Welcome, Guest. Please Login or Register.
Search
Members
Login
Register
   Mischel Internet Security Forum
   Malware
   Adware, Browser Hijackers and other Malware
(Moderators: Helena, Gavin_Coe, Magnus)
   Combofix Log
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Combofix Log  (Read 730 times)
Thomas
Full Member
***






   


Gender: male
Posts: 233
Combofix Log
« on: Nov 19th, 2009, 8:31pm »
Quote Quote  Modify Modify

ComboFix 09-11-19.05 - Owner 11/19/2009 21:17.1.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.222.92 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
c:\documents and settings\Owner\Application Data\addon.dat
c:\windows\system32\Explorer
c:\windows\system32\Explorer\Explorer.exe
c:\windows\system32\Explorer\klog.dat
c:\windows\system32\SCLabel.ocx
 
.
(((((((((((((((((((((((((   Files Created from 2009-10-20 to 2009-11-20  )))))))))))))))))))))))))))))))
.
 
2009-11-16 15:42 . 2007-05-03 18:36778240----a-w-c:\windows\system32\SkinCrafter2.dll
2009-11-14 03:34 . 2009-11-14 03:34--------d-----w-c:\documents and settings\Owner\Application Data\Registry Mechanic
2009-11-13 05:01 . 2009-11-13 05:01--------d-----w-c:\documents and settings\Owner\Application Data\Yahoo!
2009-11-03 23:13 . 2009-11-03 23:13152576----a-w-c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-03 17:23 . 2009-11-03 17:23--------d-----w-c:\windows\Sun
2009-10-29 22:10 . 2003-10-28 10:0220016------w-c:\windows\system32\drivers\pxhelp20.sys
2009-10-29 22:10 . 2009-10-29 22:12--------d-----w-c:\program files\Winamp
2009-10-29 18:20 . 2009-10-29 18:28--------d-----w-c:\program files\Y!Supra
2009-10-26 17:27 . 2009-10-29 18:35987994----a-w-c:\documents and settings\Owner\Application Data\YTK Enhanced\unins000.exe
2009-10-26 16:34 . 2009-10-26 16:34--------d-----w-c:\documents and settings\Owner\Application Data\DivX
2009-10-26 09:24 . 2009-08-06 23:23274288----a-w-c:\windows\system32\mucltui.dll
2009-10-26 08:45 . 2009-10-26 08:46--------d-----w-c:\program files\DivX
2009-10-26 08:44 . 2009-10-26 08:45--------d-----w-c:\program files\Common Files\DivX Shared
2009-10-26 07:27 . 2009-10-26 07:32--------d-----w-c:\documents and settings\Owner\Application Data\TigerPlayer
2009-10-26 07:25 . 2009-10-26 07:25--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-26 07:25 . 2009-11-01 16:40--------d-----w-c:\program files\MpcStar
2009-10-26 07:08 . 2009-10-26 07:08--------d-----w-c:\documents and settings\Owner\Local Settings\Application Data\Yahoo
2009-10-26 06:52 . 2009-10-26 06:53--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-26 06:52 . 2009-09-25 00:16607472----a-w-c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-10-26 06:52 . 2009-10-26 06:52--------d-----w-c:\program files\Yahoo!
2009-10-26 05:58 . 2009-11-20 02:15--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
2009-10-26 05:58 . 2009-10-26 05:58--------d-----w-c:\program files\Common Files\PC Tools
2009-10-26 05:54 . 2009-10-26 05:54--------d-----w-c:\program files\Trend Micro
2009-10-26 05:25 . 2009-10-26 05:25--------d-sh--w-c:\documents and settings\LocalService\IETldCache
2009-10-26 05:18 . 2009-11-12 05:52--------d-----w-c:\documents and settings\Owner\Application Data\YTK Enhanced
2009-10-26 05:04 . 2009-10-26 05:04--------d-----w-c:\documents and settings\Owner\Application Data\Digital Asphyxia
2009-10-26 05:04 . 2009-10-26 05:04--------d-----w-c:\documents and settings\All Users\Application Data\Digital Asphyxia
2009-10-25 20:06 . 2009-10-25 20:06--------d-----w-c:\windows\system32\scripting
2009-10-25 20:06 . 2009-10-25 20:06--------d-----w-c:\windows\l2schemas
2009-10-25 20:06 . 2009-10-25 20:06--------d-----w-c:\windows\system32\en
2009-10-25 20:06 . 2009-10-25 20:06--------d-----w-c:\windows\system32\bits
2009-10-25 19:55 . 2009-10-25 19:55--------d-----w-c:\windows\EHome
2009-10-25 19:45 . 2009-10-25 19:47--------d-----w-c:\program files\CCleaner
2009-10-25 19:39 . 2009-10-25 19:43--------d-----w-c:\program files\RegSeeker
2009-10-25 19:30 . 2009-11-20 01:55--------d-----w-c:\documents and settings\Owner\Tracing
2009-10-25 19:29 . 2009-10-25 19:29--------d-----w-c:\program files\Microsoft
2009-10-25 19:28 . 2009-10-25 19:28--------d-----w-c:\program files\Windows Live SkyDrive
2009-10-25 19:28 . 2009-10-25 19:29--------d-----w-c:\program files\Windows Live
2009-10-25 19:24 . 2009-10-25 19:24--------d-----w-c:\program files\Common Files\Windows Live
2009-10-25 19:23 . 2009-10-25 19:23--------d-----w-c:\program files\Microsoft Silverlight
2009-10-25 16:23 . 2009-10-25 16:24--------d-----w-c:\windows\system32\Adobe
2009-10-25 16:20 . 2009-10-26 05:04--------d-----w-c:\program files\TrojanHunter 5.2
2009-10-25 16:17 . 2006-07-12 01:35503808--s---w-c:\windows\system32\msvcp71.dll
2009-10-25 16:17 . 2006-07-12 01:35348160--s---w-c:\windows\system32\msvcr71.dll
2009-10-25 16:17 . 2006-07-12 01:431060864--s---w-c:\windows\system32\MFC71.dll
2009-10-25 16:17 . 2009-10-25 16:17--------d-----w-c:\program files\Digital Asphyxia
2009-10-25 16:17 . 2009-10-25 16:17--------d-----w-c:\documents and settings\All Users\Application Data\Tarma Installer
2009-10-25 16:17 . 2009-10-25 16:1781920--s---r-c:\documents and settings\All Users\Application Data\Tarma Installer\{D6B25B8D-0566-42B1-A23D-7576138435D6}\Setup.exe
2009-10-25 16:17 . 2008-09-27 22:0457344--s-a-r-c:\documents and settings\All Users\Application Data\Tarma Installer\{D6B25B8D-0566-42B1-A23D-7576138435D6}\_Setup.dll
2009-10-25 16:16 . 2009-10-25 16:16--------d-----w-c:\program files\YTK Enhanced
2009-10-25 15:59 . 2009-10-25 15:59--------d-----w-c:\program files\MSXML 6.0
2009-10-25 15:37 . 2009-10-25 15:38--------d-----w-C:\6d760f4edc99f40afb669ad6e117
2009-10-25 15:20 . 2009-10-25 19:37--------d-----w-c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory
2009-10-25 15:15 . 2009-10-25 15:15--------d-----w-c:\program files\MSBuild
2009-10-25 15:12 . 2009-10-25 15:39--------d-----w-c:\windows\system32\XPSViewer
2009-10-25 15:11 . 2009-10-25 15:11--------d-----w-c:\program files\Reference Assemblies
2009-10-25 15:09 . 2006-06-29 17:0714048------w-c:\windows\system32\spmsg2.dll
2009-10-25 14:54 . 2009-10-25 14:54--------d-sh--w-c:\documents and settings\NetworkService\IETldCache
2009-10-25 14:54 . 2009-10-25 14:54--------d-----w-c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-10-25 14:54 . 2009-10-25 14:54--------d-----w-c:\documents and settings\Owner\Application Data\Windows Desktop Search
2009-10-25 14:53 . 2009-10-25 15:27--------d-----w-c:\program files\Windows Desktop Search
2009-10-25 14:53 . 2009-10-25 14:53--------d-----w-c:\windows\system32\GroupPolicy
2009-10-25 14:52 . 2004-08-04 12:00221184----a-w-c:\windows\system32\wmpns.dll
2009-10-25 14:52 . 2009-10-25 14:52--------d-----w-c:\program files\Windows Media Connect 2
2009-10-25 14:50 . 2009-10-26 06:42--------d-----w-c:\windows\system32\LogFiles
2009-10-25 14:50 . 2009-10-25 14:51--------d-----w-c:\windows\system32\drivers\UMDF
2009-10-25 14:47 . 2008-04-13 18:395504----a-w-c:\windows\system32\drivers\mstee.sys
2009-10-25 14:47 . 2008-04-13 18:4610880----a-w-c:\windows\system32\drivers\ndisip.sys
2009-10-25 14:47 . 2008-04-13 18:4615232----a-w-c:\windows\system32\drivers\streamip.sys
2009-10-25 14:47 . 2008-04-13 18:4611136----a-w-c:\windows\system32\drivers\slip.sys
2009-10-25 14:47 . 2008-04-13 18:4619200----a-w-c:\windows\system32\drivers\wstcodec.sys
2009-10-25 14:47 . 2008-04-13 18:4685248----a-w-c:\windows\system32\drivers\nabtsfec.sys
2009-10-25 14:47 . 2008-04-13 18:4617024----a-w-c:\windows\system32\drivers\ccdecode.sys
2009-10-25 14:46 . 2008-04-14 00:1253760----a-w-c:\windows\system32\vfwwdm32.dll
2009-10-25 14:45 . 2009-10-25 14:46--------d-----w-c:\windows\system32\URTTemp
2009-10-25 14:44 . 2008-04-14 00:1253248------w-c:\windows\system32\tsgqec.dll
2009-10-25 14:44 . 2008-04-14 00:12290304------w-c:\windows\system32\rhttpaa.dll
2009-10-25 14:44 . 2008-04-14 00:11136192------w-c:\windows\system32\aaclient.dll
2009-10-25 14:39 . 2009-10-11 09:17411368----a-w-c:\windows\system32\deploytk.dll
2009-10-25 14:39 . 2009-11-03 23:14--------d-----w-c:\program files\Java
2009-10-25 14:39 . 2009-10-25 14:39152576----a-w-c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-25 14:34 . 2009-10-25 14:34--------d-----w-c:\program files\AC3Filter
2009-10-25 14:33 . 2008-04-13 18:456272----a-w-c:\windows\system32\drivers\splitter.sys
2009-10-25 14:33 . 2008-04-13 19:1783072----a-w-c:\windows\system32\drivers\wdmaud.sys
2009-10-25 14:33 . 2008-04-13 18:4552864----a-w-c:\windows\system32\drivers\dmusic.sys
2009-10-25 14:33 . 2006-08-01 19:0249152----a-w-c:\windows\system32\ChCfg.exe
2009-10-25 14:31 . 2006-12-08 19:2010528768----a-w-c:\windows\system32\RTLCPL.exe
2009-10-25 14:31 . 2007-04-16 19:28577536----a-w-c:\windows\soundman.exe
2009-10-25 14:31 . 2006-10-18 06:53147456----a-w-c:\windows\system32\RtlCPAPI.dll
2009-10-25 14:31 . 2006-07-31 15:27217088----a-w-c:\windows\Alcrmv.exe
2009-10-25 14:31 . 2006-07-31 15:19315392----a-w-c:\windows\alcupd.exe
2009-10-25 14:05 . 2009-10-25 14:05--------d-----w-c:\program files\CONEXANT
2009-10-25 14:03 . 2009-10-25 14:03--------d-----w-c:\program files\ATI Technologies
2009-10-25 14:03 . 2006-04-05 01:05520192------w-c:\windows\system32\ati2sgag.exe
2009-10-25 14:03 . 2009-10-25 14:31--------d--h--w-c:\program files\InstallShield Installation Information
2009-10-25 14:03 . 2009-10-25 14:31--------d-----w-c:\program files\Common Files\InstallShield
2009-10-25 13:52 . 2009-10-25 13:52--------d-----w-c:\program files\7-Zip
2009-10-25 13:49 . 2009-11-18 09:46--------d-----w-c:\program files\uTorrent
2009-10-25 13:48 . 2009-11-19 05:00--------d-----w-c:\documents and settings\Owner\Application Data\uTorrent
2009-10-25 13:40 . 2009-10-25 13:40--------d-sh--w-c:\documents and settings\Owner\IECompatCache
2009-10-25 13:38 . 2009-10-25 13:38--------d-sh--w-c:\documents and settings\Owner\PrivacIE
2009-10-25 13:38 . 2009-10-25 13:38--------d-sh--w-c:\documents and settings\Owner\IETldCache
2009-10-25 13:34 . 2009-08-29 08:0812800-c----w-c:\windows\system32\dllcache\xpshims.dll
2009-10-25 13:34 . 2009-08-29 08:08594432-c----w-c:\windows\system32\dllcache\msfeeds.dll
2009-10-25 13:34 . 2009-08-29 08:0855296-c----w-c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-25 13:34 . 2009-08-29 08:081985536-c----w-c:\windows\system32\dllcache\iertutil.dll
2009-10-25 13:34 . 2009-08-29 08:08246272-c----w-c:\windows\system32\dllcache\ieproxy.dll
2009-10-25 13:34 . 2009-08-29 08:0811069440-c----w-c:\windows\system32\dllcache\ieframe.dll
2009-10-25 13:34 . 2009-11-04 19:48--------d-----w-c:\windows\ie8updates
2009-10-25 13:34 . 2009-10-02 04:4492160-c----w-c:\windows\system32\dllcache\iecompat.dll
2009-10-25 13:33 . 2009-10-25 13:33--------dc-h--w-c:\windows\ie8
2009-10-25 13:29 . 2009-10-25 20:03--------d-----w-c:\windows\ServicePackFiles
2009-10-25 13:25 . 2004-08-04 03:2973216------w-c:\windows\system32\drivers\atintuxx.sys
2009-10-25 13:18 . 2008-06-13 11:05272128-c----w-c:\windows\system32\dllcache\bthport.sys
2009-10-25 13:18 . 2008-06-13 11:05272128------w-c:\windows\system32\drivers\bthport.sys
2009-10-25 13:16 . 2008-10-24 11:21455296-c----w-c:\windows\system32\dllcache\mrxsmb.sys
2009-10-25 13:16 . 2008-05-03 11:552560------w-c:\windows\system32\xpsp4res.dll
2009-10-25 13:16 . 2008-04-21 12:08215552-c----w-c:\windows\system32\dllcache\wordpad.exe
2009-10-25 13:14 . 2008-10-15 16:34337408-c----w-c:\windows\system32\dllcache\netapi32.dll
2009-10-25 13:11 . 2009-05-12 19:1226144----a-w-c:\windows\system32\spupdsvc.exe
2009-10-25 13:11 . 2009-11-12 00:07--------d--h--w-c:\windows\$hf_mig$
2009-10-25 13:08 . 2009-10-25 13:08--------d-sh--w-c:\documents and settings\Owner\UserData
2009-10-25 13:07 . 2009-11-12 02:2913688----a-w-c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 20:10 . 2009-10-25 12:5376487----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-25 14:32 . 2009-10-25 14:31--------d-----w-c:\program files\Realtek AC97
2009-10-25 12:54 . 2009-10-25 12:54--------d-----w-c:\program files\microsoft frontpage
2009-10-25 12:51 . 2009-10-25 12:5121640----a-w-c:\windows\system32\emptyregdb.dat
2009-10-08 19:57 . 2008-07-29 23:59611328----a-w-c:\windows\system32\uiautomationcore.dll
2009-10-08 19:57 . 2004-08-04 12:00220160----a-w-c:\windows\system32\oleacc.dll
2009-10-08 19:56 . 2004-08-04 12:0020480----a-w-c:\windows\system32\oleaccrc.dll
2009-09-25 16:41 . 2009-09-25 16:4190112----a-w-c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41856064----a-w-c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41856064----a-w-c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41847872----a-w-c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41843776----a-w-c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41839680----a-w-c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41696320----a-w-c:\windows\system32\DivX.dll
2009-09-25 05:48 . 2009-09-25 05:4881920------w-c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2004-08-04 12:00136192----a-w-c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:0058880----a-w-c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 12:00916480------w-c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00247326----a-w-c:\windows\system32\strmdll.dll
.
 
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown  
REGEDIT4
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
 
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"=
 
R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 5:30 PM 95232]
.
Contents of the 'Scheduled Tasks' folder
 
2009-11-20 c:\windows\Tasks\User_Feed_Synchronization-{01FFB2EB-1A72-4C64-A0B9-F310 B10D5701}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
 
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
 
 
 
************************************************************************ **
 
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-19 21:24
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ...  
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
************************************************************************ **
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
- - - - - - - > 'winlogon.exe'(728 )
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-11-19 21:28
ComboFix-quarantined-files.txt  2009-11-20 02:28
 
Pre-Run: 65,801,179,136 bytes free
Post-Run: 65,768,148,992 bytes free
 
- - End Of File - - A2FE50232135FB8D0720ACBC2435C286
« Last Edit: Nov 19th, 2009, 8:33pm by Thomas » IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Combofix Log
« Reply #1 on: Nov 19th, 2009, 10:27pm »
Quote Quote  Modify Modify

These are intriguing deletions by Combofix.  Would you please submit the Combofix Qoobox folder to Gavin for analysis per the instructions of the link below.
 
http://www.misec.net/forum/board/FAQ/1139308293
 
Is your system running okay after this run of Combofix?
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #2 on: Nov 19th, 2009, 11:05pm »
Quote Quote  Modify Modify

on Nov 19th, 2009, 10:27pm, siliconman01 wrote:
These are intriguing deletions by Combofix.  Would you please submit the Combofix Qoobox folder to Gavin for analysis per the instructions of the link below.
 
http://www.misec.net/forum/board/FAQ/1139308293
 
Is your system running okay after this run of Combofix?

 
 
yea so far it fine
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #3 on: Nov 20th, 2009, 9:59am »
Quote Quote  Modify Modify

i sent the Combofix Qoobox folder to Gavin and i also put this thread in the email
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Combofix Log
« Reply #4 on: Nov 20th, 2009, 3:10pm »
Quote Quote  Modify Modify

Thanks much for the submission.  It will be interesting to see what Gavin finds on these detections.
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #5 on: Nov 20th, 2009, 11:40pm »
Quote Quote  Modify Modify

on Nov 20th, 2009, 3:10pm, siliconman01 wrote:
Thanks much for the submission.  It will be interesting to see what Gavin finds on these detections.

 
when i try upload them to the email it says it a unknown virus
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Combofix Log
« Reply #6 on: Nov 21st, 2009, 3:46am »
Quote Quote  Modify Modify

Did you ZIP the Qoobox folder before you attached it to the email?
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #7 on: Nov 21st, 2009, 10:38am »
Quote Quote  Modify Modify

on Nov 21st, 2009, 3:46am, siliconman01 wrote:
Did you ZIP the Qoobox folder before you attached it to the email?

 
yup and it said that so i uploading it to a file shareing site
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Combofix Log
« Reply #8 on: Nov 21st, 2009, 10:58am »
Quote Quote  Modify Modify

hmmmm....that must be coming from your email client and server.  Submit@Trojanhunter.com is not a file sharing site.  Can you put password protection on the Zipped Qoobox folder?  If my memory serves me, you are running XP.  
 
-  Right click on the compressed Qoobox folder and select “Explore.”
-  In “File,” select “Add a Password.” Enter the password and confirm the password.  
 
Then attach it and send it.  BE SURE to include the password in your email to Gavin so that he will have it to unlock it.  
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #9 on: Nov 30th, 2009, 10:47am »
Quote Quote  Modify Modify

hey gavin what the results on the files i sent you?
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
Gavin_Coe
Trojan Analyst
*****





   
WWW  

Gender: male
Posts: 3912
Re: Combofix Log
« Reply #10 on: Dec 1st, 2009, 7:54pm »
Quote Quote  Modify Modify

Hi, I did receive this package last week. There was a Backdoor.Agent added, so thanks !
IP Logged
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: Combofix Log
« Reply #11 on: Dec 2nd, 2009, 1:23pm »
Quote Quote  Modify Modify

on Dec 1st, 2009, 7:54pm, Gavin_Coe wrote:
Hi, I did receive this package last week. There was a Backdoor.Agent added, so thanks !

 
from the ocx or the exployer
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »