Hijack This Log
Code:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:36:06, on 30/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HiJackThis\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {2004652A-4CCE-4EA5-A49E-FEEBF2A2BA8B} - C:\WINDOWS\system32\qomkihi.dll
O2 - BHO: (no name) - {2DA8327F-277A-4112-8615-05CBB1C51C9C} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O2 - BHO: GetRight IE Download Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {55EDB93B-6FCC-2A25-DA97-095A187E5D18} - C:\Program Files\Dnonezsy\rlzoyrvd.dll
O2 - BHO: (no name) - {66CAB10F-77BA-48F8-98BC-09B9F717E840} - C:\WINDOWS\system32\awvts.dll (file missing)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7BAC7AC8-F276-4202-A83B-BD841314D4CF} - C:\WINDOWS\system32\jkhfd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {91B4DDA9-F6CC-4000-90BC-68CD9E5BF6A5} - C:\WINDOWS\system32\vtutu.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [j2211830] rundll32 C:\WINDOWS\system32\j2211830.dll sook
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [srglqnqt] rundll32.exe "C:\Program Files\nmxcvgta\pybunslm.dll",Init
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvzas.dll,startup
O4 - HKLM\..\Run: [ahahslar] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\ahahslar.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ZoiPPE] "C:\Program Files\ZoiPPE\ZoiPPE.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/ActiveX/SpeedUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7FA7A03C-EDAA-4F17-91E1-832F108AF4FA}: NameServer = 62.241.162.200,62.241.163.200
O20 - Winlogon Notify: jkhfd - C:\WINDOWS\system32\jkhfd.dll (file missing)
O20 - Winlogon Notify: jkkjh - C:\WINDOWS\system32\jkkjh.dll (file missing)
O20 - Winlogon Notify: qomkihi - C:\WINDOWS\SYSTEM32\qomkihi.dll
O20 - Winlogon Notify: winexy32 - C:\WINDOWS\SYSTEM32\winexy32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InterBase InterClient Server (InterServer) - InterBase - C:\Program Files\Borland\InterBase\InterClient\bin\interserver.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\mysql\bin\mysqld-nt.exe
--
End of file - 11336 bytes VundoFix.txt Log
Code:
VundoFix V6.5.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.8
Old versions of java are exploitable and should be removed.
Scan started at 11:07:38 30/08/2007
Listing files found while scanning....
C:\windows\system32\aoptavkv.dll
C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\dfhkj.bak2
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\dfhkj.tmp
C:\windows\system32\eiwnwija.dll
C:\WINDOWS\system32\eogskjff.dll
C:\WINDOWS\system32\gqcimibq.dll
C:\windows\system32\hffsvfmd.dll
C:\WINDOWS\system32\hrhdobtd.dll
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\jkkjh.dll
C:\windows\system32\jqalbwcl.dll
C:\windows\system32\qcctiotu.dll
C:\windows\system32\snyauwku.ini
C:\WINDOWS\system32\ukwuayns.dll
C:\WINDOWS\system32\vtutqpm.dll
C:\WINDOWS\system32\vtutu.dll
Beginning removal...
Attempting to delete C:\windows\system32\aoptavkv.dll
C:\windows\system32\aoptavkv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\dfhkj.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dfhkj.bak2
C:\WINDOWS\system32\dfhkj.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\dfhkj.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\dfhkj.tmp
C:\WINDOWS\system32\dfhkj.tmp Has been deleted!
Attempting to delete C:\windows\system32\eiwnwija.dll
C:\windows\system32\eiwnwija.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gqcimibq.dll
C:\WINDOWS\system32\gqcimibq.dll Has been deleted!
Attempting to delete C:\windows\system32\hffsvfmd.dll
C:\windows\system32\hffsvfmd.dll Has been deleted!
Attempting to delete C:\windows\system32\jqalbwcl.dll
C:\windows\system32\jqalbwcl.dll Has been deleted!
Attempting to delete C:\windows\system32\qcctiotu.dll
C:\windows\system32\qcctiotu.dll Has been deleted!
Attempting to delete C:\windows\system32\snyauwku.ini
C:\windows\system32\snyauwku.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ukwuayns.dll
C:\WINDOWS\system32\ukwuayns.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtutu.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.5.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.8
Old versions of java are exploitable and should be removed.
Scan started at 11:19:05 30/08/2007
Listing files found while scanning....
C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\jkkjh.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini Has been deleted!
Performing Repairs to the registry.
Done!
Also a little more info...
After Restarting after the VundoFix thing Nortan popped up and said it had the virus MisLeadApp [edit: another one just popped up, MagicAntiSpy]
Also when the computer starts up a windows pop up comes up saying
RUNDLL (<--thats the title)
Error loading C:\WINDOWS\system32\j2211830.dll
The specified module could not be found
Just going to run that combofix thingy now, will post when it is done
Thanks for your support
Ben
EDIT: ComboFix Logs
Code:
ComboFix 07-08-30.3 - "Benjamin" 2007-08-30 11:43:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.486 [GMT 1:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\newdotnet
C:\Program Files\newdotnet\readme.txt
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bbeeg.bak1
C:\WINDOWS\system32\bbeeg.bak2
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.tmp
C:\WINDOWS\system32\byxuspq.dll
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\khfgecb.dll
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\qomkihi.dll
C:\WINDOWS\system32\stvwa.bak1
C:\WINDOWS\system32\stvwa.ini
C:\WINDOWS\system32\stvwa.ini2
C:\WINDOWS\system32\stvwa.tmp
C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.bak2
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\vtusnrvb.dll
C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\winexy32.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\ybadd.bak1
C:\WINDOWS\system32\ybadd.bak2
C:\WINDOWS\system32\ybadd.ini
C:\WINDOWS\system32\ybadd.ini2
C:\WINDOWS\system32\ybadd.tmp
I:\Autorun.inf
J:\Autorun.inf
K:\Autorun.inf
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NPF
-------\nm
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-30 )))))))))))))))))))))))))))))))
2007-08-30 11:42 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-30 11:07 <DIR> d-------- C:\VundoFix Backups
2007-08-30 11:01 <DIR> d-------- C:\HiJackThis
2007-08-29 16:45 122,880 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\ahahslar.dll
2007-08-29 16:45 <DIR> d-------- C:\WINDOWS\system32\ogvhbfee
2007-08-29 16:45 <DIR> d-------- C:\Program Files\Dnonezsy
2007-08-25 16:17 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-25 16:11 93,184 --a------ C:\WINDOWS\system32\drvzas.dll
2007-08-10 13:29 <DIR> d-------- C:\Program Files\nmxcvgta
2007-08-06 13:27 <DIR> d-------- C:\Program Files\Driving Test Success 2007-2008
2007-08-06 13:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Driving Test Success
2007-08-03 21:28 <DIR> d-------- C:\TempDVD
2007-08-03 21:27 <DIR> d-------- C:\Program Files\dvdSanta
2007-08-03 11:13 <DIR> d-------- C:\Program Files\GetRight
2007-07-31 17:28 <DIR> d-------- C:\DOCUME~1\BENJAM~1\.zone1511
2007-07-31 17:20 <DIR> d-------- C:\Program Files\ZoiPPE
2007-07-31 00:33 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-07-30 22:33 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-07-22 10:27 <DIR> d-------- C:\Program Files\Siber Systems
2007-07-13 10:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\GlobalSCAPE
2007-07-08 21:01 <DIR> d-------- C:\Program Files\IMVU
2007-07-08 16:19 <DIR> d-------- C:\Program Files\DIFX
2007-07-08 16:19 <DIR> d-------- C:\Program Files\Common Files\ComponentOne
2007-07-08 16:10 <DIR> d-------- C:\Program Files\Fomine NetSend
2007-07-05 20:55 <DIR> d-------- C:\DOCUME~1\BENJAM~1\APPLIC~1\CoreFTP
2007-07-03 21:18 <DIR> d-------- C:\Program Files\Vextractor Demo 3.80
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-30 11:52 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-08-29 20:51 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-27 23:42 --------- d-------- C:\DOCUME~1\BENJAM~1\APPLIC~1\uTorrent
2007-08-04 10:39 --------- d-------- C:\Program Files\Cheat Engine
2007-08-03 11:13 --------- d-------- C:\DOCUME~1\BENJAM~1\APPLIC~1\GetRightToGo
2007-07-31 19:53 --------- d-------- C:\DOCUME~1\BENJAM~1\APPLIC~1\LimeWire
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-13 10:38 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-13 10:38 --------- d-------- C:\Program Files\GlobalSCAPE
2007-06-29 22:52 --------- d-------- C:\DOCUME~1\BENJAM~1\APPLIC~1\SmartFTP
2007-06-29 19:51 --------- d-------- C:\Program Files\Scriptocean
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 14:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-03 14:08 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2004-08-04 12:00:00 94,784 -csh--w C:\WINDOWS\twain.dll
2004-08-04 12:00:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-04 12:00:00 1,028,096 --sh--w C:\WINDOWS\system32\mfc42.dll
2004-08-04 12:00:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 12:00:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2DA8327F-277A-4112-8615-05CBB1C51C9C}]
C:\WINDOWS\system32\jkkjh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{55EDB93B-6FCC-2A25-DA97-095A187E5D18}]
2007-08-29 16:45 122880 --a------ C:\Program Files\Dnonezsy\rlzoyrvd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66CAB10F-77BA-48F8-98BC-09B9F717E840}]
C:\WINDOWS\system32\awvts.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BAC7AC8-F276-4202-A83B-BD841314D4CF}]
C:\WINDOWS\system32\jkhfd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 05:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-02-07 23:39]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45]
"srglqnqt"="C:\Program Files\nmxcvgta\pybunslm.dll" [2007-08-10 13:29]
"ahahslar"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\ahahslar.dll" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-09-24 17:22]
"RamBooster"="C:\Program Files\RamBooster 2.0\Rambooster.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-03 11:29]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"ZoiPPE"="C:\Program Files\ZoiPPE\ZoiPPE.exe" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfd]
C:\WINDOWS\system32\jkhfd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjh]
C:\WINDOWS\system32\jkkjh.dll
R0 isdnlink;isdnlink;C:\WINDOWS\system32\DRIVERS\linkisdn.sys
R0 SLyxFltr;TI StorageLynx Device Alignment Filter;C:\WINDOWS\system32\DRIVERS\SLyxFltr.sys
R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys
R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 PRISM_USB;D-Link Air Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\PRISMUSB.sys
R3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys
S3 CEDRIVER52;CEDRIVER52;\??\C:\Program Files\Cheat Engine\dbk32.sys
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys
S3 InterServer;InterBase InterClient Server;C:\Program Files\Borland\InterBase\InterClient\bin\interserver.exe
S3 kqemu;KQEMU virtualisation module for QEMU;C:\WINDOWS\system32\DRIVERS\kqemu.sys
S3 PAC207;CamMaestro 3.01 DU PC Camera;C:\WINDOWS\system32\DRIVERS\pfc027.sys
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\mysql\bin\mysqld-nt.exe" "--defaults-file=C:\Program Files\wamp\mysql\my.ini" wampmysqld
S3 wanlink;wanlink;C:\WINDOWS\system32\DRIVERS\wanlink.sys
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-08-27 22:42:51 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Benjamin.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-30 12:04:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-30 12:08:10 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-30 12:07
--- E O F ---
ComboFix-quarantined-files.txt Code:
1995-12-22 19:16 432 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\CFX32.LIC.vir
1996-06-10 23:24 307200 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\CFX32.OCX.vir
2002-03-02 05:10 53299 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\pthreadVC.dll.vir
2003-04-04 15:54 208896 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\wpcap.dll.vir
2003-04-04 16:03 57344 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\packet.dll.vir
2003-04-04 16:07 30336 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\npf.sys.vir
2006-11-16 11:33 3522 --a--c--- C:\Qoobox\Quarantine\C\Program Files\NewDotNet\readme.txt.vir
2007-02-09 22:25 27 --a------ C:\Qoobox\Quarantine\J\autorun.inf.vir
2007-02-09 23:25 27 --a------ C:\Qoobox\Quarantine\K\autorun.inf.vir
2007-02-19 21:21 30 --a------ C:\Qoobox\Quarantine\I\autorun.inf.vir
2007-06-02 09:28 1093836 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\stvwa.bak1.vir
2007-06-03 00:13 1095054 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\stvwa.tmp.vir
2007-06-03 10:33 1095250 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\stvwa.ini.vir
2007-06-03 11:01 1095526 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\stvwa.ini2.vir
2007-07-08 21:23 15399 --a------ C:\Qoobox\Quarantine\C\ComboFix\FProps.vbs.vir
2007-07-13 10:22 20992 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\winexy32.dll.vir
2007-07-13 10:27 6369 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\bbeeg.bak1.vir
2007-07-13 20:58 48947 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\bbeeg.tmp.vir
2007-07-13 22:11 52938 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\bbeeg.ini.vir
2007-07-14 19:01 1363574 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\bbeeg.bak2.vir
2007-07-14 19:27 1364355 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\bbeeg.ini2.vir
2007-07-15 19:27 1364800 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ybadd.tmp.vir
2007-07-15 23:13 1364800 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ybadd.ini.vir
2007-07-30 15:49 69184 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\vtusnrvb.dll.vir
2007-08-01 17:12 1076520 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ybadd.bak2.vir
2007-08-01 17:12 1076537 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ybadd.bak1.vir
2007-08-01 20:56 1130404 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ybadd.ini2.vir
2007-08-25 16:11 43542 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qomkihi.dll.vir
2007-08-25 16:16 298080 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\vtutu.dll.vir
2007-08-28 11:56 1006650 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ututv.bak2.vir
2007-08-29 11:56 1004923 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ututv.bak1.vir
2007-08-29 12:00 156 --a------ C:\Qoobox\Quarantine\C\WINDOWS\cookies.ini.vir
2007-08-29 15:24 43542 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\byxuspq.dll.vir
2007-08-29 16:45 262144 --a------ C:\Qoobox\Quarantine\C\Program Files\SecCenter\scprot4.exe.vir
2007-08-30 11:12 1057468 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ututv.ini.vir
2007-08-30 11:44 43542 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\khfgecb.dll.vir
2007-08-30 11:58 1326 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.cf
2007-08-30 11:58 2354 --a------ C:\Qoobox\Quarantine\Registry_backups\services_NPF.reg.cf
2007-08-30 11:58 352 --a------ C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf
2007-08-30 11:59 157 --a------ C:\Qoobox\Quarantine\catchme.log
2007-08-30 11:59 23512 --a------ C:\Qoobox\Quarantine\catchme2007-08-30_120432.54.zip
2007-08-30 12:07 816162 --a------ C:\Qoobox\snapshot_2007-08-30_120713.46.cf
Folder PATH listing
Volume serial number is 7CA0-C620
C:\QOOBOX
| snapshot_2007-08-30_120713.46.cf
|
\---Quarantine
| catchme.log
| catchme2007-08-30_120432.54.zip
|
+---C
| +---ComboFix
| | FProps.vbs.vir
| |
| +---Program Files
| | +---NewDotNet
| | | readme.txt.vir
| | |
| | \---SecCenter
| | scprot4.exe.vir
| |
| \---WINDOWS
| | cookies.ini.vir
| |
| \---system32
| | bbeeg.bak1.vir
| | bbeeg.bak2.vir
| | bbeeg.ini.vir
| | bbeeg.ini2.vir
| | bbeeg.tmp.vir
| | byxuspq.dll.vir
| | CFX32.LIC.vir
| | CFX32.OCX.vir
| | khfgecb.dll.vir
| | packet.dll.vir
| | pthreadVC.dll.vir
| | qomkihi.dll.vir
| | stvwa.bak1.vir
| | stvwa.ini.vir
| | stvwa.ini2.vir
| | stvwa.tmp.vir
| | ututv.bak1.vir
| | ututv.bak2.vir
| | ututv.ini.vir
| | vtusnrvb.dll.vir
| | vtutu.dll.vir
| | winexy32.dll.vir
| | wpcap.dll.vir
| | ybadd.bak1.vir
| | ybadd.bak2.vir
| | ybadd.ini.vir
| | ybadd.ini2.vir
| | ybadd.tmp.vir
| |
| \---drivers
| npf.sys.vir
|
+---I
| autorun.inf.vir
|
+---J
| autorun.inf.vir
|
+---K
| autorun.inf.vir
|
\---Registry_backups
LEGACY_NPF.reg.cf
services_nm.reg.cf
services_NPF.reg.cf