inkedeagle
Newbie


Posts: 21
|
 |
Re: trojan issues
« Reply #3 on: Dec 29th, 2007, 4:13am » |
Quote Modify
|
ComboFix 07-12-21.4 - inkedeagle 2007-12-29 1:47:36.1 - NTFSx86 Running from: C:\Documents and Settings\inkedeagle\Desktop\ComboFix.exe * Created a new restore point . ADS - svchost.exe: deleted 51200 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\inkedeagle\Application Data\FunWebProducts C:\Documents and Settings\inkedeagle\Application Data\FunWebProducts\Data\inkedeagle\avatar.dat C:\Documents and Settings\inkedeagle\Application Data\inst.exe C:\Documents and Settings\inkedeagle\Application Data\install.dat C:\Documents and Settings\inkedeagle\Application Data\macromedia\Flash Player\#SharedObjects\ACUXNSYC\www.broadcaster.com C:\Documents and Settings\inkedeagle\Application Data\macromedia\Flash Player\#SharedObjects\ACUXNSYC\www.broadcaster.com\played_list.sol C:\Documents and Settings\inkedeagle\Application Data\macromedia\Flash Player\#SharedObjects\ACUXNSYC\www.broadcaster.com\video_queue.sol C:\Documents and Settings\inkedeagle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com C:\Documents and Settings\inkedeagle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com\setti ngs.sol C:\Documents and Settings\inkedeagle\err.log C:\Program Files\Helper C:\Program Files\Helper\superfindout.dll C:\Program Files\MyWebSearch C:\Program Files\MyWebSearch\bar\History\search2 C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat C:\Program Files\MyWebSearch\bar\Settings\setting2.htm C:\Program Files\MyWebSearch\bar\Settings\settings.dat C:\WINDOWS\search_res.txt C:\WINDOWS\system32\ddcyw.dll C:\WINDOWS\system32\nsr1AF.dll C:\WINDOWS\system32\stera.job C:\WINDOWS\system32\stera.log C:\WINDOWS\system32\wycdd.ini C:\WINDOWS\system32\wycdd.ini2 C:\WINDOWS\system32\xpdx.sys C:\WINDOWS\voipwet.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_FCI -------\LEGACY_FOPN -------\LEGACY_VSPF -------\LEGACY_VSPF_HK -------\FCI -------\xpdx ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 ))))))))))))))))))))))))))))))) . 2007-12-29 01:55 . 2007-12-29 01:55344,576---------C:\WINDOWS\system32\ddcyw.dll 2007-12-29 01:29 . 2007-12-29 01:29<DIR>d--h-----C:\WINDOWS\PIF 2007-12-29 01:29 . 2007-12-29 01:292,855--a------C:\WINDOWS\system32\SysSFGE.PIF 2007-12-29 01:26 . 2007-12-29 01:2622--a------C:\WINDOWS\system32\SysSFGE.zip 2007-12-29 01:21 . 2007-12-29 01:40921,646--a------C:\WINDOWS\system32\ddcyw.zip 2007-12-28 22:51 . 2007-12-28 22:51<DIR>d--------C:\Documents and Settings\inkedeagle\Application Data\TrojanHunter 2007-12-28 22:20 . 2007-12-29 01:58<DIR>d--------C:\Program Files\TrojanHunter 5.0 2007-12-28 20:37 . 2007-12-28 22:16<DIR>d--------C:\Program Files\analyse.exe 2007-12-28 18:22 . 2007-12-29 01:58155,648--a------C:\WINDOWS\system32\NeroCheck .exe 2007-12-28 18:21 . 2007-12-29 01:0415,360--a------C:\WINDOWS\system32\ctfmon .exe 2007-12-28 18:14 . 2007-12-29 01:57118,784--a------C:\WINDOWS\system32\igfxpers .exe 2007-12-28 18:14 . 2007-12-29 01:5698,304--a------C:\WINDOWS\system32\igfxtray .exe 2007-12-28 18:14 . 2007-12-29 01:5677,824--a------C:\WINDOWS\system32\hkcmd .exe 2007-12-28 18:08 . 2007-12-28 18:08<DIR>d--------C:\Program Files\Zuma Deluxe 2007-12-28 18:08 . 2007-12-28 18:39<DIR>d--------C:\Program Files\DivX 2007-12-28 18:08 . 2007-12-28 18:08<DIR>d--------C:\Program Files\Bejeweled 2 Deluxe 2007-12-28 15:45 . 2007-12-28 15:45348,160--a------C:\WINDOWS\system32\RCX158.tmp 2007-12-28 12:06 . 2007-12-28 12:06<DIR>d--------C:\Documents and Settings\inkedeagle\Application Data\Dealio 2007-12-28 12:05 . 2007-12-28 18:08<DIR>d--------C:\Program Files\Snap Visual Search 2007-12-27 19:55 . 2007-12-28 18:09<DIR>d--------C:\I Know Who Killed Me 2007-12-27 17:59 . 2007-12-28 18:09<DIR>d--------C:\the hart break kid 2007-12-26 18:38 . 2007-12-28 21:53143--a------C:\WINDOWS\system32\mcrh.tmp 2007-12-26 17:57 . 2007-12-26 17:5880,097--a------C:\WINDOWS\system32\dcads-remove.exe 2007-12-26 17:44 . 2007-12-29 01:57348,160--a------C:\WINDOWS\system32\ddcyw.exe 2007-12-26 17:33 . 2007-12-29 01:57397,824--a------C:\WINDOWS\system32\SysSFGE.exe 2007-12-26 17:27 . 2007-12-26 17:2781,656--a------C:\gsyhv.exe 2007-12-26 17:27 . 2007-12-26 17:2758,368--a------C:\fjls.exe 2007-12-26 17:27 . 2007-12-26 17:2751,200--a------C:\skaglnck.exe 2007-12-26 17:27 . 2007-12-26 17:277,168--a------C:\uxml.exe 2007-12-24 18:11 . 2007-12-24 18:11<DIR>d--------C:\home of the brave 2007-12-24 17:37 . 2007-12-24 17:37<DIR>d--------C:\eastern promises 2007-12-20 19:19 . 2007-12-20 19:19<DIR>d--------C:\Program Files\Video Piggy 2007-12-20 19:19 . 2007-12-20 19:19<DIR>d--------C:\Program Files\AviSynth 2.5 2007-12-17 14:42 . 2007-12-17 14:42<DIR>d--------C:\Documents and Settings\inkedeagle\Application Data\Skype 2007-12-04 21:32 . 2007-12-04 21:32<DIR>d--------C:\Documents and Settings\LocalService\Application Data\Webroot 2007-12-04 21:32 . 2007-10-01 16:24163,640--a------C:\WINDOWS\system32\drivers\ssidrv.sys 2007-12-04 21:32 . 2007-10-01 16:2423,864--a------C:\WINDOWS\system32\drivers\sskbfd.sys 2007-12-04 21:32 . 2007-10-01 16:2421,816--a------C:\WINDOWS\system32\drivers\sshrmd.sys 2007-12-04 21:32 . 2007-10-01 16:2420,280--a------C:\WINDOWS\system32\drivers\SSFS0BB9.sys 2007-12-04 21:31 . 2007-12-04 21:31<DIR>d--------C:\Program Files\Webroot 2007-12-04 21:31 . 2007-12-04 21:31<DIR>d--------C:\Documents and Settings\inkedeagle\Application Data\Webroot 2007-12-04 21:31 . 2007-12-04 21:31<DIR>d--------C:\Documents and Settings\All Users\Application Data\Webroot 2007-12-04 21:31 . 2007-10-01 16:401,526,072--a------C:\WINDOWS\WRSetup.dll 2007-12-04 20:33 . 2007-12-04 20:33219,136--a------C:\WINDOWS\system32\sysvideo32.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-29 09:58---------d-----wC:\Program Files\QuickTime 2007-12-29 09:57---------d-----wC:\Program Files\Windows Defender 2007-12-29 09:57---------d-----wC:\Program Files\ltmoh 2007-12-29 09:57---------d-----wC:\Program Files\Lexmark X1100 Series 2007-12-29 09:56467,968----a-wC:\WINDOWS\system32\igfxpers.exe 2007-12-29 09:56447,488----a-wC:\WINDOWS\system32\igfxtray.exe 2007-12-29 09:56427,008----a-wC:\WINDOWS\system32\hkcmd.exe 2007-12-29 09:48504,832----a-wC:\WINDOWS\system32\NeroCheck.exe 2007-12-29 02:48---------d-----wC:\Program Files\Google 2007-12-28 01:55---------d-----wC:\Documents and Settings\All Users\Application Data\DVD Shrink 2007-12-27 01:2714,336----a-wC:\WINDOWS\system32\svchost.exe 2007-12-27 01:2714,336----a-wC:\WINDOWS\system32\svchost(2).exe 2007-12-22 00:18---------d-----wC:\Program Files\MySpace 2007-12-11 09:45---------d-----wC:\Program Files\Player Tool 2007-12-05 04:56---------d-----wC:\Documents and Settings\inkedeagle\Application Data\McAfee.com Personal Firewall 2007-12-05 04:52---------d-----wC:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall 2007-11-18 03:13---------d--h--wC:\Program Files\InstallShield Installation Information 2007-11-16 03:40---------d-----wC:\Program Files\AvailaSoft 2007-11-13 10:2520,480----a-wC:\WINDOWS\system32\drivers\secdrv.sys 2007-10-29 22:351,287,680----a-wC:\WINDOWS\system32\quartz.dll 2007-10-28 01:39228,864----a-wC:\WINDOWS\system32\wmasf.dll 2007-10-17 17:2310,752----a-wC:\WINDOWS\system32\WhoisCL.exe 2007-09-25 03:4356,533----a-wC:\WINDOWS\Fonts\vehicle_decals_flames_art.zip 2007-09-07 21:30122,962----a-wC:\WINDOWS\Fonts\the_king_queen_font.zip 2007-08-25 04:4747,360----a-wC:\Documents and Settings\inkedeagle\Application Data\pcouffin.sys 2007-06-03 04:13774,144----a-wC:\Program Files\RngInterstitial.dll 2006-11-06 17:230----a-wC:\Program Files\Common Files\err.log 2003-08-05 19:4153,248----a-wC:\WINDOWS\inf\ap561.exe 2002-11-27 00:2432,768----a-wC:\WINDOWS\inf\Remove561.exe 2002-11-22 23:56118,784----a-wC:\WINDOWS\inf\ShowBmp.exe 2002-10-30 02:0736,864----a-wC:\WINDOWS\inf\Setup8a.exe 2002-10-01 22:43119,798----a-wC:\WINDOWS\inf\spca561.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3DD4EA8-C896-4b95-818F-4E1D04869D99}] 2007-01-24 14:39475136--a------C:\WINDOWS\system32\Deskbar\deskbar.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C0573F85-8B0C-4B55-999A-97823E496A00}] 2007-12-29 01:55344576---------C:\WINDOWS\system32\ddcyw.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-29 01:55] "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2007-12-29 01:55] "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2007-12-29 01:55] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2007-12-29 01:55] "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" [2007-12-29 01:59] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-12-29 01:57] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [] "two junk"="C:\DOCUME~1\INKEDE~1\APPLIC~1\THATCL~1\Mode Size 64.exe" [] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-29 01:56] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TFncKy"="TFncKy.exe" [] "TDispVol"="TDispVol.exe" [2005-03-11 15:03 C:\WINDOWS\system32\TDispVol.exe] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-29 01:56] "MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\MCUPDA~1.EXE" [2007-12-29 01:56] "MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2007-12-29 01:02] "MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MS18BE~4.EXE" [2007-12-29 01:56] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-29 01:56] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-29 01:56] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-29 01:56] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56] "THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2007-12-29 01:56] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-29 01:56] "AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 06:29 C:\WINDOWS\agrsmmsg.exe] "NDSTray.exe"="NDSTray.exe" [] "Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2007-12-29 01:56] "TPSMain"="TPSMain.exe" [2005-05-31 21:00 C:\WINDOWS\system32\TPSMain.exe] "PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [] "SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-12-29 01:56] "dla"="C:\WINDOWS\system32\dla\DLACTRLW.exe" [2007-12-29 01:56] "Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2007-12-29 01:56] "VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2007-12-29 01:48] "OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2007-12-28 18:14] "MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2007-12-29 01:56] "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-12-29 01:56] "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-12-29 01:56] "VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2007-12-28 18:14] "MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2007-12-29 01:56] "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-12-29 01:57] "CFSServ.exe"="CFSServ.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2007-12-29 01:58] "masqform.exe"="C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" [2007-12-29 01:57] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-29 01:57] "Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-12-29 01:57] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-12-29 01:57] "nvchost"="" [] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2007-12-29 01:57] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-29 01:57] "SysSFGE.exe"="C:\WINDOWS\system32\SysSFGE.exe" [2007-12-29 01:57] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard .exe" [2007-12-29 01:58] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-12-29 01:57] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-29 01:56] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-01-09 23:37:47] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04] RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2006-02-15 08:31:42] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows] "load"=C:\WINDOWS\system32\ddcyw.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau C:\WINDOWS\system32\ddcyw R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys [2005-01-12 00:05] R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS [2007-10-01 16:24] S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 17:30] S3 SVRPEDRV;SVRPEDRV;C:\SYSPREP\PEDrv.sys [] S3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32\Drivers\tcusb.sys [2005-11-25 02:38] S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 14:47] . Contents of the 'Scheduled Tasks' folder "2007-12-29 10:00:02 C:\WINDOWS\Tasks\A986B46093B927B0.job" - c:\docume~1\inkede~1\applic~1\thatcl~1\Third Up Heart.exe "2007-12-29 09:57:49 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe "2007-12-27 02:15:18 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job" - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&/ScheduleSweep=wrSpySweeperTrialSweep - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex - C:\ . ************************************************************************ ** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-29 01:57:11 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\system32\SysSFGE .exe 49664 bytes executable C:\WINDOWS\system32\wycdd.ini 6516 bytes C:\WINDOWS\system32\wycdd.ini2 6516 bytes scan completed successfully hidden files: 3 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\WINDOWS\system32\ddcyw.dll -> C:\WINDOWS\system32\TDispVol.dll . Completion time: 2007-12-29 2:02:26 - machine was rebooted . 2007-12-21 01:43:16--- E O F ---
|