Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis

 |  Print Thread
Andybib
regular


Reg'd: Thu
Posts: 48
IE ad. popups(again)+ BHO activity in IE.
      Wed Apr 30 2008 08:16 PM

Hi guys,this is becoming an all too regular occurance,even after following instructions from last postings on how to avoid getting infected!I am running xp sp2 Home on Advent 7082,40GBHDD,1.12GB RAM with Nort I,S.,Spy Guard and Blaster,running Adaware + Spybot occasionally,after disabling NIS in case of conflicts,same for AVG,anti root kit.My problem is regularly getting warnings of new BHOs in IE,plus pop up ads telling me to protect my pivacy.The final straw was an ad.telling me i had so much porn stored on my lappy with visuals,needless to say the missus not very happy,although teenage son finds quite amusing.Please help,i`ve ran several HTs but the logs dont seem to reveal much(in my laymans opinion.I`ve posted a HT log + a Combo f.log,hope this throws some light on the subject.Thanks again in advance,ANDYB ;Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:46:07, on 30/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1208406252796
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6012 bytes
ComboFix 08-04-26.3 - Andy 2008-04-30 19:55:00.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.686 [GMT 1:00]
Running from: C:\Documents and Settings\Andy\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\jkkJdDvu.dll
C:\WINDOWS\system32\jkkLFurr.dll
C:\WINDOWS\system32\uvDdJkkj.ini
C:\WINDOWS\system32\uvDdJkkj.ini2

.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))
.

2008-04-30 19:01 . 2008-04-30 19:01 53,312 --a------ C:\WINDOWS\system32\htolfdji.dll
2008-04-30 17:19 . 2008-04-30 17:19 <DIR> d-------- C:\Program Files\UseNeXT
2008-04-29 20:33 . 2008-04-29 22:00 <DIR> d-------- C:\Program Files\coverXP
2008-04-29 20:09 . 2008-04-29 20:09 <DIR> d-------- C:\spoolerlogs
2008-04-29 18:05 . 2008-04-29 18:05 53,312 --a------ C:\WINDOWS\system32\lveaedgc.dll
2008-04-29 18:03 . 2008-04-29 18:03 0 --a------ C:\WINDOWS\BM7fbecf2c.xml
2008-04-27 09:48 . 2008-04-27 09:48 <DIR> d-------- C:\VundoFix Backups
2008-04-27 07:41 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-04-27 04:21 . 2008-04-27 04:21 87,608 --a------ C:\Documents and Settings\Andy\Application Data\inst.exe
2008-04-27 02:43 . 2008-04-27 02:50 6,211 --a------ C:\WINDOWS\system32\EPPICResdb0000
2008-04-27 02:43 . 2008-04-27 02:50 117 --a------ C:\WINDOWS\system32\EPPICResdb
2008-04-27 00:46 . 2008-04-27 00:46 0 --a------ C:\WINDOWS\JCMkr32.INI
2008-04-22 19:35 . 2008-04-22 19:35 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Desktopicon
2008-04-20 18:30 . 2008-04-20 19:04 <DIR> d-------- C:\temp
2008-04-19 22:23 . 2008-04-19 22:23 0 --a------ C:\WINDOWS\tosOBEX.INI
2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-04-19 22:06 . 2008-04-19 22:06 <DIR> d-------- C:\Program Files\Toshiba
2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a--c--- C:\WINDOWS\system32\dllcache\bthmodem.sys
2008-04-19 18:42 . 2008-04-25 05:44 18,413 --a------ C:\Documents and Settings\Andy\Application Data\NMM-MetaData.db
2008-04-19 11:49 . 2008-04-19 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TomTom
2008-04-19 11:48 . 2008-04-19 11:48 <DIR> d-------- C:\Program Files\TomTom HOME
2008-04-19 11:47 . 2008-04-19 11:47 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\InstallShield
2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-04-19 10:41 . 2008-04-19 10:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-04-19 10:41 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-19 10:41 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-04-19 10:41 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-04-19 10:41 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-04-19 10:41 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-04-17 18:43 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-17 18:43 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-15 05:58 . 2008-04-15 05:58 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-13 02:36 . 2008-04-14 20:43 153 --a------ C:\WINDOWS\wininit.ini
2008-04-13 01:29 . 2008-04-13 01:29 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 00:29 . 2008-04-13 00:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-11 18:59 . 2008-04-11 18:59 <DIR> d-------- C:\Setup
2008-04-11 18:54 . 2008-04-27 10:49 <DIR> d-------- C:\Program Files\AutoCAD Civil 3D 2008
2008-04-11 18:54 . 2008-04-11 18:54 <DIR> d-------- C:\Civil 3D Projects
2008-04-11 17:33 . 2008-04-13 19:03 <DIR> d-------- C:\Program Files\PowerISO
2008-04-10 13:44 . 2008-04-10 13:44 <DIR> d-------- C:\WINDOWS\WinRAR
2008-04-06 18:49 . 2008-04-06 18:53 <DIR> d-------- C:\Program Files\AutoCAD 2009
2008-04-06 18:47 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-04-06 18:36 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-04-06 16:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-04-06 16:00 . 2008-04-06 16:00 <DIR> d-------- C:\Program Files\MSBuild
2008-04-06 15:58 . 2008-04-26 11:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-04-06 15:57 . 2008-04-06 15:57 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-04-06 15:57 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-04-06 13:35 . 2008-04-10 13:47 <DIR> d-------- C:\Program Files\MagicISO
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\WINDOWS\Performance
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-04-04 19:29 . 2008-04-04 19:29 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-04-02 20:58 . 2008-04-02 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\dvdcss
2008-03-30 14:50 . <DIR> C:\Documents and Settings\Andy\Application Data\NeroDigitalT
2008-03-29 20:58 . 2008-04-30 19:44 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\UseNeXT
2008-03-29 20:09 . 2008-03-29 20:09 <DIR> d-------- C:\Program Files\Softgogo
2008-03-29 17:58 . 2008-02-18 17:21 402,728 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-03-29 12:39 . 2008-03-29 12:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\vlc
2008-03-29 06:38 . 2008-03-29 06:38 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-29 01:37 . 2008-04-27 04:26 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
2008-03-28 18:50 . 2008-04-27 04:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-03-26 21:39 . 2008-04-30 17:51 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-26 21:37 . 2008-03-26 21:37 2,525 --a------ C:\WINDOWS\system32\NMMediaServer.cfg
2008-03-26 19:24 . 2008-03-26 19:24 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-03-26 19:21 . 2008-03-26 19:21 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Program Files\Nero
2008-03-26 19:17 . 2008-03-26 19:19 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-24 22:48 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-03-24 22:48 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-03-24 22:48 . 2006-05-11 20:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-03-24 22:48 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-03-24 22:48 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-03-24 22:48 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-03-24 22:48 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-03-24 18:24 . 2002-12-16 19:09 30,970 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys
2008-03-24 18:24 . 2002-12-11 12:48 27,235 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys
2008-03-24 18:13 . 2008-03-24 18:13 0 --a------ C:\Documents and Settings\Andy\Application Data\wklnhst.dat
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\ODM
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\directx
2008-03-24 17:53 . 2003-02-27 18:14 226,688 --a------ C:\WINDOWS\system32\drivers\cccp106.sys
2008-03-24 17:53 . 2003-03-08 17:02 192,512 --a------ C:\WINDOWS\select.exe
2008-03-24 17:53 . 2003-02-18 15:48 61,440 --a------ C:\WINDOWS\system32\dcccp106.dll
2008-03-24 17:53 . 2003-02-18 15:48 45,056 --a------ C:\WINDOWS\system32\vcccp106.dll
2008-03-24 17:53 . 2002-11-13 16:54 36,864 --a------ C:\WINDOWS\CleanDev.exe
2008-03-24 17:53 . 2003-02-18 15:48 28,672 --a------ C:\WINDOWS\system32\dcccp106.ax
2008-03-24 17:53 . 2003-02-18 15:48 15,542 --a------ C:\WINDOWS\cccp106.ini
2008-03-24 17:53 . 2003-02-18 15:48 13,023 --------- C:\WINDOWS\cccp106.src
2008-03-24 17:53 . 2003-03-14 21:45 320 --a------ C:\WINDOWS\DC2110a.ini
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll
2008-03-24 16:05 . 2008-03-24 16:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-03-24 11:22 . 2008-03-24 11:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-03-24 11:22 . 2008-03-24 11:22 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-03-24 11:22 . 2008-02-27 14:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-24 03:12 . 2008-03-24 03:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Motive
2008-03-24 03:10 . 2008-03-24 03:10 <DIR> d-------- C:\WINDOWS\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\btbb_wcm
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-03-24 03:08 . 2008-03-24 03:08 <DIR> d-------- C:\Program Files\Motive
2008-03-24 03:08 . 2008-03-24 03:10 <DIR> d-------- C:\Program Files\BT Broadband Desktop Help
2008-03-24 00:39 . 2008-03-24 00:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\TuneUp Software
2008-03-24 00:38 . 2008-04-18 18:32 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 10:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-30 13:50 --------- d-----w C:\Documents and Settings\Andy\Application Data\NeroDigital™
2008-03-17 18:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-03-06 04:37 --------- d-----w C:\Program Files\Synaptics
2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek Semiconductor Corp
2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek AC97
2008-03-06 04:37 --------- d-----w C:\Program Files\RALINK
2008-03-06 04:36 --------- d-----w C:\Program Files\NewTech Infosystems
2008-03-06 04:36 --------- d-----w C:\Program Files\Microsoft Works
2008-03-06 04:36 --------- d-----w C:\Program Files\InterVideo
2008-03-06 04:36 --------- d-----w C:\Program Files\AvRack
2008-03-06 04:36 --------- d-----w C:\Program Files\ATI Technologies
2008-03-06 04:36 --------- d-----w C:\Program Files\AMD
2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2003-08-27 21:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-25 04:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-06 02:11 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-25 04:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-25 04:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]

C:\Documents and Settings\Andy\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXRLcAq]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkLFurr]
jkkLFurr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.scg726"= scg726.acm
"msacm.alf2cd"= alf2cd.acm
"vidc.dvsd"= mcdvd_32.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"kdx"=C:\Program Files\Kontiki\KHost.exe -all
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog
"EPSON Stylus DX4200 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /M "Stylus DX4200" /EF "HKCU"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"btbb_McciTrayApp"=C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
"CardReaderReset"=C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe
"SM1BG"=C:\WINDOWS\SM1BG.EXE
"btbb_wcm_McciTrayApp"=C:\Program Files\btbb_wcm\McciTrayApp.exe
"SoundMan"=SOUNDMAN.EXE
"YBrowser"=C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 13:00]
S3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-02-27 18:14]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 22:32]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-24 11:22]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-30 19:03:11 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-04-27 19:07:19 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Andy.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 20:04:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> ?:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-04-30 20:08:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-30 19:08:03
ComboFix2.txt 2008-04-15 23:33:31

Pre-Run: 20,148,396,032 bytes free
Post-Run: 20,162,777,088 bytes free

286 --- E O F --- 2008-04-26 10:41:17
One of the files deleted was the bho warned about by Spyware Guard.

Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* IE ad. popups(again)+ BHO activity in IE. Andybib Wed Apr 30 2008 08:16 PM
. * * Re: IE ad. popups(again)+ BHO activity in IE. bricatModerator   Thu May 01 2008 12:22 AM
. * * Re: IE ad. popups(again)+ BHO activity in IE. Andybib   Thu May 01 2008 01:35 AM
. * * Re: IE ad. popups(again)+ BHO activity in IE. bricatModerator   Thu May 01 2008 10:14 AM
. * * Re: IE ad. popups(again)+ BHO activity in IE. Andybib   Thu May 01 2008 06:32 PM
. * * Re: IE ad. popups(again)+ BHO activity in IE. bricatModerator   Thu May 01 2008 06:41 PM
. * * Re: IE ad. popups(again)+ BHO activity in IE. Andybib   Fri May 02 2008 01:08 AM
. * * Re: IE ad. popups(again)+ BHO activity in IE. bricatModerator   Fri May 02 2008 08:40 AM
. * * Re: IE ad. popups(again)+ BHO activity in IE. Andybib   Fri May 02 2008 07:29 PM
. * * Re: IE ad. popups(again)+ BHO activity in IE. bricatModerator   Fri May 02 2008 10:18 PM

Extra information
0 registered and 17 anonymous users are browsing this forum.

Moderator:  putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved