Stephen1001
Newbie


Posts: 11
|
 |
Re: I got ALOT of trojans
« Reply #5 on: Jun 11th, 2008, 2:54pm » |
Quote Modify
|
ComboFix 08-06-10.5 - Stephen 2008-06-11 13:45:43.1 - NTFSx86 Running from: C:\Documents and Settings\Stephen\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\Starware C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindIt.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindItHot.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\findithotxp.png C:\Documents and Settings\All Users\Application Data\Starware\buttons\finditxp.png C:\Documents and Settings\All Users\Application Data\Starware\buttons\Highlight.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\HighlightHot.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlighthotxp.png C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlightxp.png C:\Documents and Settings\All Users\Application Data\Starware\buttons\jokesearch.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\logo.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\logoxp.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\pranks.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\smiley.bmp C:\Documents and Settings\All Users\Application Data\Starware\buttons\smileyxp.png C:\Documents and Settings\All Users\Application Data\Starware\contexts\error.xml C:\Documents and Settings\All Users\Application Data\Starware\contexts\related.xml C:\Documents and Settings\All Users\Application Data\Starware\contexts\travel.xml C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml.backup C:\Documents and Settings\All Users\Application Data\Starware\Tem525.tmp C:\Documents and Settings\Stephen\Application Data\SpamBlockerUtility_Icons C:\Documents and Settings\Stephen\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico C:\Documents and Settings\Stephen\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico C:\Documents and Settings\Stephen\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico C:\WINDOWS\system32\d.txt C:\WINDOWS\system32\drivers\fad.sys C:\WINDOWS\system32\windows.txt C:\WINDOWS\Tasks\SysFile.brk . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NETWM -------\Service_netwm ((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 ))))))))))))))))))))))))))))))) . 2008-06-11 13:36 . 2008-06-11 13:36<DIR>d--------C:\Program Files\Trend Micro 2008-06-11 00:14 . <DIR>C:\WINDOWS\LastGood.Tmp 2008-06-10 23:13 . 2008-06-10 23:13<DIR>d--------C:\Documents and Settings\Stephen\Application Data\TrojanHunter 2008-06-10 20:10 . 2008-06-10 20:10<DIR>d--------C:\Program Files\TrojanHunter 5.0 2008-06-09 12:39 . 2006-05-25 15:52162,304--a------C:\WINDOWS\system32\ztvunrar36.dll 2008-06-09 12:39 . 2003-02-02 20:06153,088--a------C:\WINDOWS\system32\UNRAR3.dll 2008-06-09 12:39 . 2005-08-26 01:5077,312--a------C:\WINDOWS\system32\ztvunace26.dll 2008-06-09 12:39 . 2002-03-06 01:0075,264--a------C:\WINDOWS\system32\unacev2.dll 2008-06-09 12:39 . 2006-06-19 13:0169,632--a------C:\WINDOWS\system32\ztvcabinet.dll 2008-06-09 12:38 . 2008-06-09 12:40<DIR>d--------C:\Program Files\Trojan Remover 2008-06-09 12:38 . 2008-06-09 12:38<DIR>d--------C:\Documents and Settings\Stephen\Application Data\Simply Super Software 2008-06-09 12:38 . 2008-06-09 12:38<DIR>d--------C:\Documents and Settings\All Users\Application Data\Simply Super Software 2008-06-08 09:57 . 2008-06-08 09:57<DIR>d--------C:\Documents and Settings\LocalService\Application Data\AdobeUM 2008-06-08 09:45 . 2008-06-08 09:45<DIR>d--------C:\Program Files\Avira 2008-06-08 09:45 . 2008-06-08 09:45<DIR>d--------C:\Documents and Settings\All Users\Application Data\Avira 2008-06-07 12:18 . 2008-06-07 12:18<DIR>d--------C:\Program Files\Common Files\plugin 2008-06-05 17:27 . 2008-06-05 17:27<DIR>d--------C:\Documents and Settings\Stephen\Application Data\Acreon . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-11 19:04---------d-----wC:\Documents and Settings\Stephen\Application Data\Xfire 2008-06-11 19:00---------d-s---wC:\Program Files\Xfire 2008-06-11 18:56---------d-----wC:\Program Files\Microsoft AntiSpyware 2008-06-11 04:50---------d-----wC:\Program Files\Diablo II 2008-06-11 04:3543,520----a-wC:\WINDOWS\system32\CmdLineExt03.dll 2008-06-11 04:33249,856------wC:\WINDOWS\Setup1.exe 2008-06-11 04:3273,216----a-wC:\WINDOWS\ST6UNST.EXE 2008-06-10 15:38---------d-----wC:\Program Files\AltPayments 2008-06-09 17:54---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP 2008-06-09 17:43---------d-----wC:\Program Files\Blink 2008-06-08 03:31---------d-----wC:\Documents and Settings\Stephen\Application Data\Ventrilo 2008-06-08 02:15---------d-----wC:\Program Files\World of Warcraft 2008-05-08 21:29---------d-----wC:\Program Files\iTunes 2008-05-08 21:29---------d-----wC:\Program Files\iPod 2008-05-08 21:00---------d-----wC:\Program Files\Safari 2008-05-04 03:3221,840----atwC:\WINDOWS\system32\SIntfNT.dll 2008-05-04 03:3217,212----atwC:\WINDOWS\system32\SIntf32.dll 2008-05-04 03:3212,067----atwC:\WINDOWS\system32\SIntf16.dll 2008-05-04 03:1594,208----a-wC:\WINDOWS\DIIUnin.exe 2008-05-04 03:152,829----a-wC:\WINDOWS\DIIUnin.pif 2008-04-30 21:41---------d-----wC:\Program Files\QuickTime 2008-04-30 21:27---------d-----wC:\Program Files\Apple Software Update 2008-03-27 08:12151,583----a-wC:\WINDOWS\system32\msjint40.dll 2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys 2006-01-16 02:5871----a-wC:\Documents and Settings\Stephen\chars.dat 2006-01-16 02:5828----a-wC:\Documents and Settings\Stephen\settings.dat 2006-01-12 15:0120,921,040----a-wC:\Program Files\AdbeRdr705_enu_full.exe 2006-01-12 14:587,050,552----a-wC:\Program Files\psa30se_en_us.exe 2006-01-12 14:57762,512----a-wC:\Program Files\ytb612_efgsip.exe 2005-11-16 13:4520,798,256----a-wC:\Program Files\AdbeRdr70_enu_full.exe 2005-11-16 13:426,811,904----a-wC:\Program Files\psa2011se_us.exe 2005-11-16 13:41494,704----a-wC:\Program Files\ytb02_efgsip.exe 2002-09-03 16:3930----a-wC:\Documents and Settings\Stephen\08770877.dat 2005-01-28 04:513,547--sha-wC:\WINDOWS\tnjrn.dat 2005-01-19 13:153,547--sha-wC:\WINDOWS\wtxhe.dat 2005-01-09 12:174,402--sha-wC:\WINDOWS\system32\asgcr.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 06:56 68856] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 11:15 50528] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360] "AOL Fast Start"="C:\Program Files\America Online 9.0\AOL.exe" [2005-07-12 07:17 50776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 14:16 5058560] "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-12-16 20:24 26112] "MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2003-08-27 12:00 245760] "MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2003-08-21 19:10 180224] "VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2003-08-17 22:50 163840] "VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2003-08-08 19:02 122880] "HostManager"="C:\Program Files\Common Files\AOL\1115819366\ee\AOLSoftware.exe" [2006-09-25 19:52 50736] "AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216] "cuaagt83"="C:\WINDOWS\System32\cuaagt83.exe" [ ] "gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 13:12 473928] "nwiz"="nwiz.exe" [2003-10-06 14:16 741376 C:\WINDOWS\system32\nwiz.exe] "BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496] "XJNY Agent"="C:\WINDOWS\System32\Sys32\XJNY.exe" [ ] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "AOLAspSunset2"="C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe" [ ] "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06 11776] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401] "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-06-03 20:33 878672] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-03-25 19:08 1047712] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696] Billminder.lnk - C:\QUICKENW\BILLMIND.EXE [2004-12-16 21:05:24 36864] Event Planner Reminders Tray Icon.lnk - C:\Sierra\Planner\PLNRnote.exe [2005-01-08 10:54:17 172032] HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472] HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{303F44D5-5FEA-4509-ABDE-5E00C3F2125A}"= C:\WINDOWS\System32\hun32.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ctmp3"= C:\WINDOWS\System32\ctmp3.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= *Newly Created Service* - ALG . Contents of the 'Scheduled Tasks' folder "2008-06-05 13:39:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-06-11 18:55:46 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (STEPHEN-2I9YCIR-Stephen).job" - c:\program files\mcafee.com\vso\mcmnhdlr.exe "2008-06-11 19:28:00 C:\WINDOWS\Tasks\McAfee.com Update Check (STEPHEN-2I9YCIR-Stephen).job" - C:\PROGRA~1\mcafee.com\agent\mcupdate.ex - C:\PROGRA~1\mcafee.com\agent "2008-06-11 14:32:48 C:\WINDOWS\Tasks\rpc.job" - C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe . ************************************************************************ ** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-11 13:57:18 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\America Online 9.0\waol.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\AOL\1115819366\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe C:\Program Files\America Online 9.0\shellmon.exe . ************************************************************************ ** . Completion time: 2008-06-11 14:30:20 - machine was rebooted ComboFix-quarantined-files.txt 2008-06-11 19:30:16 Pre-Run: 11,482,484,736 bytes free Post-Run: 13,934,428,160 bytes free 217--- E O F ---2008-06-10 05:04:46
|