View Single Post
Old 07-04-2007, 12:59 AM   #25 (permalink)
Disko_Stu
Registered User
 
Disko_Stu's Avatar
 
Join Date: May 2007
Location: Australia
Posts: 46
OS: Windows XP and Vista


Re: Internet Explorer Pop-ups

Finally it worked!! I deleted the old ComboFix.exe and downloaded the new and it ran perfectly. Here's the log it created. Do you need the quarantined file list (A text file was created)?

_____________

Completed ComboFix Log


"Jacqui Hampton" - 2007-07-04 13:01:50 - ComboFix 07-07-04.1 - Service Pack 2 FAT32


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\scchk32.exe.bak


((((((((((((((((((((((((( Files Created from 2007-06-04 to 2007-07-04 )))))))))))))))))))))))))))))))


2007-07-01 23:03 <DIR> d-------- C:\WINDOWS\LastGood
2007-06-30 22:57 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-29 21:46 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-06-29 16:51 0 --a------ C:\WINDOWS\nsreg.dat
2007-06-29 16:11 <DIR> d-------- C:\Deckard
2007-06-28 20:48 1,048,576 --ah----- C:\DOCUME~1\LOCALS~1.NTA\NTUSER.DAT
2007-06-28 20:48 <DIR> d---s---- C:\DOCUME~1\LOCALS~1.NTA\UserData
2007-06-28 20:47 <DIR> d--hs---- C:\FOUND.000
2007-06-23 23:35 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-22 11:37 <DIR> d-------- C:\DOCUME~1\JACQUI~1\APPLIC~1\Atari
2007-06-22 11:14 197,120 --a------ C:\WINDOWS\patchw32.dll
2007-06-22 11:14 <DIR> d-------- C:\Program Files\Common Files\PocketSoft
2007-06-22 11:14 <DIR> d-------- C:\DOCUME~1\JACQUI~1\APPLIC~1\Leadertech
2007-06-22 11:09 <DIR> d-------- C:\Program Files\Atari
2007-06-21 16:12 <DIR> d-------- C:\DOCUME~1\JACQUI~1\APPLIC~1\FileMaker
2007-06-13 22:02 <DIR> d-------- C:\DOCUME~1\JACQUI~1\APPLIC~1\Tenebril
2007-06-13 21:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tenebril
2007-06-13 21:52 40,960 --a-s---- C:\WINDOWS\system32\ProcessKiller.dll
2007-06-13 21:52 180,224 --a-s---- C:\WINDOWS\system32\archlib.dll
2007-06-13 21:52 169,544 --a-s---- C:\WINDOWS\system32\SecuLoad.dll
2007-06-13 21:52 1,103,944 --a-s---- C:\WINDOWS\system32\Protector.dll
2007-06-13 21:52 <DIR> d-------- C:\WINDOWS\system32\tenarchlib
2007-06-13 21:52 <DIR> d-------- C:\Program Files\SpyCatcher
2007-06-13 17:57 754,808 --a------ C:\WINDOWS\system32\LiveProtectSetup.exe
2007-06-12 17:20 <DIR> d-------- C:\Program Files\Yahoo! Games
2007-06-11 16:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-06-11 16:12 <DIR> d-------- C:\DOCUME~1\JACQUI~1\APPLIC~1\Sandlot Games


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-01 12:12:06 12 ----a-w C:\WINDOWS\bthservsdp.dat
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-01 08:49:06 16 ----a-w C:\WINDOWS\system32\a99vi88f.dat
2007-05-01 08:49:02 573,944 ----a-w C:\WINDOWS\system32\nc5vfm94.dat
2007-05-01 08:48:58 2,256 ----a-w C:\WINDOWS\system32\rl5ba39o.dat
2007-04-25 14:21:16 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:24 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 12:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 12:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 12:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 12:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 12:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 12:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 12:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 12:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
2004-09-29 11:02 292947 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A87E45F-537A-40B4-B812-E2544C21A09F}]
2005-08-22 21:57 118784 --a------ C:\Program Files\SpyCatcher\SCActiveBlock.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
2004-08-13 16:42 155648 --a------ C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 23:55 2403392 -ra------ c:\program files\google\googletoolbar3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
2007-06-28 23:40 325048 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
2006-01-17 16:04 282624 --a------ C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2003-06-20 14:55 C:\WINDOWS\system32\CTHELPER.EXE]
"AsioReg"="REGSVR32.exe" [2004-08-04 18:56 C:\WINDOWS\system32\regsvr32.exe]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 19:53 C:\WINDOWS\soundman.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 11:52]
"nwiz"="nwiz.exe" [2004-04-23 14:24 C:\WINDOWS\system32\nwiz.exe]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 06:59]
"Nokia Tray Application"="C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe" [2003-02-10 14:30]
"DataLayer"="C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe" [2003-10-07 06:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-11 14:52]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-12-20 20:54]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 18:56 C:\WINDOWS\system32\bthprops.cpl]
"DriveSMART"="C:\PROGRA~1\COMPUA~1\smartapp.exe" []
"F5D9050"="C:\Program Files\Belkin\F5D9050\Belkinwcui.exe" [2006-03-14 15:52]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"ctqbgngx.exe"="C:\Documents and Settings\All Users\Application Data\ctqbgngx.exe" []
"SpyCatcher Reminder"="C:\Program Files\SpyCatcher\SpyCatcher.exe" [2007-05-07 11:56]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 23:40]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-10-08 12:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=secuload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
NtmlSvc

*Newly Created Service* - GTNDIS5

**************************************************************************

catchme 0.3.914 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-04 14:03:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwQueryDirectoryFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\WINDOWSGatorPdpSetup.log 32768 bytes
C:\WINDOWS\system32SahImages

scan completed successfully
hidden files: 2

**************************************************************************

Completion time: 2007-07-04 16:13:41
C:\ComboFix-quarantined-files.txt ... 2007-07-04 16:13

--- E O F ---
Disko_Stu is offline