Page 1 of 1

my buddy's log.

PostPosted: Tue May 13, 2008 11:01 am
by modernsamurai
buddy of mine's been having issues with his comp. here's his log.
Logfile of HijackThis v1.99.1
Scan saved at 2:44:01 AM, on 5/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PRISMSVR.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Administrator\Desktop\HJT\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

Re: my buddy's log.

PostPosted: Tue May 13, 2008 11:38 am
by Gecko
modernsamurai,

Have him download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.


When it's done running it will produce a log for you. Please post that log in your next reply.

Re: my buddy's log.

PostPosted: Tue May 13, 2008 12:06 pm
by modernsamurai
ComboFix 08-05-12.1 - Administrator 2008-05-13 3:55:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.225 [GMT -7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.

2008-05-13 03:35 . 2008-05-13 03:35 1,169 --a------ C:\WINDOWS\mozver.dat
2008-05-13 02:34 . 2008-05-13 02:34 <DIR> d-------- C:\Program Files\CCleaner
2008-05-13 02:00 . 2008-05-13 02:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-13 02:00 . 2008-05-13 02:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-13 01:58 . 2002-08-29 03:41 150,528 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-05-13 01:58 . 2002-08-29 01:48 14,208 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-13 01:58 . 2002-08-29 01:48 14,208 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-13 01:58 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-05-13 01:50 . 2008-05-13 01:50 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-05-13 01:50 . 2008-05-13 01:50 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-13 01:50 . 2008-05-13 01:50 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-13 01:50 . 2008-05-13 01:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-13 01:42 . 2008-05-13 01:42 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-13 01:42 . 2008-05-13 01:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-13 01:26 . 2008-05-13 01:26 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-13 01:22 . 2008-05-13 01:22 <DIR> d-------- C:\WUTemp
2008-05-13 01:22 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuengine.dll
2008-05-13 01:22 . 2003-08-25 18:06 182,880 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2008-05-13 01:22 . 2005-09-20 09:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-05-13 01:18 . 2008-05-13 01:18 <DIR> d-------- C:\Program Files\Dell TrueMobile
2008-05-13 01:18 . 2008-05-13 01:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prism
2008-05-13 01:18 . 2003-10-20 15:31 651,264 -ra------ C:\WINDOWS\system32\libeay32.dll
2008-05-13 01:18 . 2003-10-20 15:31 507,904 -ra------ C:\WINDOWS\system32\AegisE5.dll
2008-05-13 01:18 . 2003-11-20 14:08 360,537 --a------ C:\WINDOWS\system32\PRISMAPI.dll
2008-05-13 01:18 . 2003-11-20 14:12 282,713 --a------ C:\WINDOWS\system32\PRISMSVR.exe
2008-05-13 01:18 . 2003-10-20 15:32 147,456 -ra------ C:\WINDOWS\system32\ssleay32.dll
2008-05-13 01:18 . 2003-10-20 15:31 15,781 -ra------ C:\WINDOWS\system32\drivers\mdc8021x.sys
2008-05-13 01:17 . 2008-05-13 01:17 <DIR> d-------- C:\Program Files\Digital Line Detect
2008-05-13 01:17 . 2008-05-13 01:17 <DIR> d-------- C:\Program Files\Creative
2008-05-13 01:17 . 2003-03-05 12:19 15,840 --------- C:\WINDOWS\system32\drivers\PFMODNT.SYS
2008-05-13 01:15 . 2008-05-13 01:15 <DIR> d-------- C:\drvrtmp
2008-05-13 01:15 . 2003-02-11 09:58 126,976 --a------ C:\WINDOWS\system32\e1000msg.dll
2008-05-13 01:15 . 2003-07-11 10:58 121,856 --a------ C:\WINDOWS\system32\drivers\e1000325.sys
2008-05-13 01:15 . 2003-07-11 12:15 118,784 --a------ C:\WINDOWS\system32\Prounstl.exe
2008-05-13 01:15 . 2002-12-29 05:00 24,064 --a------ C:\WINDOWS\system32\IntelNic.dll
2008-05-13 01:15 . 2002-09-03 02:34 2,725 -ra------ C:\WINDOWS\system32\e1000325.din
2008-05-13 01:12 . 2008-05-13 01:12 <DIR> d-------- C:\Program Files\Dell TrueMobile 2300
2008-05-13 01:09 . 2008-05-13 01:13 <DIR> d-------- C:\Program Files\Intel
2008-05-13 01:08 . 2008-05-13 01:08 <DIR> d-------- C:\Program Files\Analog Devices
2008-05-13 01:08 . 2001-09-19 13:32 720,896 --a------ C:\WINDOWS\system32\a3d.dll
2008-05-13 01:07 . 2008-05-13 01:07 <DIR> d-------- C:\Program Files\NetWaiting
2008-05-13 01:07 . 2008-05-13 01:18 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-05-13 01:07 . 2008-05-13 01:18 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-05-13 01:07 . 2008-05-13 01:07 <DIR> d-------- C:\dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 07:12 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-13 07:11 558,142 ----a-w C:\WINDOWS\java\Packages\YG3Z3T71.ZIP
2008-05-13 07:11 155,995 ----a-w C:\WINDOWS\java\Packages\W67HR7RT.ZIP
.

------- Sigcheck -------

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRISMSVR.EXE"="C:\WINDOWS\System32\PRISMSVR.exe" [2003-11-20 14:12 282713]
"igfxtray"="C:\WINDOWS\System32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxhkcmd"="C:\WINDOWS\System32\hkcmd.exe" [2005-09-20 09:32 77824]
"igfxpers"="C:\WINDOWS\System32\igfxpers.exe" [2005-09-20 09:36 114688]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-05-13 01:17:56 24576]


*Newly Created Service* - AAWSERVICE
*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 03:56:21
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-13 3:56:57
ComboFix-quarantined-files.txt 2008-05-13 10:56:55

Pre-Run: 36,869,632,000 bytes free
Post-Run: 36,872,482,816 bytes free

94

Re: my buddy's log.

PostPosted: Tue May 13, 2008 5:05 pm
by Gecko