It is currently Tue Sep 01, 2026 4:32 pm


log check please

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

log check please

Postby clennonuk » Sat Jun 13, 2009 7:44 pm

i tried to download some maps for my tom tom sat nav from lime wire but ever since i have a message coming up on my desktop saying my computer is infected with a virus and a programm opens up telling me to enter a code to activate a spywhere removal programme i am also getting lots of pop ups everytime i go on the net and i cant evan open any type of programme from my desktop i just get message saying this programme has a virus and cannot be opened

can u please look at my log and see if i can delete whatever it is using hjt
thanks
chris
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby Psymon » Sat Jun 13, 2009 8:31 pm

looks clear to me :D
User avatar
Psymon
Senior Geek
Senior Geek
 
Posts: 353
Joined: Wed Oct 26, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby clennonuk » Sat Jun 13, 2009 8:38 pm

i manage to run nortan in safe mode and it found a few bits to be removed i havent seen any problems since
looks like it might have sorted it
cheers
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby Gecko » Sun Jun 14, 2009 2:43 am

clennonuk,

I don't see a log? :?

Norton may have gotten some of it but I don't think Norton would get all of it.
Post a fresh Hijackthis log and I could tell better if you have something lurking that could be activated later.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: log check please

Postby clennonuk » Sun Jun 14, 2009 12:30 pm

what a penis i forgot to evan post the log
err here it is
{\rtf1\ansi\ansicpg1252\deff0\deflang1033{\fonttbl{\f0\fswiss\fcharset0 Arial;}}
{\*\generator Msftedit 5.41.15.1515;}\viewkind4\uc1\pard\f0\fs20 Logfile of HijackThis v1.99.1\par
Scan saved at 19:24:24, on 13/06/2009\par
Platform: Windows XP SP3 (WinNT 5.01.2600)\par
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)\par
\par
Running processes:\par
C:\\WINDOWS\\system32\\csrss.exe\par
C:\\WINDOWS\\system32\\winlogon.exe\par
C:\\WINDOWS\\system32\\services.exe\par
C:\\WINDOWS\\system32\\lsass.exe\par
C:\\WINDOWS\\system32\\svchost.exe\par
C:\\WINDOWS\\system32\\svchost.exe\par
C:\\WINDOWS\\system32\\svchost.exe\par
C:\\WINDOWS\\Explorer.EXE\par
C:\\Documents and Settings\\Owner\\Desktop\\hijackthis_sfx.exe\par
C:\\Program Files\\HijackThis\\HijackThis.exe\par
\par
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.yahoo.co.uk/\par
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant = \par
R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = *.local\par
F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,C:\\WINDOWS\\system32\\oembios.exe,\par
O1 - Hosts: 193.125.23.12 updates.sald.com\par
O2 - BHO: Adobe PDF Reader Link Helper - \{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3\} - C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll (file missing)\par
O2 - BHO: Symantec NCO BHO - \{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408\} - C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\coIEPlg.dll\par
O2 - BHO: Symantec Intrusion Prevention - \{6D53EC84-6AAE-4787-AEEE-F4628F01010C\} - C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\IPSBHO.DLL\par
O2 - BHO: (no name) - \{7E853D72-626A-48EC-A868-BA8D5E23E045\} - (no file)\par
O2 - BHO: Windows Live Sign-in Helper - \{9030D464-4C02-4ABF-8ECC-5164760863C6\} - C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll\par
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - \{DBC80044-A445-435b-BC74-9C25C1C588A9\} - C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll\par
O2 - BHO: JQSIEStartDetectorImpl - \{E7E6F031-17CE-4C07-BC86-EABFE594F69C\} - C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\ie\\jqs_plugin.dll\par
O3 - Toolbar: Norton Toolbar - \{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA\} - C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\coIEPlg.dll\par
O4 - HKLM\\..\\Run: [ehTray] C:\\WINDOWS\\ehome\\ehtray.exe\par
O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup\par
O4 - HKLM\\..\\Run: [nwiz] nwiz.exe /install\par
O4 - HKLM\\..\\Run: [NvMediaCenter] RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit\par
O4 - HKLM\\..\\Run: [RTHDCPL] RTHDCPL.EXE\par
O4 - HKLM\\..\\Run: [Alcmtr] ALCMTR.EXE\par
O4 - HKLM\\..\\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent\par
O4 - HKLM\\..\\Run: [NeroFilterCheck] C:\\WINDOWS\\system32\\NeroCheck.exe\par
O4 - HKLM\\..\\Run: [TkBellExe] "C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe" -osboot\par
O4 - HKLM\\..\\Run: [Adobe Reader Speed Launcher] "C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"\par
O4 - HKLM\\..\\Run: [QuickTime Task] "C:\\Program Files\\QuickTime\\qttask.exe" -atboottime\par
O4 - HKLM\\..\\Run: [iTunesHelper] "C:\\Program Files\\iTunes\\iTunesHelper.exe"\par
O4 - HKLM\\..\\Run: [AppleSyncNotifier] C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleSyncNotifier.exe\par
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] "C:\\Program Files\\Java\\jre6\\bin\\jusched.exe"\par
O4 - HKLM\\..\\Run: [KernelFaultCheck] %systemroot%\\system32\\dumprep 0 -k\par
O4 - HKLM\\..\\Run: [13227184] C:\\Documents and Settings\\All Users\\Application Data\\13227184\\13227184.exe\par
O4 - HKLM\\..\\Run: [93237176] C:\\Documents and Settings\\All Users\\Application Data\\93237176\\93237176.exe\par
O4 - HKCU\\..\\Run: [Window Washer] C:\\Program Files\\Webroot\\Washer\\wwDisp.exe\par
O4 - HKCU\\..\\Run: [MsnMsgr] "C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe" /background\par
O4 - HKCU\\..\\Run: [ISUSPM] "C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\ISUSPM.exe" -scheduler\par
O4 - HKCU\\..\\Run: [TomTomHOME.exe] "C:\\Program Files\\TomTom HOME 2\\TomTomHOMERunner.exe" -s\par
O4 - HKCU\\..\\Run: [BitTorrent DNA] "C:\\Program Files\\DNA\\btdna.exe"\par
O4 - Global Startup: Extender Resource Monitor.lnk = C:\\WINDOWS\\ehome\\RMSysTry.exe\par
O9 - Extra button: (no name) - \{e2e2dd38-d088-4134-82b7-f2ba38496583\} - %windir%\\Network Diagnostic\\xpnetdiag.exe (file missing)\par
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - \{e2e2dd38-d088-4134-82b7-f2ba38496583\} - %windir%\\Network Diagnostic\\xpnetdiag.exe (file missing)\par
O9 - Extra button: Messenger - \{FB5F1910-F110-11d2-BB9E-00C04F795683\} - C:\\Program Files\\Messenger\\msmsgs.exe\par
O9 - Extra 'Tools' menuitem: Windows Messenger - \{FB5F1910-F110-11d2-BB9E-00C04F795683\} - C:\\Program Files\\Messenger\\msmsgs.exe\par
O10 - Unknown file in Winsock LSP: c:\\program files\\bonjour\\mdnsnsp.dll\par
O16 - DPF: Photobucket Publisher - http://smg.photobucket.com/csve/ie_plugin.php\par
O16 - DPF: \{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB\} - http://ak.exe.imgfarm.com/images/nocach ... .0.1.1.cab\par
O16 - DPF: \{4C39376E-FA9D-4349-BACC-D305C1750EF3\} (EPUImageControl Class) - http://sell-vehicle.ebay.co.uk/images/e ... 0-3-50.cab\par
O16 - DPF: \{6414512B-B978-451D-A0D8-FCFDF33E833C\} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 2414097548\par
O16 - DPF: \{67DABFBF-D0AB-41FA-9C46-CC0F21721616\} - http://go.divx.com/plugin/DivXBrowserPlugin.cab\par
O16 - DPF: \{C3F79A2B-B9B4-4A66-B012-3EE46475B072\} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab\par
O18 - Protocol: livecall - \{828030A1-22C1-4009-854F-8E305202313F\} - C:\\PROGRA~1\\WI1F86~1\\MESSEN~1\\MSGRAP~1.DLL\par
O18 - Protocol: msnim - \{828030A1-22C1-4009-854F-8E305202313F\} - C:\\PROGRA~1\\WI1F86~1\\MESSEN~1\\MSGRAP~1.DLL\par
O18 - Protocol: symres - \{AA1061FE-6C41-421F-9344-69640C9732AB\} - C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\coIEPlg.dll\par
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\\System32\\dimsntfy.dll (file missing)\par
O21 - SSODL: WPDShServiceObj - \{AAA288BA-9A4C-45B0-95D7-94D524869DB5\} - C:\\WINDOWS\\system32\\WPDShServiceObj.dll\par
O23 - Service: Apple Mobile Device - Apple Inc. - C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe\par
O23 - Service: Bonjour Service - Apple Inc. - C:\\Program Files\\Bonjour\\mDNSResponder.exe\par
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files\\Common Files\\InstallShield\\Driver\\1050\\Intel 32\\IDriverT.exe\par
O23 - Service: iPod Service - Apple Inc. - C:\\Program Files\\iPod\\bin\\iPodService.exe\par
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\\Program Files\\Java\\jre6\\bin\\jqs.exe" -service -config "C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\jqs.conf (file missing)\par
O23 - Service: Norton Internet Security - Unknown owner - C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\\Program Files\\Norton Internet Security\\Engine\\16.5.0.135\\diMaster.dll" /prefetch:1 (file missing)\par
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\\WINDOWS\\system32\\nvsvc32.exe\par
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe\par
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe\par
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxMediaDB9.exe\par
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\\Program Files\\Common Files\\SureThing Shared\\stllssvr.exe\par
O23 - Service: TomTomHOMEService - TomTom - C:\\Program Files\\TomTom HOME 2\\TomTomHOMEService.exe\par
\par
}
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby clennonuk » Sun Jun 14, 2009 12:34 pm

sorry thats the old one here is the new one

Logfile of HijackThis v1.99.1
Scan saved at 12:33:45, on 14/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
O1 - Hosts: 193.125.23.12 updates.sald.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: Photobucket Publisher - http://smg.photobucket.com/csve/ie_plugin.php
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://sell-vehicle.ebay.co.uk/images/e ... 0-3-50.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 2414097548
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll" /prefetch:1 (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby Gecko » Sun Jun 14, 2009 1:11 pm

clennonuk,

It looks as though you have an active trojan.

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: log check please

Postby clennonuk » Sun Jun 14, 2009 4:01 pm

ok here is the combofix log



mboFix 09-06-13.09 - Owner 14/06/2009 13:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.563 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Application Data\sysproc64
c:\documents and settings\NetworkService\Application Data\sysproc64
c:\program files\IEToolbar
c:\program files\runit
c:\windows\swxw6562.exe
c:\windows\system32\sysproc64
c:\windows\tseo1133.exe
c:\documents and settings\LocalService\Application Data\sysproc64\sysproc32.sys
c:\documents and settings\NetworkService\Application Data\sysproc64\sysproc32.sys
c:\program files\runit\config.txt
c:\windows\kb913800.exe
c:\windows\system32\drivers\SKYNETypqmlqji.sys
c:\windows\system32\SKYNETiyihbote.dll
c:\windows\system32\SKYNETlxdulxud.dll
c:\windows\system32\SKYNETpntymrgg.dat
c:\windows\system32\SKYNETwqvrsrsa.dat
c:\windows\system32\sysproc64\sysproc32.sys
c:\windows\system32\sysproc64\sysproc86.sys
H:\Autorun.inf
H:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETkkfrcqtk


((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))
.

2009-06-14 03:35 . 2009-06-12 01:28 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\NAVENG.SYS
2009-06-14 03:35 . 2009-06-12 01:28 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\NAVEX15.SYS
2009-06-14 03:35 . 2009-06-12 01:28 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\EECTRL.SYS
2009-06-14 03:35 . 2009-06-12 01:28 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\ECMSVR32.DLL
2009-06-14 03:35 . 2009-06-12 01:28 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\CCERASER.DLL
2009-06-14 03:35 . 2009-06-12 01:28 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\NAVENG32.DLL
2009-06-14 03:35 . 2009-06-12 01:28 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\NAVEX32A.DLL
2009-06-14 03:35 . 2009-06-12 01:28 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090613.023\ERASER.SYS
2009-06-13 19:35 . 2009-06-13 19:26 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-13 19:26 . 2009-06-13 19:25 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-13 19:26 . 2009-06-13 19:26 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-13 19:26 . 2009-06-13 19:26 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-13 19:26 . 2009-06-13 19:26 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-13 19:26 . 2009-06-13 19:26 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-13 19:24 . 2009-06-13 19:24 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-13 19:24 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-13 19:24 . 2009-06-13 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-13 19:24 . 2009-06-13 19:24 -------- d-----w- c:\program files\Lavasoft
2009-06-13 17:36 . 2009-06-13 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\93237176
2009-06-12 21:20 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
2009-06-12 21:20 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
2009-06-12 21:20 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
2009-06-12 21:20 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
2009-06-12 21:20 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
2009-06-11 14:35 . 2009-06-11 14:35 -------- d-----r- c:\program files\Norton Support
2009-06-11 14:35 . 2009-06-11 14:35 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Symantec
2009-06-10 21:13 . 2009-06-10 21:13 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 20:19 . 2009-06-10 21:12 -------- d-----w- c:\program files\Incomplete
2009-06-08 18:26 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll
2009-06-08 18:26 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys
2009-06-08 18:26 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys
2009-06-08 18:26 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll
2009-06-08 18:26 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys
2009-06-08 17:23 . 2008-11-05 17:48 4457808 ----a-w- c:\documents and settings\Owner\Application Data\TomTom\HOME\Profiles\5vchrz7x.default\extensions\Navcore.8.300.9732@tomtom.com\8-300-9732-1.dll
2009-06-08 17:18 . 2009-06-08 17:18 -------- d-----w- c:\program files\TomTom International B.V
2009-06-08 17:18 . 2009-06-08 17:18 -------- d-----w- c:\program files\TomTom HOME 2
2009-06-06 09:24 . 2008-06-11 09:47 9022288 ----a-w- c:\documents and settings\Owner\Application Data\TomTom\HOME\Profiles\5vchrz7x.default\extensions\Navcore.8.010.9369@tomtom.com\8-010-9369-1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-14 12:30 . 2009-02-18 14:12 -------- d-----w- c:\documents and settings\Owner\Application Data\DNA
2009-06-14 08:28 . 2009-02-18 14:12 -------- d-----w- c:\program files\DNA
2009-06-10 21:53 . 2008-02-18 18:05 -------- d-----w- c:\program files\LimeWire
2009-06-10 21:14 . 2008-02-18 18:05 -------- d-----w- c:\program files\Java
2009-06-10 20:21 . 2008-02-18 18:06 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-05-21 10:33 . 2009-01-04 12:40 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-12 22:12 . 2008-11-27 20:50 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-05-12 20:03 . 2009-05-12 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-12 20:03 . 2008-11-27 20:50 -------- d-----w- c:\program files\iTunes
2009-05-12 20:02 . 2009-05-12 20:02 -------- d-----w- c:\program files\iPod
2009-05-12 20:02 . 2008-11-27 20:48 -------- d-----w- c:\program files\Common Files\Apple
2009-05-12 20:01 . 2009-05-12 20:01 -------- d-----w- c:\program files\Bonjour
2009-05-12 20:00 . 2009-05-12 20:00 -------- d-----w- c:\program files\QuickTime
2009-05-12 19:55 . 2009-05-12 19:55 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-12 18:51 . 2009-05-12 18:51 -------- d-----w- c:\documents and settings\Owner\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
2009-05-12 18:51 . 2009-05-12 18:51 -------- d-----w- c:\program files\BBC iPlayer Desktop
2009-05-12 18:51 . 2009-05-12 18:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-12 18:50 . 2009-05-12 18:51 38208 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-07 15:32 . 2004-08-10 11:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2006-03-04 03:33 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-10 11:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-10 11:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 10:28 . 2009-04-17 10:28 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-04-15 14:51 . 2004-08-10 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-15 08:29 . 2009-04-15 08:29 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-26 14:23 . 2009-05-12 19:58 1900544 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-03-26 14:23 . 2008-11-27 20:48 36864 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-20 09:22 . 2009-02-12 19:12 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-03-20 09:22 . 2009-02-12 19:12 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-19 15:32 . 2009-03-19 15:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 15:32 . 2008-11-27 20:50 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-16 20:03 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2005-03-08 910336]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-24 251240]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-02-18 321344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-06 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-13 518488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [13/06/2009 20:26 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [20/03/2009 10:22 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [20/03/2009 10:22 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [20/03/2009 10:22 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys [12/06/2009 22:20 276344]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 20:06 1005904]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [20/03/2009 10:22 115560]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [24/04/2009 12:57 92008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/02/2009 10:00 101936]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2009-06-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:25]

2009-06-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride = *.local
DPF: Photobucket Publisher - hxxp://smg.photobucket.com/csve/ie_plugin.php
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-14 13:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-06-14 13:39
ComboFix-quarantined-files.txt 2009-06-14 12:39

Pre-Run: 293,126,709,248 bytes free
Post-Run: 293,206,704,128 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
h:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

214 --- E O F --- 2009-06-11 15:38
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top

Re: log check please

Postby Gecko » Mon Jun 15, 2009 3:29 pm

clennonuk,

Do you know what the following directory is for?
c:\program files\Incomplete

Otherwise you Combofix log looks clean, how's it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: log check please

Postby clennonuk » Mon Jun 15, 2009 3:56 pm

yeah it seems ok now thanks for your help

i dont know what this is for c:\program files\Incomplete perhaps something to do with incomplete limewire files
User avatar
clennonuk
Senior Geek
Senior Geek
 
Posts: 158
Joined: Thu Feb 12, 2004 1:00 am
Location: London England

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron