My full Hijack this Log, please check it!!!
asif New Member Date Joined Jun 2006 Total Posts : 8 Posted 9-30-2007 6:41 (GMT +1) Logfile of HijackThis v1.99.1 Scan saved at 23:35, on 2007-09-30 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Messenger\msmsgs.exe c:\windows\system32\winhost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\asif\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll O4 - HKLM\..\Run: [Microsoft InternetExplorer Update Check] C:\WINDOWS\iupdate.exe O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\cmd.exe /c cd /d C:\ComboFix\ & Combobatch.bat O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{FF68C4A5-447E-4363-A7F4-5FF1F2CC8045}: NameServer = 172.16.101.1 202.148.56.5 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe ********************************* ROOTCHK-(21-09-07)-LOG, by ejvindh Sun 09/30/2007 23:19:49.18 The rootkits that are detected by this tool were not found. ********************************* ROOTCHK-LOG-end catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-30 23:19:50 Windows 5.1.2600 Service Pack 2 scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... hidden processes: 0 hidden services: 0 hidden files: 0 2003-01-01 00:14 246272 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SSVICHOSST.exe.vir 2003-01-01 00:14 246272 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\SSVICHOSST.exe.vir 2006-09-14 21:21 32 --a------ C:\Qoobox\Quarantine\D\autorun.inf.vir 2007-07-08 21:23 15399 --a------ C:\Qoobox\Quarantine\C\ComboFix\FProps.vbs.vir 2007-09-30 22:33 109 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\autorun.ini.vir 2007-09-30 23:26 352 --a------ C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.dat Folder PATH listing Volume serial number is 0891-EE63 C:\QOOBOX\QUARANTINE +---C | +---ComboFix | | FProps.vbs.vir | | | \---WINDOWS | | SSVICHOSST.exe.vir | | | \---system32 | autorun.ini.vir | SSVICHOSST.exe.vir | +---Registry_backups | services_nm.reg.dat | \---D autorun.inf.vir
ComboFix 07-09-21.2 - "asif" 2007-09-30 23:37:42.2 - FAT32 x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.70 [GMT 6:00] . ((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-30 ))))))))))))))))))))))))))))))) . 2007-09-30 23:23 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-09-30 23:15 <DIR> d-------- C:\Program Files\CCleaner 2007-09-30 23:11 <DIR> d-------- C:\Program Files\Flash Slideshow Maker Professional 2007-09-25 16:00 24,384 --a------ C:\DOCUME~1\asif\APPLIC~1\GDIPFONTCACHEV1.DAT 2007-09-25 02:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP 2007-09-25 02:07 <DIR> d-------- C:\WINDOWS\Easy CD-DA Extractor 2007-09-25 02:07 <DIR> d-------- C:\Program Files\Easy CD-DA Extractor 10 2007-09-23 14:48 <DIR> d--hs---- C:\FOUND.030 2007-09-22 16:03 <DIR> d--hs---- C:\FOUND.029 2007-09-19 16:42 <DIR> d--hs---- C:\FOUND.028 2007-09-18 12:39 <DIR> d--hs---- C:\FOUND.027 2007-09-08 16:55 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-09-08 16:55 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-09-08 16:55 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-09-08 16:55 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys 2007-09-08 00:10 <DIR> d--hs---- C:\FOUND.026 2007-09-06 19:28 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-08-30 01:15 719,872 --a------ C:\WINDOWS\system32\devil.dll 2007-08-30 01:15 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll 2007-08-30 01:15 66,560 --a------ C:\WINDOWS\MOTA113.exe 2007-08-30 01:15 502,784 --a------ C:\WINDOWS\x2.64.exe 2007-08-30 01:15 394,240 --a------ C:\WINDOWS\system32\Smab.dll 2007-08-30 01:15 318,976 --a------ C:\WINDOWS\system32\avisynth.dll 2007-08-30 01:15 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll 2007-08-30 01:15 240,128 --a------ C:\WINDOWS\system32\x.264.exe 2007-08-30 01:15 217,073 --a------ C:\WINDOWS\meta4.exe 2007-08-30 01:15 <DIR> d-------- C:\Program Files\AviSynth 2.5 2007-08-30 01:14 31,232 -r-hs---- C:\WINDOWS\system32\msfDX.dll 2007-08-30 01:14 163,328 -r-hs---- C:\WINDOWS\system32\flvDX.dll 2007-08-30 01:14 <DIR> d-------- C:\Program Files\eRightSoft 2007-08-29 10:11 <DIR> d--hs---- C:\FOUND.025 2007-08-25 15:21 <DIR> d--hs---- C:\FOUND.024 2007-08-20 21:13 <DIR> d--hs---- C:\FOUND.023 2007-08-20 15:04 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll 2007-08-20 15:04 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys 2007-08-20 15:04 53,760 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll 2007-08-20 15:04 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS 2007-08-20 15:04 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys 2007-08-20 15:04 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys 2007-08-20 15:04 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe 2007-08-19 23:06 <DIR> d-------- C:\Program Files\Winamp 2007-08-19 22:47 122,928 --a------ C:\WINDOWS\system32\drivers\spca561.sys 2007-08-19 22:42 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2007-08-19 22:42 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys 2007-08-18 18:23 <DIR> d--hs---- C:\FOUND.022 2007-08-18 09:39 <DIR> d--hs---- C:\FOUND.021 2007-08-16 20:07 <DIR> d--hs---- C:\FOUND.020 2007-08-12 23:23 <DIR> d-------- C:\Program Files\TeamManager 2007-08-07 01:53 <DIR> d-------- C:\Program Files\Sony Ericsson . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-30 23:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2007-09-30 23:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-09-30 23:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2007-09-30 23:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-09-07 13:50 82061 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-09-07 13:50 81549 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-07-30 15:21 --------- dr-h----- C:\Program Files\rnamfler 2007-07-30 01:44 --------- d-------- C:\DOCUME~1\asif\APPLIC~1\Syntrillium 2007-07-30 01:43 --------- d-------- C:\Program Files\coolpro2 2007-07-13 02:27 65536 --a------ C:\WINDOWS\IFinst27.exe 2007-06-28 12:51 206088 --a------ C:\WINDOWS\system32\klogon.dll 2007-06-15 13:38 1521216 --a------ C:\WINDOWS\WRSetup.dll 2007-06-08 10:52 135168 --a------ C:\WINDOWS\system32\34api.dll 2007-06-08 10:52 110592 --a------ C:\WINDOWS\system32\Prop7134.dll 2007-06-08 10:52 110592 --a------ C:\WINDOWS\system32\34com.dll 2007-06-06 02:19 107132 --a------ C:\WINDOWS\UninstallFirefox.exe 2007-06-03 14:31 10752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll 2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Microsoft InternetExplorer Update Check"="C:\WINDOWS\iupdate.exe" [2007-01-04 00:06] "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickTV.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickTV.lnk backup=C:\WINDOWS\pss\QuickTV.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SvcHost] C:\WINDOWS\svchost.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] C:\WINDOWS\UpdReg.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch] CTHELPER.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe R3 Cap7134;AVerMedia, AVerTV WDM Video Capture (Silicon);C:\WINDOWS\system32\DRIVERS\Cap7134.sys R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys R3 PhTVTune;Cap7134 TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys S3 W700bus;Sony Ericsson W700 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\W700bus.sys S3 W700mdfl;Sony Ericsson W700 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\W700mdfl.sys S3 W700mdm;Sony Ericsson W700 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\W700mdm.sys S3 W700mgmt;Sony Ericsson W700 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\W700mgmt.sys S3 W700obex;Sony Ericsson W700 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\W700obex.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14423886-1782-11dc-8240-00e04c316fed}] 1\AutoPlay\command- kopa.exe e AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL kopa.exe e Explore\command- kopa.exe e Open\command- kopa.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25af86ac-14d3-11dc-8239-00e04c316fed}] 1\AutoPlay\command- I:\kopa.exe e AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL kopa.exe e Explore\command- I:\kopa.exe e Open\command- I:\kopa.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{652efaae-1e53-11dc-8254-00e04c316fed}] AutoRun\command- SSVICHOSST.exe Open\command- SSVICHOSST.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6fa19984-221c-11dc-8262-00e04c316fed}] Auto\command- NTDETECT.EXE e AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NTDETECT.EXE e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6fa19985-221c-11dc-8262-00e04c316fed}] Auto\command- NTDETECT.EXE e AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NTDETECT.EXE e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7e7b98c8-20a1-11dc-825b-00e04c316fed}] auto\command- Knight.exe open AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open explore\command- Knight.exe open find\command- Knight.exe open install\command- Knight.exe open open\command- Knight.exe open [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e416042-2b9d-11dc-b5ce-00e04c316fed}] Auto\command- I:\sxs.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f85aeab4-4bed-11dc-b635-00e04c316fed}] AutoRun\command- Copy of Desktop.ini explore\Command- Copy of Desktop.ini open\Command- Copy of Desktop.ini . Contents of the 'Scheduled Tasks' folder "2007-09-30 16:08:14 C:\WINDOWS\Tasks\At1.job" - C:\WINDOWS\system32\SSVICHOSST.exe . ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-30 23:39:32 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-09-30 23:40:46 C:\ComboFix-quarantined-files.txt ... 2007-09-30 23:40 . --- E O F --- Back to Top
Forum Information Currently it is Friday, January 09, 2009 11:24 PM (GMT +1) There are a total of 66.008 posts in 16.187 threads. In the last 3 days there were 18 new threads and 108 reply posts. View Active Threads Who's Online This forum has 27804 registered members. Please welcome our newest member, revmrf . 53 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads