View Single Post
Old 10-14-2007, 02:13 PM   #4 (permalink)
Ecinue
Registered User
 
Join Date: Oct 2007
Posts: 17
OS: xp service pack 2


Re: System32 folder's in quarantine - Log

Ok I did the scan with ComboFix and this are the results:

ComboFix 07-10-14.4 - Eunice 2007-10-14 16:01:21.2 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\Eunice\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\xOe
C:\Temp\xOe\tOasF.log
C:\WINDOWS\system32\vMW02a

.
((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
.

2007-10-12 15:06 <DIR> d-------- C:\Deckard
2007-10-12 01:12 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-12 01:12 <DIR> d-------- C:\WINDOWS\LastGood
2007-10-10 15:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-09 16:49 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-06 13:26 <DIR> d-------- C:\Documents and Settings\Eunice\Application Data\Printer Info Cache
2007-10-05 19:11 <DIR> d-------- C:\Program Files\DIFX
2007-10-05 19:11 25,792 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2007-10-05 19:10 26,944 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2007-10-05 19:04 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2007-10-05 19:04 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Pure Networks
2007-10-05 19:03 <DIR> d-------- C:\Program Files\Pure Networks
2007-10-04 15:42 <DIR> d-------- C:\Documents and Settings\Eunice\Application Data\Grisoft
2007-10-04 15:35 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-04 13:54 <DIR> d-------- C:\Documents and Settings\Eunice\Application Data\WinPatrol
2007-10-04 13:53 <DIR> d-------- C:\Program Files\BillP Studios
2007-10-03 22:35 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2007-10-03 22:35 <DIR> d-------- C:\Documents and Settings\Eunice\Application Data\AVG7
2007-10-03 22:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-10-03 22:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-10-03 22:10 <DIR> d-------- C:\Program Files\Temporary
2007-10-03 22:07 <DIR> d-------- C:\WINDOWS\system32\abc2
2007-10-03 22:06 <DIR> d-------- C:\WINDOWS\system32\ep1
2007-10-03 22:05 <DIR> d-------- C:\Temp
2007-10-03 22:00 <DIR> d-------- C:\Documents and Settings\Eunice\.java
2007-09-29 21:59 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-09-29 21:59 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-09-26 02:11 <DIR> d-------- C:\Documents and Settings\Eunice\Application Data\Ventrilo
2007-09-26 02:06 <DIR> d-------- C:\Program Files\Ventrilo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-12 21:30 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-12 06:54 --------- d-----w C:\Program Files\RocketDock
2007-10-12 06:47 --------- d-----w C:\Program Files\LClock
2007-10-12 06:45 --------- d-----w C:\Program Files\iTunes
2007-10-09 23:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\hpqwmi
2007-10-09 23:10 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2007-10-06 22:58 --------- d-----w C:\Documents and Settings\Eunice\Application Data\Screenshot Sender
2007-10-06 17:27 --------- d-----w C:\Documents and Settings\Eunice\Application Data\Image Zone Express
2007-10-04 20:35 --------- d-----w C:\Documents and Settings\Eunice\Application Data\Azureus
2007-10-04 04:48 --------- d-----w C:\Documents and Settings\Eunice\Application Data\load else ooze
2007-10-04 04:48 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\loadcopydatajunk
2007-10-04 03:53 --------- d-----w C:\Program Files\Yahoo!
2007-10-04 02:03 --------- d-----w C:\Program Files\Azureus
2007-09-29 08:29 --------- d-----w C:\Program Files\Legacy Online
2007-09-15 15:42 --------- d-----w C:\Documents and Settings\Eunice\Application Data\AdobeUM
2007-09-13 02:46 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-13 02:40 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2007-09-13 02:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe Systems
2007-08-31 16:55 --------- d-----w C:\Documents and Settings\Eunice\Application Data\Yahoo!
2007-08-31 02:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2007-08-22 14:44 --------- d-----w C:\Program Files\In The Groove
2007-08-22 14:20 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-14 14:43 --------- d-----w C:\Program Files\MSXML 6.0
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 23:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-01-05 03:29 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37F0F8AE-AC34-462C-9EAE-D5E961ABF59B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 08:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 08:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 08:00]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 09:12 C:\WINDOWS\AGRSMMSG.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-20 07:50]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-09-07 16:28]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-12-08 20:23]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\bcmntray" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12]
"Glass2k"="C:\Program Files\Glass2k\Glass2k.exe" [2003-12-12 23:43]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-20 01:27]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-03 22:34]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-07 12:13]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2006-11-01 00:04]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-19 00:05]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-27 16:19]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpq]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
"Persistence"=C:\WINDOWS\system32\igfxpers.exe
"eabconfg.cpl"=C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0\bin\jusched.exe
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

R1 ClntMgmt.sys;ClntMgmt.sys;C:\WINDOWS\system32\Drivers\ClntMgmt.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1998dde-c68e-11db-a88f-0014a514a058}]
AutoRun\command - F:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-10-12 21:20:24 C:\WINDOWS\Tasks\1-Click Maintenance.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-14 16:09:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?2?8?4??????? ???B???????????????B? ??????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-14 16:10:22
C:\ComboFix2.txt ... 2007-10-10 15:25
.
--- E O F ---


Additionally my computer crashed the internet. It appeared connected but it wasn't working.
Ecinue is offline