perplexing
Newbie


Posts: 9
|
 |
Re: been batteling Vundo for a week now
« Reply #2 on: Dec 11th, 2007, 10:13am » |
Quote Modify
|
hey conman, I have carried out the tasks and here are the results. I have the full version of TrojanHunter which is purchased two days back. Also, please note that there is a message I wrote among the posts stating what Norton found. I am sorry for the multiple postings but the form will not allow me to post the whole thing in one piece ComboFix 07-12-09.1 - faziz 2007-12-11 10:52:57.7 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1250 [GMT -5:00] Running from: C:\Documents and Settings\faziz\Desktop\ComboFix.exe * Created a new restore point . The following files were disabled during the run: C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll ((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 ))))))))))))))))))))))))))))))) . 2007-12-11 10:41 . 2007-12-11 10:41<DIR>d--------C:\Program Files\CCleaner 2007-12-10 09:05 . 2007-12-10 09:3190,624--a------C:\WINDOWS\system32\JDEAP.DLL 2007-12-07 12:25 . 2007-12-07 12:24102,664--a------C:\WINDOWS\system32\drivers\tmcomm.sys 2007-12-07 12:24 . 2007-12-07 16:17<DIR>d--------C:\Documents and Settings\faziz\.housecall6.6 2007-12-07 12:23 . 2007-09-24 23:3169,632--a------C:\WINDOWS\system32\javacpl.cpl 2007-12-07 12:21 . 2007-12-07 12:22<DIR>d--------C:\Program Files\Java 2007-12-07 12:21 . 2007-12-07 12:21<DIR>d--------C:\Program Files\Common Files\Java 2007-12-06 14:44 . 2007-12-06 14:44<DIR>d--------C:\Documents and Settings\faziz\Application Data\TrojanHunter 2007-12-06 12:29 . 2007-12-10 08:02<DIR>d--------C:\Program Files\TrojanHunter 5.0 2007-12-06 08:42 . 2007-12-06 08:42<DIR>d--------C:\Documents and Settings\NetworkService\Application Data\Webroot 2007-12-04 17:54 . 2007-12-04 17:54<DIR>d--------C:\Documents and Settings\faziz\Application Data\Roxio 2007-12-04 17:20 . 2007-12-04 17:20<DIR>d--------C:\Documents and Settings\LocalService\Application Data\Webroot 2007-12-04 17:20 . 2007-10-01 16:24163,640--a------C:\WINDOWS\system32\drivers\ssidrv.sys 2007-12-04 17:20 . 2007-10-01 16:2423,864--a------C:\WINDOWS\system32\drivers\sskbfd.sys 2007-12-04 17:20 . 2007-10-01 16:2421,816--a------C:\WINDOWS\system32\drivers\sshrmd.sys 2007-12-04 17:20 . 2007-10-01 16:2420,280--a------C:\WINDOWS\system32\drivers\SSFS0BB9.sys 2007-12-04 17:19 . 2007-12-04 17:19<DIR>d--------C:\Program Files\Webroot 2007-12-04 17:19 . 2007-12-04 17:19<DIR>d--------C:\Documents and Settings\faziz\Application Data\Webroot 2007-12-04 17:19 . 2007-12-04 17:19<DIR>d--------C:\Documents and Settings\All Users\Application Data\Webroot 2007-12-04 17:19 . 2007-10-01 16:401,526,072--a------C:\WINDOWS\WRSetup.dll 2007-12-04 17:18 . 2007-12-04 17:18164--a------C:\install.dat 2007-12-04 12:29 . 2007-12-04 12:29<DIR>d--------C:\Program Files\GiPo@Utilities 2007-12-04 12:29 . 2007-12-04 12:29<DIR>d--------C:\Program Files\Common Files\Gibinsoft Shared 2007-12-04 10:58 . 2006-09-11 10:56526,184--a------C:\WINDOWS\system32\XceedCry.dll 2007-12-04 10:58 . 2006-12-21 14:18497,496--a------C:\WINDOWS\system32\XceedZip.dll 2007-12-04 10:58 . 2004-12-07 09:11258,352--a------C:\WINDOWS\system32\unicows.dll 2007-12-04 10:57 . 2003-05-14 21:07389,120--a------C:\WINDOWS\system32\actskn43.ocx 2007-12-04 08:39 . 2007-12-04 08:39<DIR>d--------C:\Program Files\Enigma Software Group 2007-12-03 10:32 . 2007-12-11 07:52<DIR>d--------C:\Program Files\Spyware Doctor 2007-12-03 10:32 . 2007-12-03 10:32<DIR>d--------C:\Documents and Settings\faziz\Application Data\PC Tools 2007-12-03 10:32 . 2005-09-23 08:29626,688--a------C:\WINDOWS\system32\msvcr80.dll 2007-12-03 10:32 . 2007-10-18 00:1679,688--a------C:\WINDOWS\system32\drivers\iksyssec.sys 2007-12-03 10:32 . 2007-10-18 00:1562,280--a------C:\WINDOWS\system32\drivers\iksysflt.sys 2007-12-03 10:32 . 2007-10-18 00:1441,288--a------C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-12-03 10:32 . 2007-10-18 00:1629,000--a------C:\WINDOWS\system32\drivers\kcom.sys 2007-12-03 07:45 . 2007-12-03 07:45<DIR>d--hs----C:\found.000 2007-11-30 12:56 . 2007-11-30 12:56<DIR>d--------C:\Program Files\Lavasoft 2007-11-30 12:56 . 2007-11-30 12:56<DIR>d--------C:\Program Files\Common Files\Wise Installation Wizard 2007-11-30 12:56 . 2007-11-30 12:56<DIR>d--------C:\Documents and Settings\All Users\Application Data\Lavasoft 2007-11-30 09:37 . 2007-11-30 09:37<DIR>d--------C:\Documents and Settings\faziz\Application Data\Grisoft 2007-11-30 09:37 . 2007-05-30 07:1010,872--a------C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-11-30 09:36 . 2007-11-30 09:36<DIR>d--------C:\Documents and Settings\All Users\Application Data\Grisoft 2007-11-29 11:40 . 2007-11-29 11:400--a------C:\WINDOWS\vpc32.INI 2007-11-29 08:23 . 2007-11-29 08:24<DIR>d--------C:\Program Files\ClamWinPortable 2007-11-28 12:18 . 2007-12-03 15:34<DIR>d--------C:\Program Files\efkdkhex 2007-11-28 12:18 . 2007-12-04 17:48<DIR>d--------C:\Program Files\Dpgkoonr 2007-11-28 09:30 . 2007-11-28 09:30<DIR>d--------C:\Program Files\Common Files\Macrovision Shared 2007-11-28 09:30 . 2007-12-04 11:37<DIR>d--------C:\Documents and Settings\All Users\Application Data\FLEXnet 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\WINDOWS\DewberryApps 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\wstahl\Dewberry 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\mfriedenthal\Dewberry 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\faziz\Dewberry 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\Default User\Dewberry 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\cellis\Dewberry 2007-11-27 16:33 . 2007-11-27 16:33<DIR>d--------C:\Documents and Settings\BONA\Dewberry 2007-11-14 16:20 . 2006-12-13 10:06<DIR>d---s----C:\Documents and Settings\cellis\UserData 2007-11-14 16:20 . 2007-01-03 10:48<DIR>d--------C:\Documents and Settings\cellis\Application Data\Lavasoft 2007-11-14 07:21 . 2007-11-14 07:21<DIR>d--------C:\Program Files\Tracker Software 2007-11-14 05:18 . 2007-11-14 05:18<DIR>d--------C:\Program Files\RealVNC . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-11 14:50---------d-----wC:\Program Files\Application Folder 2007-12-11 14:00---------d-----wC:\Documents and Settings\All Users\Application Data\Google Updater 2007-12-11 12:07---------d-----wC:\Program Files\LogMeIn 2007-11-28 15:59---------d--h--wC:\Program Files\InstallShield Installation Information 2007-11-28 14:30---------d-----wC:\Program Files\Common Files\Adobe 2007-11-21 19:0987,352----a-wC:\WINDOWS\system32\LMIinit.dll 2007-11-21 19:0983,288----a-wC:\WINDOWS\system32\LMIRfsClientNP.dll 2007-11-21 19:0923,736----a-wC:\WINDOWS\system32\lmimirr.dll 2007-11-21 19:0921,496----a-wC:\WINDOWS\system32\LMIport.dll 2007-11-21 19:0910,040----a-wC:\WINDOWS\system32\lmimirr2.dll 2007-11-20 18:50---------d-----wC:\Program Files\Google 2007-11-14 18:36167,936----a-wC:\WINDOWS\system32\fbdcnfg.dll 2007-11-12 15:26---------d-----wC:\Program Files\Windows Media Connect 2 2007-11-12 15:26---------d-----wC:\Program Files\Pocket Islam 2007-11-12 15:26---------d-----wC:\Program Files\PackIt 1.1 2007-11-06 13:27---------d-----wC:\Documents and Settings\faziz\Application Data\LimeWire 2007-11-06 13:18---------d-----wC:\Program Files\Microsoft ActiveSync 2007-11-02 16:18---------d-----wC:\Program Files\IrfanView 2007-11-01 19:28---------d-----wC:\Program Files\LimeWire 2007-10-29 12:24---------d-----wC:\Program Files\Nagarro Inc 2007-10-25 19:05---------d-----wC:\Program Files\eFax Messenger 4.3 2007-10-25 19:05---------d-----wC:\Documents and Settings\faziz\Application Data\eFax Messenger 2007-10-25 19:05---------d-----wC:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup 2007-10-25 19:05---------d-----wC:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output 2007-10-25 15:5423----a-wC:\WINDOWS\Fonts\AdobeFnt.lst 2007-10-22 11:31---------d-----wC:\Program Files\Common Files\Symantec Shared 2007-10-22 11:27---------d-----wC:\Program Files\Pakistan Data Management Services 2007-10-17 14:16---------d-----wC:\Program Files\OW Info 2007-10-17 14:06286,720------wC:\WINDOWS\Setup1.exe 2007-10-17 14:06---------d-----wC:\Program Files\123JulianToDate 2007-10-17 13:46---------d-----wC:\Program Files\Everest Software International 2007-10-11 16:02---------d-----wC:\Documents and Settings\faziz\Application Data\webex 2007-10-11 16:0151,304----a-wC:\WINDOWS\system32\drivers\atnt40k.sys 2007-10-11 16:01202,826----a-wC:\WINDOWS\system32\atasnt40.dll 2004-03-24 15:461,748,917----a-wC:\Program Files\xpsp1DeployTools_en.cab . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-02 11:10] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 21:36] "SyncMyCal"="C:\Program Files\Nagarro Inc\SyncMyCal\SyncMyCal.exe" [2007-08-09 10:51] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 08:15] "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] "nwiz"="nwiz.exe" [2006-07-12 12:19 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 18:26] "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-09-27 19:33] "PDDM"="C:\Program Files\PatchLink\Update Agent\pddm.exe" [2007-01-25 15:32] "LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 13:03] "eFax 4.3"="C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 12:21] "SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2007-11-30 13:47] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2007-09-09 09:31] "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "HideStartupScripts"= 0 (0x0) "RunLogonScriptSync"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] LMIinit.dll 2007-11-21 14:09 87352 C:\WINDOWS\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List\{00000000-0000-0000-0000-00000000000 0}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Extension-List\{c6dc5466-785a-11d2-84d0-00c04fb169f 7}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\1] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\2] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\3] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\4] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\5] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPLink-List\6] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\1] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\2] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\3] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\4] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\5] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\GPO-List\6] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\Extension-Li st] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\Extension-Li st\{00000000-0000-0000-0000-000000000000}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\GPLink-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\GPLink-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\GPO-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\GPO-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\Loopback-GPL ink-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-1003\Loopback-GPO -List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\Extension-Lis t] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\Extension-Lis t\{00000000-0000-0000-0000-000000000000}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\Extension-Lis t\{c6dc5466-785a-11d2-84d0-00c04fb169f7}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\GPLink-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\GPLink-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\GPO-List] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\GPO-List\0] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3292650235-2419647484-3825283475-500\Loopback-GPLi nk-List]
|