,128--a------c:\windows\system32\dllcache\bthport.sys 2008-10-23 00:34 . 2008-08-14 05:112,189,184--a------c:\windows\system32\dllcache\ntoskrnl.exe 2008-10-23 00:34 . 2008-08-14 05:092,145,280--a------c:\windows\system32\dllcache\ntkrnlmp.exe 2008-10-23 00:34 . 2008-08-14 04:332,066,048--a------c:\windows\system32\dllcache\ntkrnlpa.exe 2008-10-23 00:34 . 2008-08-14 04:332,023,936--a------c:\windows\system32\dllcache\ntkrpamp.exe 2008-10-23 00:34 . 2008-09-15 07:121,846,400--a------c:\windows\system32\dllcache\win32k.sys 2008-10-23 00:34 . 2008-09-08 05:41333,824--a------c:\windows\system32\dllcache\srv.sys 2008-10-23 00:32 . 2008-04-11 14:04691,712--a------c:\windows\system32\dllcache\inetcomm.dll 2008-10-23 00:32 . 2008-05-08 09:02203,136--a------c:\windows\system32\dllcache\rmcast.sys 2008-10-22 23:17 . 2008-11-08 11:39<DIR>d-a------c:\documents and settings\All Users\Application Data\TEMP 2008-10-22 22:49 . 2008-10-22 22:49<DIR>d--------c:\program files\iTunes 2008-10-22 22:49 . 2008-10-22 22:49<DIR>d--------c:\program files\iPod 2008-10-22 22:49 . 2008-10-22 22:49<DIR>d--------c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-10-22 22:48 . 2008-10-22 22:48<DIR>d--------c:\program files\Bonjour 2008-10-22 22:47 . 2008-10-22 22:48<DIR>d--------c:\program files\QuickTime 2008-10-22 22:46 . 2008-10-22 22:49<DIR>d----c---c:\windows\system32\DRVSTORE 2008-10-22 22:46 . 2008-10-22 22:47<DIR>d--------c:\program files\Common Files\Apple 2008-10-22 22:46 . 2008-10-22 22:47<DIR>d--------c:\program files\Apple Software Update 2008-10-22 22:46 . 2008-10-22 22:46<DIR>d--------c:\documents and settings\All Users\Application Data\Apple 2008-10-22 22:42 . 2008-06-10 01:3273,728--a------c:\windows\system32\javacpl.cpl 2008-10-22 22:40 . 2008-04-13 13:395,504--a------c:\windows\system32\drivers\mstee.sys 2008-10-22 22:39 . 2008-04-13 19:1291,136--a------c:\windows\system32\kswdmcap.ax 2008-10-22 22:39 . 2008-04-13 13:4685,248--a------c:\windows\system32\drivers\nabtsfec.sys 2008-10-22 22:39 . 2008-04-13 19:1261,952--a------c:\windows\system32\kstvtune.ax 2008-10-22 22:39 . 2008-04-13 19:1228,672--a------c:\windows\system32\vidcap.ax 2008-10-22 22:39 . 2008-04-13 13:4619,200--a------c:\windows\system32\drivers\wstcodec.sys 2008-10-22 22:39 . 2008-04-13 13:4617,024--a------c:\windows\system32\drivers\ccdecode.sys 2008-10-22 22:39 . 2008-04-13 19:1216,384--a------c:\windows\system32\ipsink.ax 2008-10-22 22:39 . 2008-04-13 13:4615,232--a------c:\windows\system32\drivers\streamip.sys 2008-10-22 22:39 . 2008-04-13 13:4611,136--a------c:\windows\system32\drivers\slip.sys 2008-10-22 22:39 . 2008-04-13 13:4610,880--a------c:\windows\system32\drivers\ndisip.sys 2008-10-22 22:38 . 2008-04-13 19:1253,760--a------c:\windows\system32\vfwwdm32.dll 2008-10-22 22:38 . 2008-04-13 19:1243,008--a------c:\windows\system32\ksxbar.ax 2008-10-22 22:21 . 2008-10-22 22:23<DIR>d--------c:\program files\Winamp 2008-10-22 22:21 . 2008-11-08 01:181,125--a------c:\windows\winamp.ini 2008-10-22 22:20 . 2008-10-22 22:20<DIR>d--------c:\program files\7-Zip 2008-10-22 22:01 . 2004-08-04 07:00221,184--a------c:\windows\system32\wmpns.dll 2008-10-22 22:00 . 2008-10-22 22:011,857-rahs----c:\windows\system32\drivers\103C_HP_CPC_ED861AA-ABA SR1603WM NA540_YC_0Pres_QCNH542_E54NAheRED2_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.08_T050913_WXH2_L409_M223_J80_7AMD_8Sempron_91.79_#051225_ N10EC8139_Z14F12F20_G10025954.MRK 2008-10-22 21:58 . 2005-08-08 17:50<DIR>d--------c:\documents and settings\Compaq_Owner\WINDOWS 2008-10-22 21:58 . 2005-08-08 17:54<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\SampleView 2008-10-22 21:58 . 2005-08-08 17:49<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Apple Computer 2008-10-22 21:58 . 2008-10-22 23:07<DIR>d--------c:\documents and settings\Compaq_Owner 2008-10-22 21:56 . 2005-08-08 17:50<DIR>d--------c:\windows\system32\config\systemprofile\WINDOWS 2008-10-22 21:55 . 2005-08-08 17:50<DIR>d--------c:\documents and settings\Default User\WINDOWS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-24 12:01---------d-----wc:\program files\Common Files\Adobe 2008-10-23 10:4361,440----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll 2008-10-23 10:4345,056----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe 2008-10-23 10:4344,032----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe 2008-10-23 10:4340,960----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll 2008-10-23 10:4332,768----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll 2008-10-23 10:4332,768----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard ,L=Cupertino,S=Ca,C=US\plugin\Scom.dll 2008-10-23 10:43287,310----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packar d,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection.dll 2008-10-23 10:43163,840----a-wc:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packar d,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll 2008-10-23 04:14---------d-----wc:\program files\Common Files\InstallShield 2008-10-23 04:12---------d--h--wc:\program files\InstallShield Installation Information 2008-10-23 03:47---------d-----wc:\documents and settings\All Users\Application Data\Apple Computer 2008-10-23 03:42---------d-----wc:\program files\Java 2008-09-15 12:121,846,400----a-wc:\windows\system32\win32k.sys 2008-09-08 10:41333,824----a-wc:\windows\system32\drivers\srv.sys 2008-08-29 14:1887,336----a-wc:\windows\system32\dns-sd.exe 2008-08-29 13:5361,440----a-wc:\windows\system32\dnssd.dll 2008-08-27 17:543,593,216----a-wc:\windows\system32\dllcache\mshtml.dll 2008-08-25 08:3770,656----a-wc:\windows\system32\dllcache\ie4uinit.exe 2008-08-23 05:56635,848----a-wc:\windows\system32\dllcache\iexplore.exe 2008-08-23 05:54161,792----a-wc:\windows\system32\dllcache\ieakui.dll 2008-08-14 10:092,145,280----a-wc:\windows\system32\ntoskrnl.exe 2008-08-14 10:04138,496----a-wc:\windows\system32\dllcache\afd.sys 2008-08-14 09:332,023,936----a-wc:\windows\system32\ntkrnlpa.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "Y!TunnelPro"="c:\program files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe" [2008-09-27 1412608] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-09-10 1056928] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=mtcunz.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"= R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\Drivers\ubVeo532.sys [2002-07-01 95232] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 *Newly Created Service* - MCHINJDRV . - - - - ORPHANS REMOVED - - - - BHO-{51c46c26-aecf-4c77-bf84-f867875f0083} - c:\windows\system32\mtcunz.dll BHO-{96E74E0B-9143-4D55-B522-35112296956A} - c:\windows\system32\ssqPjgFu.dll BHO-{E4083A24-0B25-4C9C-8922-D83F41418036} - c:\windows\system32\efcBTLfE.dll ShellExecuteHooks-{96E74E0B-9143-4D55-B522-35112296956A} - c:\windows\system32\ssqPjgFu.dll . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/ R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser R1 -: HKCU-Internet Settings,ProxyOverride = *.local R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s O8 -: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 . ************************************************************************ ** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 11:39:04 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: c:\windows\explorer.exe -> c:\program files\TrojanHunter 5.0\THSec.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\searchindexer.exe . ************************************************************************ ** . Completion time: 2008-11-08 11:51:51 - machine was rebooted ComboFix-quarantined-files.txt 2008-11-08 16:51:39 Pre-Run: 19,322,314,752 bytes free Post-Run: 19,244,920,832 bytes free 245--- E O F ---2008-10-24 03:22:58
|