Damon129
Topic Starter
Hello,
I followed all the instructions in this thread:
http://forums.whatthetech.com/Unable_to_run_HijackThis_t94050.html
I would like to post my HijackThis log file as well as my Combo Fix log file for review and for one of the experts here to tell me if there is anything left for me to do.
HIJACK THIS LOG FILE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:27 AM, on 8/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Parallels\Parallels Tools\cohrence.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Parallels Tools] C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144884804046
O20 - AppInit_DLLs: lalwzj.dll kelurv.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Parallels Coherence Service (cohrence) - Parallels Software International, Inc. - C:\Program Files\Parallels\Parallels Tools\cohrence.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
–
End of file - 4504 bytes
CF LOG FILE
ComboFix 08-08-01.04 - User 2008-08-02 9:26:27.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.275 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\efcBttrS.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MWwHNqss.ini
C:\WINDOWS\system32\MWwHNqss.ini2
C:\WINDOWS\system32\ssqNHwWM.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-08-02 09:04 . 2008-08-02 09:04 d——– C:\Program Files\Trend Micro
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Documents and Settings\User\Application Data\Malwarebytes
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-02 08:55 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-02 08:55 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-02 08:29 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-02 08:29 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-02 08:29 . 2008-05-29 09:35 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-02 08:29 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-02 08:29 . 2008-07-02 13:33 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-02 08:29 . 2008-05-23 18:21 81,920 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-02 08:29 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-02 08:29 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-02 08:29 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-02 08:29 . 2008-08-02 08:29 1,918 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-02 08:22 . 2008-08-02 08:22 d–hs—- C:\FOUND.007
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Program Files\Spyware Doctor
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Documents and Settings\User\Application Data\PC Tools
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 08:11 . 2008-08-02 08:11 130,432 ——— C:\WINDOWS\system32\kelurv.dll
2008-08-02 08:11 . 2008-06-10 21:22 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-02 08:11 . 2008-06-02 15:19 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-02 08:11 . 2008-06-02 15:19 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-02 08:11 . 2008-06-02 15:19 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-08-02 08:04 . 2008-08-02 08:04 d——– C:\Documents and Settings\Administrator
2008-08-01 15:18 . 2008-08-01 15:18 d——– C:\Program Files\CCleaner
2008-08-01 15:13 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-08-01 13:54 . 2008-08-01 13:55 129,920 –a—— C:\WINDOWS\system32\pvpkmdij.dll
2008-08-01 13:54 . 2008-08-01 13:55 129,920 –a—— C:\WINDOWS\system32\lalwzj.dll
2008-08-01 13:48 . 2008-08-01 13:48 dr-h—– C:\$VAULT$.AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 20:01 ——— d—–w C:\Program Files\Common Files\SolidWorks Shared
2008-06-03 20:01 ——— d—–w C:\Program Files\Common Files\eDrawings2008
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-08-01 15:22 579584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-03 10:06 6731312]
"Parallels Tools"="C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe" [2007-06-21 15:25 2506864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-26 12:24 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lalwzj.dll kelurv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 PrlNP;PrlNP;C:\WINDOWS\system32\DRIVERS\prlfs.sys [2007-06-21 15:12]
R2 cohrence;Parallels Coherence Service;C:\Program Files\Parallels\Parallels Tools\cohrence.exe [2007-06-21 15:26]
R2 PrlTime;Parallels Time Synchronization Driver;C:\WINDOWS\system32\drivers\PrlTime.sys [2007-06-21 15:26]
R3 PCITG;PCITG;C:\WINDOWS\system32\drivers\pcitg.sys [2007-06-21 15:13]
R3 PrlMouse;Parallels Mouse Synchronization Tool;C:\WINDOWS\system32\DRIVERS\PrlMouse.sys [2007-06-21 15:26]
R3 PrlVideo;PrlVideo;C:\WINDOWS\system32\DRIVERS\PrlVideo.sys [2007-06-21 15:26]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 13:47]
S3 prleth;Parallels Network Adapter;C:\WINDOWS\system32\DRIVERS\prleth.sys [2007-06-21 15:26]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rnncp3nn.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-02 09:28:47
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\prlnp.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
.
**************************************************************************
.
Completion time: 2008-08-02 9:29:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-02 13:29:26
Pre-Run: 3,388,608,512 bytes free
Post-Run: 3,341,344,768 bytes free
135 — E O F — 2008-07-11 12:17:19
Thanks!
I followed all the instructions in this thread:
http://forums.whatthetech.com/Unable_to_run_HijackThis_t94050.html
I would like to post my HijackThis log file as well as my Combo Fix log file for review and for one of the experts here to tell me if there is anything left for me to do.
HIJACK THIS LOG FILE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:27 AM, on 8/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Parallels\Parallels Tools\cohrence.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Parallels Tools] C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144884804046
O20 - AppInit_DLLs: lalwzj.dll kelurv.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Parallels Coherence Service (cohrence) - Parallels Software International, Inc. - C:\Program Files\Parallels\Parallels Tools\cohrence.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
–
End of file - 4504 bytes
CF LOG FILE
ComboFix 08-08-01.04 - User 2008-08-02 9:26:27.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.275 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\efcBttrS.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MWwHNqss.ini
C:\WINDOWS\system32\MWwHNqss.ini2
C:\WINDOWS\system32\ssqNHwWM.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-08-02 09:04 . 2008-08-02 09:04 d——– C:\Program Files\Trend Micro
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Documents and Settings\User\Application Data\Malwarebytes
2008-08-02 08:55 . 2008-08-02 08:55 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-02 08:55 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-02 08:55 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-02 08:29 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-02 08:29 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-02 08:29 . 2008-05-29 09:35 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-02 08:29 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-02 08:29 . 2008-07-02 13:33 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-02 08:29 . 2008-05-23 18:21 81,920 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-02 08:29 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-02 08:29 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-02 08:29 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-02 08:29 . 2008-08-02 08:29 1,918 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-02 08:22 . 2008-08-02 08:22 d–hs—- C:\FOUND.007
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Program Files\Spyware Doctor
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Documents and Settings\User\Application Data\PC Tools
2008-08-02 08:11 . 2008-08-02 08:11 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 08:11 . 2008-08-02 08:11 130,432 ——— C:\WINDOWS\system32\kelurv.dll
2008-08-02 08:11 . 2008-06-10 21:22 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-02 08:11 . 2008-06-02 15:19 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-02 08:11 . 2008-06-02 15:19 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-02 08:11 . 2008-06-02 15:19 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-08-02 08:04 . 2008-08-02 08:04 d——– C:\Documents and Settings\Administrator
2008-08-01 15:18 . 2008-08-01 15:18 d——– C:\Program Files\CCleaner
2008-08-01 15:13 . 2002-12-29 01:14 81,920 –a—— C:\WINDOWS\system32\Startup.cpl
2008-08-01 13:54 . 2008-08-01 13:55 129,920 –a—— C:\WINDOWS\system32\pvpkmdij.dll
2008-08-01 13:54 . 2008-08-01 13:55 129,920 –a—— C:\WINDOWS\system32\lalwzj.dll
2008-08-01 13:48 . 2008-08-01 13:48 dr-h—– C:\$VAULT$.AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 20:01 ——— d—–w C:\Program Files\Common Files\SolidWorks Shared
2008-06-03 20:01 ——— d—–w C:\Program Files\Common Files\eDrawings2008
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-08-01 15:22 579584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-03 10:06 6731312]
"Parallels Tools"="C:\Program Files\Parallels\Parallels Tools\ParallelsToolsCenter.exe" [2007-06-21 15:25 2506864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-26 12:24 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lalwzj.dll kelurv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 PrlNP;PrlNP;C:\WINDOWS\system32\DRIVERS\prlfs.sys [2007-06-21 15:12]
R2 cohrence;Parallels Coherence Service;C:\Program Files\Parallels\Parallels Tools\cohrence.exe [2007-06-21 15:26]
R2 PrlTime;Parallels Time Synchronization Driver;C:\WINDOWS\system32\drivers\PrlTime.sys [2007-06-21 15:26]
R3 PCITG;PCITG;C:\WINDOWS\system32\drivers\pcitg.sys [2007-06-21 15:13]
R3 PrlMouse;Parallels Mouse Synchronization Tool;C:\WINDOWS\system32\DRIVERS\PrlMouse.sys [2007-06-21 15:26]
R3 PrlVideo;PrlVideo;C:\WINDOWS\system32\DRIVERS\PrlVideo.sys [2007-06-21 15:26]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 13:47]
S3 prleth;Parallels Network Adapter;C:\WINDOWS\system32\DRIVERS\prleth.sys [2007-06-21 15:26]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rnncp3nn.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-02 09:28:47
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\prlnp.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
.
**************************************************************************
.
Completion time: 2008-08-02 9:29:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-02 13:29:26
Pre-Run: 3,388,608,512 bytes free
Post-Run: 3,341,344,768 bytes free
135 — E O F — 2008-07-11 12:17:19
Thanks!