12/04/07 activities & reports
1. Ran ComboFix - report files are below.
When ComboFix rebooted the computer WebRoot SpySweeper asked me for
its product key. Keyed it in, seems to be functioning OK.
Can any files created by ComboFix, especially ones in
c:\qoobox and below
ultimately be deleted?
2. Ran HiJackThis, report file below.
ComboFix-quarantined-files.txt
2007-11-20 14:39 17408 –a—— C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\~tmp1174.exe.vir
2007-11-20 14:54 23742 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Microsoft\25319.dat.vir
2007-12-04 11:04 736 –a—— C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME.reg.dat
——————————–
Log file from ComboFix
ComboFix 07-12-02.7 - Administrator 2007-12-04 11:03:10.1 -
FAT32x86
Running from: C:\cf\combofix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\~tmp1174.exe
C:\Program Files\Temporary
C:\WINDOWS\system32\config\system~1\Applic~1\Microsoft\25319.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_RUNTIME
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-04 10:08 . 2007-12-04 10:08 d-a—— C:\cf
2007-12-03 09:51 . 2007-12-03 09:51 d——– C:\fixware
2007-12-03 09:50 . 2007-12-03 09:50 d——– C:\otmove
2007-11-20 22:17 . 2007-11-20 22:17 29 –a—— C:\WINDOWS\system32\defruoip.tmp
2007-11-20 20:44 . 2007-12-04 11:08 2,184 –a—— C:\WINDOWS\system32\wpa.dbl
2007-11-20 14:39 . 2007-11-20 14:40 11,264 –a—— C:\WINDOWS\system\wecsnd32.dll
2007-11-20 14:39 . 2007-11-20 14:39 6,144 –a—— C:\Documents and Settings\Administrator\ie_update3r.exe
2007-11-12 09:17 . 2007-11-12 09:17 141 –a—— C:\NSMTEST.BAT
2007-11-11 16:05 . 2007-11-11 16:06 143 –a—— C:\NSMTEST.BAK
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 14:54 139 —-a-w C:\NSM.BAT
2007-10-20 17:05 ——— d—–w C:\Program Files\Citrix
2007-10-03 18:46 139 —-a-w C:\NSM_E.BAT
2007-09-10 17:19 158 —-a-w C:\nsm10.bat
2005-01-26 11:10 3,547 –sha-w C:\WINDOWS\bjcxk.dat
2004-12-26 07:43 70,144 –sha-w C:\WINDOWS\cugxf.dll
2005-01-01 00:17 70,144 –sha-w C:\WINDOWS\system32\awuqp.dll
2004-12-27 20:57 70,144 –sha-w C:\WINDOWS\system32\stlxe.dll
2005-02-01 03:05 7,471 –sha-w C:\WINDOWS\system32\xrijl.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-14 21:35]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\Antivirus\pccguide.exe" [2004-02-16 22:51]
"PCClient.exe"="C:\Program Files\Trend Micro\Antivirus\PCClient.exe" [2004-02-16 22:51]
"TM Outbreak Agent"="C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" [2004-02-16 22:50]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2006-07-07 17:16]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 14:05:56]
Quicken Startup.lnk - C:\quic2002\QWDLLS.EXE [2004-11-17 08:30:48]
Billminder.lnk - C:\quic2002\BILLMIND.EXE [2004-11-17 08:30:23]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\System32\wmfhotfix.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-07-08 09:25 1397760 ——— C:\Program Files\Ahead\InCD\InCD.exe
R0 SSFS041A;Spy Sweeper File System Filer Driver: 041A;C:\WINDOWS\System32\Drivers\SSFS041A.SYS
R3 neo20xx;neo20xx;C:\WINDOWS\System32\DRIVERS\neo20xx.sys
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\System32\DRIVERS\SonyPI.sys
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS
S4 Microsoft Inet Service;Microsoft Inet Service;C:\WINDOWS\System32\_svchost.exe -A
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 09:00:02 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&/ScheduleSweep=wrSpySweeperTrialSweep
"2007-12-01 10:00:02 C:\WINDOWS\Tasks\wrSpySweeper_FA584012640E49EA82E3CAAE8423A1A1.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_FA584012640E49EA82E3CAAE8423A1A1
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\,D:
"2007-12-03 09:00:02 C:\WINDOWS\Tasks\wrSpySweeper_4EA35A71447E46E98823393EA94301B7.job"
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-04 11:10:27
Windows 5.1.2600 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 11:12:04 - machine was rebooted
.
— E O F —
End Log file from ComboFix
——————————–
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:35 AM, on 12/4/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Antivirus\pccguide.exe
C:\Program Files\Trend Micro\Antivirus\PCClient.exe
C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\quic2002\QWDLLS.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\hijack\HijackThis.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O15 - Trusted Zone:
http://*.turbotax.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1161106391872
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} (GoToMeeting/GoToWebinar Web Starter) -
https://www.gotomeeting.com/default/applets/g2mdlax.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\wmfhotfix.dll
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
–
End of file - 3011 bytes
—– End HiJackThis log —–
—- End post —–