cristi199833
Newbie


Posts: 6
|
 |
Re: trojan hunter says no/antivirus say yes
« Reply #8 on: Dec 5th, 2007, 1:09pm » |
Quote Modify
|
ComboFix 07-12-02.6 - Xp 2007-11-29 20:44:46.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.213 [GMT 2:00] Running from: E:\alarma\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\screensavers.com C:\Program Files\screensavers.com\ActiveDesktop\bin\ActiveDesktopExe.exe C:\Program Files\screensavers.com\SSSInstaller\bin\screensavers.exe C:\Program Files\screensavers.com\SSSInstaller\bin\sinstaller3.exe C:\Program Files\screensavers.com\SSSInstaller\bin\SSSInstaller.dll C:\Program Files\screensavers.com\SSSUninst.exe C:\Program Files\Starware316 C:\Program Files\Starware316\bin\Starware316.dll C:\WINDOWS\system32\ci.dll C:\WINDOWS\system32\drivers\pvhwydib.dat C:\WINDOWS\system32\drivers\vnafudcc.dat . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_MGLPEWGN -------\mglpewgn ((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 ))))))))))))))))))))))))))))))) . 2007-11-29 16:24 . 2007-11-29 16:24 <DIR> d-------- C:\Program Files\Trend Micro 2007-11-24 22:39 . 2007-11-24 22:39 <DIR> d-------- C:\Screensavers.com 2007-11-24 22:39 . 2007-11-24 22:39 2,285,222 --a------ C:\WINDOWS\Matrix Code.exe 2007-11-24 22:39 . 2007-11-24 22:39 232,784 --a------ C:\WINDOWS\Matrix Code.scr 2007-11-24 22:39 . 2007-11-24 22:39 29,696 --a------ C:\WINDOWS\mickey32.dll 2007-11-09 08:23 . 2007-11-09 08:23 <DIR> d-------- C:\New Folder 2007-11-08 19:30 . 2007-11-08 19:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TrojanHunter 2007-11-08 19:30 . 2007-11-08 19:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7 2007-11-08 19:01 . 2007-11-08 19:01 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft 2007-11-08 17:48 . 2007-11-08 18:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-11-08 17:30 . 2007-11-08 17:30 <DIR> d-------- C:\Documents and Settings\Xp\Application Data\Grisoft 2007-11-08 17:27 . 2007-11-08 17:29 <DIR> d-------- C:\Program Files\RogueRemover FREE 2007-11-08 17:27 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-11-08 14:19 . 2007-11-08 14:19 <DIR> d-------- C:\Documents and Settings\Xp\Application Data\TrojanHunter 2007-11-08 13:38 . 2007-11-08 13:38 <DIR> d-------- C:\Program Files\TrojanHunter 5.0 2007-11-07 21:38 . 2007-11-07 21:38 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared 2007-11-07 21:37 . 2007-11-07 22:00 <DIR> d-------- C:\Program Files\StrongDC++ 2007-11-07 21:21 . 2007-11-07 21:28 <DIR> d-------- C:\WINDOWS\SxsCaPendDel . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-29 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7 2007-11-23 15:58 --------- d-----w C:\Program Files\3GP Player 2007-11-08 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft 2007-11-08 10:58 --------- d-----w C:\Documents and Settings\Xp\Application Data\AVG7 2007-11-07 22:27 --------- d-----w C:\Program Files\oDC 2007-11-07 19:32 --------- d-----w C:\Program Files\Common Files\Adobe 2007-11-07 19:28 --------- d-----w C:\Program Files\Google 2007-11-05 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet 2007-11-01 16:30 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-10-25 16:14 --------- d-----w C:\Documents and Settings\Xp\Application Data\Canon 2007-10-24 08:49 --------- d-----w C:\Program Files\Investintech.com Inc 2007-10-24 08:28 --------- d-----w C:\Program Files\FinePixViewer 2006-05-04 20:41 397,352 ----a-w C:\Program Files\msgr75us.exe 2005-04-13 20:20 262,144 ----a-w C:\Program Files\CloseWindows.exe 2007-01-07 15:02 56 --sh--r C:\WINDOWS\system32\E920C22E51.sys 2007-07-03 18:25 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56] "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 21:49] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-06-16 13:38] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-07-09 21:25] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-07-09 21:13] "AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 04:59 C:\WINDOWS\AGRSMMSG.exe] "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2002-11-25 03:23] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-19 03:37] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-19 03:35] "LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2003-05-12 14:28] "HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2003-09-04 15:46] "CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2003-08-22 15:08] "LMgrOSD"="C:\Program Files\Launch Manager\OSD.exe" [2003-06-25 10:53] "Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2003-09-08 15:48] "AVManager"="C:\Program Files\Wistron\AVManager\AVManager.exe" [2004-03-02 15:41] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-22 19:50] "Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-12 22:32] "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 16:05] "SpywareHeal"="C:\Program Files\SpywareHeal\SpywareHeal.exe" [] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-24 22:58] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 21:26] "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 21:17] "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32] "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-22 19:50] C:\Documents and Settings\Xp\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2007-11-01 18:33:34] Rainlendar.lnk - C:\Program Files\Rainlendar\Rainlendar.exe [2005-07-22 17:14:46] R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS.SYS R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;C:\WINDOWS\system32\Drivers\WBSD.SYS S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys . ************************************************************************ ** catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-02 20:51:19 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . Completion time: 2007-12-02 20:52:20 - machine was rebooted . --- E O F --- so this is it ; i tried to erase starware,but i could not but i saw that combofix did for me. so it is erased now. thanks a milion; next ? what can i do?
|