Thomas
Full Member
  

Gender: 
Posts: 233
|
 |
Re: my pc might be infected
« Reply #5 on: Dec 21st, 2008, 5:24pm » |
Quote Modify
|
ComboFix 08-12-21.02 - Compaq_Owner 2008-12-21 18:04:12.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.222.55 [GMT -5:00] Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ----- BITS: Possible infected sites ----- hxxp://speedytorrents.net . ((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 ))))))))))))))))))))))))))))))) . 2008-12-21 15:19 . 2008-12-21 15:19<DIR>d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-21 15:18 . 2008-12-21 15:19<DIR>d--------c:\program files\SUPERAntiSpyware 2008-12-21 15:18 . 2008-12-21 15:18<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com 2008-12-21 15:17 . 2008-12-21 15:17<DIR>d--------c:\program files\Common Files\Wise Installation Wizard 2008-12-21 13:30 . 2008-12-21 13:30<DIR>d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-21 13:30 . 2008-12-21 13:30<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes 2008-12-21 13:30 . 2008-12-21 13:30<DIR>d--------c:\documents and settings\All Users\Application Data\Malwarebytes 2008-12-21 13:30 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-21 13:30 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys 2008-12-18 09:50 . 2008-12-18 09:50<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\DivX 2008-12-18 06:37 . 2008-12-18 06:37<DIR>d--------c:\program files\AC3Filter 2008-12-18 06:37 . 2008-07-09 03:05421,888--a------c:\windows\system32\ac3filter.acm 2008-12-18 06:36 . 2008-12-18 06:36<DIR>d--------c:\program files\DivX 2008-12-18 05:37 . 2008-12-18 05:38<DIR>d--------c:\program files\MagicDVDRipper 2008-12-14 06:21 . 2003-10-28 05:0220,016---------c:\windows\system32\drivers\pxhelp20.sys 2008-12-13 04:40 . 2008-12-13 04:40<DIR>d--------C:\mysql 2008-12-09 21:43 . 2008-12-09 21:43<DIR>d--------c:\program files\Viewpoint 2008-12-09 21:43 . 2008-12-09 21:43<DIR>d--------c:\documents and settings\All Users\Application Data\Viewpoint 2008-12-07 21:44 . 2006-03-03 10:02658,432--a------c:\windows\system32\cc3270mt.dll 2008-12-07 21:44 . 2003-05-21 13:5024,576--a------c:\windows\system32\msxml3a.dll 2008-12-06 21:55 . 2004-05-14 16:53462,848--a------c:\windows\system32\ltkrn13n.dll 2008-12-06 21:55 . 2004-05-14 16:53450,560--a------c:\windows\system32\ltimg13n.dll 2008-12-06 21:55 . 2004-05-14 16:53401,408--a------c:\windows\system32\lfcmp13n.dll 2008-12-06 21:55 . 2004-05-14 16:53299,008--a------c:\windows\system32\ltdis13n.dll 2008-12-06 21:55 . 2004-01-12 02:09206,336--a------c:\windows\system32\ltefx13n.dll 2008-12-06 21:55 . 2004-05-14 16:53163,840--a------c:\windows\system32\ltfil13n.dll 2008-12-06 21:55 . 2003-11-04 15:1069,632--a------c:\windows\system32\lfgif13n.dll 2008-12-06 21:55 . 2004-05-14 16:5357,344--a------c:\windows\system32\lfbmp13n.dll 2008-11-23 20:07 . 2008-11-23 20:07<DIR>d--------c:\documents and settings\Compaq_Owner\Contacts 2008-11-23 20:04 . 2008-11-23 20:04<DIR>d--------c:\program files\MSN Messenger 2008-11-21 16:47 . 2008-11-21 16:473,596,288--a------c:\windows\system32\qt-dx331.dll 2008-11-21 16:47 . 2008-11-21 16:47524,288--a------c:\windows\system32\DivXsm.exe 2008-11-21 16:47 . 2008-11-21 16:474,816--a------c:\windows\system32\divxsm.tlb 2008-11-21 16:46 . 2008-11-21 16:461,044,480--a------c:\windows\system32\libdivx.dll 2008-11-21 16:46 . 2008-11-21 16:46200,704--a------c:\windows\system32\ssldivx.dll 2008-11-21 16:44 . 2008-11-21 16:44161,096--a------c:\windows\system32\DivXCodecVersionChecker.exe 2008-11-21 16:44 . 2008-11-21 16:4412,288--a------c:\windows\system32\DivXWMPExtType.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-21 23:00---------d---a-wc:\documents and settings\All Users\Application Data\TEMP 2008-12-21 20:23---------d-----wc:\documents and settings\Compaq_Owner\Application Data\uTorrent 2008-12-18 12:37---------d-----wc:\program files\TrojanHunter 5.0 2008-12-14 11:22---------d-----wc:\program files\Winamp 2008-11-14 09:29---------d-----wc:\program files\MySpace 2008-11-14 09:29---------d-----wc:\documents and settings\Compaq_Owner\Application Data\MySpace 2008-10-31 01:20---------d-----wc:\documents and settings\Compaq_Owner\Application Data\Windows Search 2008-10-24 12:01---------d-----wc:\program files\Common Files\Adobe Systems Shared 2008-10-24 12:01---------d-----wc:\program files\Common Files\Adobe 2008-10-24 11:21455,296----a-wc:\windows\system32\drivers\mrxsmb.sys 2008-10-23 11:44---------d-----wc:\documents and settings\All Users\Application Data\Yahoo! 2008-10-23 11:42---------d-----wc:\program files\Yahoo! 2008-10-23 11:41---------d-----wc:\program files\Trend Micro 2008-10-23 11:15---------d-----wc:\documents and settings\Compaq_Owner\Application Data\Digital Asphyxia 2008-10-23 11:15---------d-----wc:\documents and settings\All Users\Application Data\Digital Asphyxia 2008-10-23 11:14---------d-----wc:\program files\Digital Asphyxia 2008-10-23 11:14---------d-----wc:\documents and settings\All Users\Application Data\Tarma Installer 2008-10-23 11:10---------d-----wc:\documents and settings\Compaq_Owner\Application Data\TrojanHunter 2008-10-23 08:16---------d-----wc:\program files\Microsoft Silverlight 2008-10-23 08:16---------d-----wc:\program files\Microsoft CAPICOM 2.1.0.2 2008-10-23 08:01---------d-----wc:\program files\MSXML 6.0 2008-10-23 07:54---------d-----wc:\program files\MSBuild 2008-10-23 07:51---------d-----wc:\program files\Reference Assemblies 2008-10-23 07:31---------d-----wc:\documents and settings\Compaq_Owner\Application Data\Windows Desktop Search 2008-10-23 07:30---------d-----wc:\program files\Windows Desktop Search 2008-10-23 07:28---------d-----wc:\program files\Windows Media Connect 2 2008-10-23 05:49---------d-----wc:\program files\uTorrent 2008-10-23 04:14---------d-----wc:\program files\Common Files\InstallShield 2008-10-23 04:12---------d--h--wc:\program files\InstallShield Installation Information 2008-10-23 03:49---------d-----wc:\program files\iTunes 2008-10-23 03:49---------d-----wc:\program files\iPod 2008-10-23 03:49---------d-----wc:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-10-23 03:48---------d-----wc:\program files\QuickTime 2008-10-23 03:48---------d-----wc:\program files\Bonjour 2008-10-23 03:47---------d-----wc:\program files\Common Files\Apple 2008-10-23 03:47---------d-----wc:\program files\Apple Software Update 2008-10-23 03:47---------d-----wc:\documents and settings\All Users\Application Data\Apple Computer 2008-10-23 03:46---------d-----wc:\documents and settings\All Users\Application Data\Apple 2008-10-23 03:42---------d-----wc:\program files\Java 2008-10-23 03:20---------d-----wc:\program files\7-Zip 2008-10-23 03:011,857--sha-rc:\windows\system32\drivers\103C_HP_CPC_ED861AA-ABA SR1603WM NA540_YC_0Pres_QCNH542_E54NAheRED2_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.08_T050913_WXH2_L409_M223_J80_7AMD_8Sempron_91.79_#051225_ N10EC8139_Z14F12F20_G10025954.MRK . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184] "Y!TunnelPro"="c:\program files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe" [2008-09-27 1412608] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-09-10 1056928] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944] R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024] R2 MBAMService;MBAMService;"c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe" [2008-12-21 170640] R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-12-09 24652] R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\Drivers\ubVeo532.sys [2002-07-01 95232] R3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys [2008-12-21 15504] R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 . ************************************************************************ ** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-21 18:13:23 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(648 ) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll . Completion time: 2008-12-21 18:16:45 ComboFix-quarantined-files.txt 2008-12-21 23:16:21 Pre-Run: 58,224,181,248 bytes free Post-Run: 59,723,051,008 bytes free 177--- E O F ---2008-12-11 17:16:18
|