gurdeep
Newbie


Posts: 29
|
 |
Re: HJT log, Please check ASAP.
« Reply #2 on: Apr 21st, 2008, 11:33pm » |
Quote Modify
|
ComboFix 08-04-20.2 - computer 2008-04-21 20:33:40.2 - NTFSx86 Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.1166 [GMT -7:00] Running from: C:\Users\computer\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\Windows\Downloaded Program Files\setup.inf C:\Windows\System32\AaJmnnnn.ini C:\Windows\System32\AaJmnnnn.ini2 C:\Windows\system32\ddcAtrsp.dll C:\Windows\system32\gEwvvvwW.dll C:\Windows\System32\LoqsvGgh.ini C:\Windows\System32\LoqsvGgh.ini2 C:\Windows\System32\onWwvyxx.ini C:\Windows\System32\onWwvyxx.ini2 C:\Windows\System32\RrYGPVut.ini C:\Windows\System32\RrYGPVut.ini2 C:\Windows\system32\tuVPGYrR.dll C:\Windows\System32\xGMWayay.ini C:\Windows\System32\xGMWayay.ini2 . ((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 ))))))))))))))))))))))))))))))) . 2082-07-02 16:30 . 2082-07-02 15:34 <DIR> d-------- C:\Windows\Panther 2082-07-02 16:30 . 2008-01-09 22:07 <DIR> d--hs---- C:\Boot 2082-07-02 16:30 . 2008-01-09 20:30 443,912 -rahs---- C:\bootmgr 2082-07-02 15:32 . 2008-04-13 14:11 <DIR> d-------- C:\Windows\Debug 2008-04-18 19:01 . 2008-04-19 23:42 654 ---hs---- C:\Windows\System32\qjkqtnhd.ini 2008-04-17 19:48 . 2008-04-17 19:52 237,057 --a------ C:\Windows\System32\Office [Keygen].exe 2008-04-16 22:10 . 2008-04-16 22:10 <DIR> d-------- C:\Program Files\Alwil Software 2008-04-16 22:10 . 2008-03-29 11:32 50,768 --a------ C:\Windows\System32\drivers\aswMonFlt.sys 2008-04-08 17:36 . 2008-02-28 21:16 2,027,008 --a------ C:\Windows\System32\win32k.sys 2008-04-08 17:35 . 2008-02-14 16:19 944,184 --a------ C:\Windows\System32\winload.exe 2008-04-08 17:35 . 2008-02-18 22:10 620,088 --a------ C:\Windows\System32\ci.dll 2008-04-08 17:35 . 2008-02-28 23:39 371,712 --a------ C:\Windows\System32\srcore.dll 2008-04-08 17:35 . 2008-02-28 23:38 313,856 --a------ C:\Windows\System32\rstrui.exe 2008-04-08 17:35 . 2008-02-28 23:39 40,960 --a------ C:\Windows\System32\srclient.dll 2008-04-08 17:35 . 2008-02-28 23:51 19,000 --a------ C:\Windows\System32\kd1394.dll 2008-04-08 17:35 . 2008-02-28 23:38 16,384 --a------ C:\Windows\System32\srdelayed.exe 2008-04-08 17:35 . 2008-02-28 23:34 7,168 --a------ C:\Windows\System32\f3ahvoas.dll 2008-04-08 17:35 . 2008-02-28 23:35 6,656 --a------ C:\Windows\System32\kbd106n.dll 2008-04-08 16:58 . 2008-04-08 16:58 <DIR> d-------- C:\Users\dad\AppData\Roaming\vlc 2008-04-03 23:02 . 2008-04-03 23:02 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{8f2119c1-020c-11dd-b3 9e-0015f294eb8b}.TMContainer00000000000000000002.regtrans-ms 2008-04-03 23:02 . 2008-04-03 23:02 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{8f2119c1-020c-11dd-b3 9e-0015f294eb8b}.TMContainer00000000000000000001.regtrans-ms 2008-04-03 23:02 . 2008-04-03 23:02 65,536 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{8f2119c1-020c-11dd-b3 9e-0015f294eb8b}.TM.blf 2008-03-27 00:04 . 2008-03-27 00:04 268 --ah----- C:\sqmdata06.sqm 2008-03-27 00:04 . 2008-03-27 00:04 244 --ah----- C:\sqmnoopt06.sqm 2008-03-26 23:16 . 2008-04-08 17:08 <DIR> d-------- C:\Users\dad\AppData\Roaming\DivX 2008-03-26 10:17 . 2008-03-26 10:17 <DIR> d-------- C:\Users\dad\AppData\Roaming\Apple Computer 2008-03-24 22:41 . 2008-04-11 20:38 <DIR> d-------- C:\Program Files\LimeWire Acceleration Patch . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-17 03:23 --------- d-----w C:\Program Files\BitComet 2008-04-13 20:51 --------- d-----w C:\Users\computer\AppData\Roaming\LimeWire 2008-04-12 00:44 --------- d-----w C:\Program Files\Windows Mail 2008-03-17 13:00 --------- d-----w C:\Program Files\Free WMA to MP3 Converter 2008-03-16 07:19 --------- d-----w C:\ProgramData\Lavasoft 2008-03-16 07:18 --------- d-----w C:\Program Files\Lavasoft 2008-03-16 07:17 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-03-15 05:30 --------- d-----w C:\Program Files\PokerStars 2008-03-10 05:30 --------- d-----w C:\Program Files\Common Files\xing shared 2008-03-10 05:29 --------- d-----w C:\Program Files\Common Files\Real 2008-03-06 07:02 --------- d-----w C:\Program Files\Smallvideosoft 2008-03-03 00:32 --------- d-----w C:\Users\dad\AppData\Roaming\Talkback 2008-02-26 07:46 --------- d-----w C:\ProgramData\DVD Shrink 2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll 2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2008-02-14 00:24 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-02-14 00:10 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-02-14 00:10 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-02-14 00:09 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-02-14 00:09 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-02-14 00:09 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll 2008-02-14 00:09 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-02-14 00:08 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-02-14 00:08 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-02-14 00:08 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll 2008-02-14 00:08 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-02-14 00:08 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-02-14 00:08 1,686,528 ----a-w C:\Windows\System32\gameux.dll 2007-08-29 22:37 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 20:34 1232896] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27 153136] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352] "WeatherEye"="C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2007-09-26 15:14 4484816] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:33 201728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-02 21:33 1006264] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016] "SoundMan"="SOUNDMAN.EXE" [2007-07-02 17:54 598016 C:\Windows\SOUNDMAN.EXE] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136] "THGuard"="C:\Program Files\TrojanHunter 4.7\THGuard.exe" [2007-06-23 00:19 1102848] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15 271672] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048] "PC Pitstop Optimize2 Reminder"="C:\Program Files\PCPitstop\Optimize2\Reminder.exe" [ ] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 10:53 780312] "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 10:52 505368] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-09 22:27 185896] "BM1b7b21a5"="Rundll32.exe" [2006-11-02 02:45 44544 C:\Windows\System32\rundll32.exe] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-06-21 18:57 5355832] C:\Users\computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-07-26 14:08:21 147456] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048] Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872] Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-02 04:29:26 180224] KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "LogonHoursAction"= 2 (0x2) "DontDisplayLogonHoursWarnings"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 14:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 14:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{B02FDFEF-FA55-4AF3-AF6E-1034D7A87F43}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{A29F60A8-18C8-44FF-94E3-F73D934CD7DC}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{975DB941-C072-4AE0-BD45-44B524572430}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{62710C88-003B-4B3A-B0BA-4EA34C24FBB8}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{5A5FD5AA-4941-445A-BF48-D7C4BCA8BEA8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{A083600D-C6B7-4DDB-9154-6415F7B73FE1}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{840AC66F-5CFF-450F-B0A6-EF09532854B1}"= UDP:14592:BitComet 14592 TCP "{32FBD3AA-494E-4950-8A34-073F63A3DF99}"= TCP:14592:BitComet 14592 UDP "{3E7BD79A-75BE-4E07-B25D-9038BE9FFE58}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{D0A7D053-720A-432C-9B96-B785817E7FC8}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire "{A15C815D-C774-4CED-AA94-7A44D9D83939}"= UDP:25242:BitComet 25242 TCP "{75451C9A-8861-43ED-888B-337BD719380E}"= TCP:25242:BitComet 25242 UDP "{8FB590C1-09C7-4467-B4F7-45B810C887FF}"= UDP:C:\Program Files\PPLive\PPLive.exe PLive "{DE14D94F-318E-46E9-AF39-B89E16040893}"= TCP:C:\Program Files\PPLive\PPLive.exe PLive "{0175D907-6C60-4051-A63D-8C1920D4B28D}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{C8B0C98E-7F1E-4769-9FCF-6BB68327BFC4}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{22443B45-8FE7-4E8F-84BB-D5BE7577FD11}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{E8412761-5762-4D93-BD90-A55F020CDE37}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype "{D24DE6E4-9657-4F2F-B5B8-8A9BF42318FF}"= UDP:25506:BitComet 25506 TCP "{CB48C4D7-C0C8-42BA-BD1A-22E6A9896B9A}"= TCP:25506:BitComet 25506 UDP "{BABE57CF-BE59-47A9-86C6-4C6FD52E34E6}"= UDP:25148:BitComet 25148 TCP "{51396CAB-D7DD-4213-ABE3-8FE83EDE66B2}"= TCP:25148:BitComet 25148 UDP "{FB20FF3B-A3A5-4B06-BB29-5640C16F60EC}"= UDP:53521:BitComet 53521 TCP "{7A641D84-A5AD-4940-B422-A5E13C424B76}"= TCP:53521:BitComet 53521 UDP "{5A0E1B3A-FB3A-415B-A0CA-29497765B52A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{38473D1B-ABE9-4667-87CD-E8768619CB3F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\Windows\system32\Drivers\SSFS0BB8.SYS [2007-06-21 18:43] R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 11:31] R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071220.001\IDSvi x86.sys [2007-11-06 09:07] R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 11:35] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 11:32] R2 vistatalk;vistatalk;C:\Windows\system32\vistatalk.sys [2007-07-02 22:40] R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 15:32] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 00:30] S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 00:30] S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys [2007-11-02 14:36] S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRIVERS\motccgpfl.sys [2007-01-22 19:33] S3 MotDev;Motorola Inc. USB Device;C:\Windows\system32\DRIVERS\motodrv.sys [2007-10-10 16:41] S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2007-10-02 15:53] S3 USB_RNDIS_XP;Linksys Wireless-G USB Network Adapter with SpeedBooster Driver;C:\Windows\system32\DRIVERS\usb8023.sys [2006-11-02 01:57] S4 BOHCI;BOHCI;C:\Windows\system32\drivers\BOHCI.sys [2004-02-04 13:35] S4 BUHCI;BUHCI;C:\Windows\system32\drivers\BUHCI.sys [2004-02-04 13:35] S4 BUSBD;BUSBD;C:\Windows\system32\drivers\BUSBD.sys [2004-02-04 13:35] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-04-22 02:59:59 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - computer.job" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK: . ************************************************************************ ** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-21 20:36:47 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . Completion time: 2008-04-21 20:38:22 ComboFix-quarantined-files.txt 2008-04-22 03:38:04 Pre-Run: 96,651,231,232 bytes free Post-Run: 96,610,390,016 bytes free 215 --- E O F --- 2008-04-18 00:06:08
|
|
IP Logged |
|
|
|