It is currently Tue Sep 01, 2026 4:36 pm


New Log

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

New Log

Postby TheExero » Mon Jan 11, 2010 2:53 am

Here is a log i worry that i am infected with some sort of keylogger.


Logfile of HijackThis v1.99.1
Scan saved at 8:51:08 PM, on 1/10/2010
Platform: Unknown Windows (WinNT 6.00.1906 SP2)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MagicTune Premium\GammaTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Dean\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html ... &M=GM5457E
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html ... &M=GM5457E
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html ... &M=GM5457E
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html ... &M=GM5457E
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShopperReports - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShopperReports3\bin\3.0.242.0\ShopperReports.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: GammaTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShopperReports3\bin\3.0.242.0\ShopperReports.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShopperReports3\bin\3.0.242.0\ShopperReports.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CEFEF1B-4110-48FB-85C4-C235D38A3217}: NameServer = 192.168.1.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: SQL Server (SONY_MEDIAMGR2) (MSSQL$SONY_MEDIAMGR2) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSONY_MEDIAMGR2 (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: The Browser Highlighter Monitor (tbhMonitor.exe) - Unknown owner - C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top

Re: New Log

Postby Gecko » Mon Jan 11, 2010 12:48 pm

TheExero,

I don't see any keylogger however I do see some spyware
Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: New Log

Postby TheExero » Mon Jan 11, 2010 4:48 pm

Ty for the reply and sorry for the double threads i was just a bit paranoid. Also before i post the log i would like to know since i have two computer that i used to transfer files and do backups via Network Sharing with USB is there a chance that the other pc can have a keylogger and it keylogs both computers? If so should i do a hijack scan on the other pc?

And here is the combo log. :cool:

ComboFix 10-01-04.01 - Dean 01/11/2010 10:33:28.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.741 [GMT -5:00]
Running from: c:\users\Dean\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Internet Security *enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3678024670-894085293-2732371526-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.

2010-01-11 15:42 . 2010-01-11 15:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-11 15:42 . 2010-01-11 15:43 -------- d-----w- c:\users\Dean\AppData\Local\temp
2010-01-11 01:07 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-01-11 01:07 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-01-11 01:07 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-01-11 00:55 . 2010-01-11 15:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-11 00:55 . 2010-01-11 15:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-11 00:54 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-01-11 00:51 . 2009-11-21 06:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-11 00:49 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2010-01-10 19:49 . 2010-01-10 19:49 -------- d-----w- c:\program files\ESET
2010-01-10 19:27 . 2010-01-10 19:27 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-01-08 21:11 . 2010-01-08 21:16 55325 ----a-w- c:\windows\War3Unin.dat
2010-01-08 21:11 . 2010-01-08 21:15 2829 ----a-w- c:\windows\War3Unin.pif
2010-01-08 21:11 . 2010-01-08 21:15 139264 ----a-w- c:\windows\War3Unin.exe
2010-01-08 21:08 . 2010-01-08 21:28 -------- d-----w- c:\program files\Warcraft III
2010-01-04 01:49 . 2010-01-04 01:49 -------- d-----w- c:\program files\Redbana
2009-12-25 06:44 . 2009-12-25 06:44 -------- d-----w- C:\Windows.old
2009-12-24 02:53 . 1998-09-14 13:41 285216 ----a-w- c:\windows\system32\drivers\Onsio.sys
2009-12-24 02:53 . 1998-08-01 17:00 60928 ----a-w- c:\windows\system32\drivers\Smplscsi.sys
2009-12-24 02:53 . 1997-02-14 18:10 7680 ----a-w- c:\windows\system32\drivers\Onsreged.sys
2009-12-24 02:53 . 2009-12-24 02:53 -------- d-----w- C:\Kpcms
2009-12-24 02:53 . 2003-07-17 21:12 12499 ----a-w- c:\windows\system32\Msmusd7.dll
2009-12-24 02:53 . 2003-06-11 17:03 15396 ----a-w- c:\windows\system32\Msmusd5.dll
2009-12-24 02:53 . 2001-06-20 20:44 13962 ----a-w- c:\windows\system32\Msmusd6.dll
2009-12-24 02:53 . 2009-12-24 02:53 -------- d-----w- c:\program files\Microtek
2009-12-24 02:52 . 2009-12-24 02:52 -------- d-----w- C:\ScanWizard 5 V6.63
2009-12-19 15:59 . 2009-12-19 15:59 -------- d-----w- c:\programdata\Messenger Plus!
2009-12-19 07:55 . 2010-01-08 16:48 -------- d-----w- c:\users\Dean\AppData\Roaming\vlc
2009-12-19 07:54 . 2009-12-19 07:54 -------- d-----w- c:\program files\VideoLAN
2009-12-19 07:53 . 2009-12-19 07:53 -------- d-----w- c:\users\Dean\AppData\Roaming\ShopperReports3
2009-12-19 07:53 . 2009-12-19 07:53 -------- d-----w- c:\program files\ShopperReports3
2009-12-19 03:47 . 2009-12-19 03:47 -------- d-----w- c:\program files\Messenger Plus! Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 15:29 . 2009-12-09 20:03 -------- d-----w- c:\users\Dean\AppData\Roaming\Skype
2010-01-11 13:06 . 2009-12-09 20:11 -------- d-----w- c:\users\Dean\AppData\Roaming\skypePM
2010-01-11 01:25 . 2009-12-05 02:00 -------- d-----w- c:\users\Dean\AppData\Roaming\uTorrent
2010-01-11 01:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-11 01:06 . 2009-12-01 19:09 -------- d-----w- c:\programdata\Microsoft Help
2010-01-04 07:18 . 2009-12-04 16:34 70888 ----a-w- c:\users\Dean\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 01:49 . 2009-12-01 19:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-21 13:39 . 2009-12-11 03:26 2066200 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-12-18 18:23 . 2009-12-05 06:27 -------- d-----w- c:\program files\Left 4 Dead
2009-12-11 18:04 . 2009-12-05 19:49 393216 ----a-w- c:\programdata\NexonUS\NGM\NGMResource.dll
2009-12-11 18:04 . 2009-12-05 19:49 258352 ----a-w- c:\programdata\NexonUS\NGM\unicows.dll
2009-12-11 18:04 . 2009-12-05 19:49 118784 ----a-w- c:\programdata\NexonUS\NGM\nxgameus.dll
2009-12-11 18:04 . 2009-12-05 19:49 561152 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2009-12-11 18:04 . 2009-12-05 19:49 167936 ----a-w- c:\programdata\NexonUS\NGM\NGM.exe
2009-12-11 04:08 . 2009-12-11 04:08 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe1_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-12-11 04:08 . 2009-12-11 04:08 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-12-11 04:08 . 2009-12-11 04:08 10134 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\ARPPRODUCTICON.exe
2009-12-11 03:46 . 2009-12-05 01:11 -------- d-----w- c:\programdata\PMB Files
2009-12-11 03:19 . 2009-12-05 00:41 -------- d-----w- c:\users\Dean\AppData\Roaming\Ventrilo
2009-12-11 02:41 . 2009-12-11 02:41 552 ----a-w- c:\users\Dean\AppData\Local\d3d8caps.dat
2009-12-10 16:09 . 2009-12-10 16:09 -------- d-sh--w- c:\programdata\SecuROM
2009-12-10 15:46 . 2009-12-10 15:46 -------- d-----w- c:\program files\2K Games
2009-12-10 15:43 . 2009-12-10 15:43 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-09 20:11 . 2009-12-09 20:11 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-12-09 20:02 . 2009-12-09 20:02 -------- d-----w- c:\program files\tbh
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----r- c:\program files\Skype
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----w- c:\program files\Common Files\Skype
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----w- c:\programdata\Skype
2009-12-09 06:23 . 2009-12-08 01:30 -------- d-----w- c:\program files\SINS
2009-12-08 19:14 . 2009-12-08 19:14 -------- d-----w- c:\users\Dean\AppData\Roaming\Publish Providers
2009-12-08 19:14 . 2009-12-05 06:01 -------- d-----w- c:\users\Dean\AppData\Roaming\Sony
2009-12-08 19:06 . 2009-12-05 06:00 -------- d-----w- c:\programdata\Sony
2009-12-08 19:05 . 2009-12-05 06:00 -------- d-----w- c:\program files\Sony
2009-12-08 18:56 . 2009-12-08 18:42 -------- d-----w- c:\users\Dean\AppData\Roaming\DAEMON Tools Lite
2009-12-08 18:43 . 2009-12-08 18:43 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-08 18:43 . 2009-12-08 01:33 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-08 18:42 . 2009-12-08 01:49 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-12-08 01:33 . 2009-12-08 01:33 -------- d-----w- c:\users\Dean\AppData\Roaming\DAEMON Tools Pro
2009-12-08 01:30 . 2009-12-06 22:58 -------- d-----w- c:\program files\Stardock Games
2009-12-07 20:01 . 2009-12-07 19:42 -------- d-----w- c:\users\Dean\AppData\Roaming\GameRanger
2009-12-07 19:41 . 2009-12-07 19:28 -------- d-----w- c:\program files\GameSpy Arcade
2009-12-07 17:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2009-12-07 08:02 . 2009-12-05 05:52 -------- d-----w- c:\program files\Microsoft SQL Server
2009-12-07 01:10 . 2009-12-07 01:10 -------- d-----w- c:\programdata\Ironclad Games
2009-12-06 14:41 . 2009-12-06 14:41 680 ----a-w- c:\users\Dean\AppData\Local\d3d9caps.dat
2009-12-06 14:29 . 2009-12-01 19:10 -------- d-----w- c:\program files\Microsoft Works
2009-12-06 08:43 . 2009-12-06 08:43 -------- d-----w- c:\program files\Windows Portable Devices
2009-12-06 08:43 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-06 08:43 . 2009-12-06 08:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-06 08:04 . 2009-12-06 08:04 -------- d-----w- c:\program files\MSXML 4.0
2009-12-05 20:06 . 2009-12-05 20:06 -------- d-----w- c:\programdata\Nexon
2009-12-05 20:06 . 2009-12-05 19:49 -------- d-----w- c:\programdata\NexonUS
2009-12-05 19:49 . 2009-12-05 19:49 90112 ----a-w- c:\programdata\NexonUS\NGM\npNxGameUS.dll
2009-12-05 06:17 . 2009-12-05 01:33 -------- d-----w- c:\users\Dean\AppData\Roaming\Winamp
2009-12-05 06:03 . 2009-12-05 05:52 -------- d-----w- c:\program files\Sony Setup
2009-12-05 05:54 . 2009-12-01 19:10 -------- d-----w- c:\program files\Microsoft.NET
2009-12-05 05:40 . 2009-12-05 05:40 -------- d-----w- c:\programdata\FLEXnet
2009-12-05 05:36 . 2009-12-01 19:08 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 05:35 . 2009-12-05 05:35 -------- d-----w- c:\program files\Adobe Media Player
2009-12-05 05:34 . 2009-12-05 05:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-05 05:31 . 2009-12-05 05:31 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-05 05:15 . 2009-12-05 05:14 -------- d-----w- c:\program files\MagicISO
2009-12-05 05:10 . 2009-12-05 05:10 -------- d-----w- c:\users\Dean\AppData\Roaming\CyberLink
2009-12-05 05:10 . 2009-12-05 05:10 -------- d-----w- c:\programdata\CyberLink
2009-12-05 02:01 . 2009-12-05 02:01 -------- d-----w- c:\program files\uTorrent
2009-12-05 01:50 . 2009-12-05 01:50 -------- d-----w- c:\users\Dean\AppData\Roaming\AusLogics
2009-12-05 01:43 . 2009-12-05 01:43 -------- d-----w- c:\program files\Auslogics
2009-12-05 01:33 . 2009-12-05 01:33 -------- d-----w- c:\program files\Winamp
2009-12-05 01:33 . 2009-12-05 01:33 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-05 01:18 . 2009-12-05 01:18 -------- d-----w- c:\program files\SEC
2009-12-05 01:14 . 2009-12-05 01:14 -------- d-----w- c:\program files\MagicTune Premium
2009-12-05 01:14 . 2009-12-05 01:14 -------- d-----w- c:\users\Dean\AppData\Roaming\InstallShield
2009-12-05 01:11 . 2009-12-05 01:11 -------- d-----w- c:\program files\Pando Networks
2009-12-05 01:02 . 2009-12-05 00:59 -------- d-----w- c:\program files\Windows Live
2009-12-05 01:01 . 2009-12-05 01:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-05 01:00 . 2009-12-05 01:00 -------- d-----w- c:\program files\Microsoft
2009-12-05 01:00 . 2009-12-05 01:00 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-05 00:55 . 2009-12-05 00:55 -------- d-----w- c:\program files\Common Files\Windows Live
2009-12-05 00:34 . 2009-12-01 19:13 -------- d-----w- c:\programdata\McAfee
2009-12-05 00:29 . 2009-12-05 00:18 -------- d-----w- c:\programdata\avg8
2009-12-05 00:29 . 2009-12-05 00:18 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-05 00:29 . 2009-12-05 00:18 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-05 00:29 . 2009-12-05 00:18 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-05 00:29 . 2009-12-05 00:29 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-05 00:29 . 2009-12-05 00:29 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-05 00:18 . 2009-12-05 00:18 -------- d-----w- c:\program files\AVG
2009-12-04 23:54 . 2009-12-04 23:54 -------- d-----w- c:\programdata\Downloaded Installations
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-12-04 22:00 . 2009-12-04 22:00 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-12-04 21:06 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-12-04 21:06 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-12-04 16:58 . 2009-12-01 19:12 -------- d-----w- c:\program files\Google
2009-12-04 16:52 . 2009-12-04 16:52 -------- d-----w- c:\users\Dean\AppData\Roaming\Logitech
2009-12-04 16:51 . 2009-12-04 16:51 -------- d-----w- c:\users\Dean\AppData\Roaming\Leadertech
2009-12-04 16:51 . 2009-12-04 16:49 -------- d-----w- c:\program files\Common Files\Logishrd
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-05 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SigmatelSysTrayApp"="sttray.exe" [2006-11-02 303104]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-06 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-06 81920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-4 809488]
Microtek Scanner Finder.lnk - c:\program files\Microtek\ScanWizard 5\ScannerFinder.exe [2009-12-23 344064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NCProTray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NCProTray.lnk
backup=c:\windows\pss\NCProTray.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Dean^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\Dean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Dean^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\users\Dean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 12:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
2006-11-17 00:04 2348584 ----a-w- c:\program files\BigFix\bigfix.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
2006-11-18 15:01 182744 ----a-w- c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-12-04 16:36 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ledpointer]
2006-11-10 00:01 5585408 ----a-w- c:\windows\CNYHKey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoLed]
2006-11-10 00:15 53248 ----a-w- c:\windows\ModLEDKey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
2006-09-26 18:56 423424 ----a-w- c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-11-02 20:38 303104 ----a-w- c:\windows\sttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tbhSystray]
2010-01-11 15:31 492840 ----a-w- c:\program files\tbh\base\bin\tbhSystray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-05 02:01 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 04:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9f,63,2b,4f,2e,75,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3678024670-894085293-2732371526-500]
"EnableNotificationsRef"=dword:00000002

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [12/4/2009 7:18 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [12/4/2009 7:29 PM 108552]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/4/2009 7:29 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/4/2009 7:29 PM 297752]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [5/14/2009 3:49 PM 93312]
R2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [9/27/2006 7:37 PM 28672]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [10/19/2006 6:49 PM 7424]
R2 tbhMonitor.exe;The Browser Highlighter Monitor;c:\program files\tbh\monitor\bin\tbhMonitor.exe [10/22/2009 1:57 PM 70952]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [12/1/2009 1:58 PM 5504]
R3 xcbdaNtsc;ViXS Tuner Card (NTSC);c:\windows\System32\drivers\xcbda.sys [12/1/2009 2:42 PM 147328]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [12/7/2009 8:33 PM 691696]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [10/29/2006 12:03 PM 208896]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [12/4/2009 12:33 PM 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/1/2009 2:12 PM 30192]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [5/27/2009 3:27 AM 29262680]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 5:25 AM 2589184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gateway.com/g/startpage.html ... &M=GM5457E
mStart Page = hxxp://www.gateway.com/g/startpage.html ... &M=GM5457E
uInternet Settings,ProxyOverride = <local>
TCP: {5CEFEF1B-4110-48FB-85C4-C235D38A3217} = 192.168.1.1
FF - ProfilePath - c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\jfy60p36.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\jfy60p36.default\extensions\browserhighlighter@ebay.com\components\Shim.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-MskAgentexe - c:\program files\McAfee\MSK\MskAgent.exe
MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-11 10:42
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(672)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-01-11 10:45:10
ComboFix-quarantined-files.txt 2010-01-11 15:45

Pre-Run: 301,906,710,528 bytes free
Post-Run: 301,958,610,944 bytes free

- - End Of File - - 346160B8099B8035B783A2563622776E
TheExero
Geek
Geek
 
Posts: 51
Joined: Sat Dec 01, 2007 12:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron