This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Need help analyzing ComboFix log

6 min read

This thread's last reply is from August 27, 2008, 4:52 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I ran ComboFix and now need your help in analyzing the log file to make sure nothing bad is still on my computer. Please note that I have uninstalled AVG since ComboFix was run. Thanks. -- A. Tagore



ComboFix 08-08-26.02 - Owner 2008-08-27 3:34:57.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.443 [GMT -5:00]

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4KYLD8J9\bin.clearspring.com

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4KYLD8J9\bin.clearspring.com\clearspring.sol

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol

C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt

C:\WINDOWS\system32\gjjlm.ini2

C:\WINDOWS\system32\lnnmp.ini2

C:\WINDOWS\system32\lnnmp.tmp

C:\WINDOWS\system32\mdm.exe

C:\WINDOWS\system32\opqss.ini2

C:\WINDOWS\system32\opqss.tmp

D:\Autorun.inf

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_IPRIP

-------\Service_Iprip



((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))

.

2008-08-26 04:16 . 2008-06-10 02:32 73,728 --a--c--- C:\WINDOWS\system32\javacpl.cpl

2008-08-26 04:08 . 2008-08-26 04:16 <DIR> d----c--- C:\Program Files\Java

2008-08-25 22:34 . 2008-08-25 22:34 <DIR> d----c--- C:\Program Files\Lavasoft

2008-08-25 22:32 . 2008-08-25 22:32 <DIR> d----c--- C:\Program Files\Common Files\Wise Installation Wizard

2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware

2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Malwarebytes

2008-08-25 19:31 . 2008-08-25 19:31 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes

2008-08-25 19:31 . 2008-08-17 15:05 38,472 --a--c--- C:\WINDOWS\system32\drivers\mbamswissarmy.sys

2008-08-25 19:31 . 2008-08-17 15:05 17,144 --a--c--- C:\WINDOWS\system32\drivers\mbam.sys

2008-08-25 08:35 . 2008-08-25 09:06 <DIR> d----c--- C:\Program Files\Yahoo!

2008-08-25 08:35 . 2008-08-25 08:37 <DIR> d----c--- C:\Program Files\CCleaner

2008-08-24 19:47 . 2008-08-27 03:29 <DIR> d--h-c--- C:\$AVG8.VAULT$

2008-08-24 18:49 . 2008-08-27 03:57 <DIR> d----c--- C:\WINDOWS\system32\drivers\Avg

2008-08-24 18:49 . 2008-08-24 18:49 96,520 --a--c--- C:\WINDOWS\system32\drivers\avgldx86.sys

2008-08-24 18:49 . 2008-08-24 18:49 10,520 --a--c--- C:\WINDOWS\system32\avgrsstx.dll

2008-08-24 18:48 . 2008-08-24 18:48 <DIR> d----c--- C:\Program Files\AVG

2008-08-24 18:48 . 2008-08-24 18:48 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg8

2008-08-24 12:02 . 2008-08-24 18:28 <DIR> d----c--- C:\Program Files\Spybot - Search & Destroy

2008-08-24 09:24 . 2008-08-22 17:22 3,262 --a--c--- C:\WINDOWS\system32\2.ico

2008-08-24 09:23 . 2008-08-25 08:10 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\TmpRecentIcons

2008-08-24 09:20 . 2008-08-25 23:56 <DIR> d----c--- C:\Program Files\MSA

2008-08-24 09:20 . 2008-08-22 17:22 3,262 --a--c--- C:\WINDOWS\system32\1.ico

2008-08-24 07:52 . 2008-08-25 06:25 <DIR> d----c--- C:\Program Files\DNA

2008-08-20 11:34 . 2008-08-20 11:34 <DIR> d----c--- C:\Program Files\FileZilla Client

2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\system32\scripting

2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\system32\en

2008-08-20 07:24 . 2008-08-20 07:24 <DIR> d----c--- C:\WINDOWS\l2schemas

2008-08-19 20:31 . 2008-04-13 19:12 712,704 -----c--- C:\WINDOWS\system32\windowscodecs.dll

2008-08-19 20:31 . 2008-04-13 19:12 346,112 -----c--- C:\WINDOWS\system32\windowscodecsext.dll

2008-08-19 20:31 . 2008-04-13 19:12 276,992 -----c--- C:\WINDOWS\system32\wmphoto.dll

2008-08-19 20:31 . 2008-04-13 19:12 69,120 -----c--- C:\WINDOWS\system32\wlanapi.dll

2008-08-19 20:31 . 2008-04-13 19:12 53,248 -----c--- C:\WINDOWS\system32\tsgqec.dll

2008-08-19 20:31 . 2008-04-13 19:12 50,688 -----c--- C:\WINDOWS\system32\tspkg.dll

2008-08-19 20:30 . 2008-04-13 19:12 412,160 -----c--- C:\WINDOWS\system32\photometadatahandler.dll

2008-08-19 20:30 . 2008-04-13 19:12 291,328 -----c--- C:\WINDOWS\system32\qagentrt.dll

2008-08-19 20:30 . 2008-04-13 19:12 290,304 -----c--- C:\WINDOWS\system32\rhttpaa.dll

2008-08-19 20:30 . 2008-04-13 19:12 150,528 -----c--- C:\WINDOWS\system32\qagent.dll

2008-08-19 20:30 . 2008-04-13 19:12 144,384 -----c--- C:\WINDOWS\system32\onex.dll

2008-08-19 20:30 . 2008-04-13 19:12 76,800 -----c--- C:\WINDOWS\system32\qutil.dll

2008-08-19 20:30 . 2008-04-13 19:12 62,464 -----c--- C:\WINDOWS\system32\qcliprov.dll

2008-08-19 20:30 . 2008-04-13 19:12 61,952 -----c--- C:\WINDOWS\system32\rasqec.dll

2008-08-19 20:30 . 2008-04-13 19:12 32,768 -----c--- C:\WINDOWS\system32\setupn.exe

2008-08-19 20:30 . 2008-04-13 13:40 10,240 -----c--- C:\WINDOWS\system32\drivers\sffp_mmc.sys

2008-08-19 20:28 . 2008-04-13 19:11 650,752 -----c--- C:\WINDOWS\system32\dot3ui.dll

2008-08-19 20:27 . 2008-04-13 19:11 233,472 -----c--- C:\WINDOWS\system32\azroles.dll

2008-08-19 20:27 . 2008-04-13 19:11 136,192 -----c--- C:\WINDOWS\system32\aaclient.dll

2008-08-19 20:27 . 2008-04-13 19:11 12,800 -----c--- C:\WINDOWS\system32\credssp.dll

2008-08-19 20:27 . 2008-04-13 19:11 7,168 -----c--- C:\WINDOWS\system32\bitsprx4.dll

2008-08-14 14:40 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll

2008-08-08 08:52 . 2008-08-08 08:52 124,168 --a--c--- C:\WINDOWS\system32\PPPFilt.dll

2008-07-27 08:50 . 2008-07-27 08:50 20 --ahsc--- C:\ArcDeviceInfo

2008-07-27 08:48 . 2008-07-27 08:48 94 --a--c--- C:\WINDOWS\MusicRip.ini

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-27 08:57 81,984 -c--a-w C:\WINDOWS\system32\bdod.bin

2008-08-26 10:46 --------- dc----w C:\Documents and Settings\Owner\Application Data\FileZilla

2008-08-26 10:10 --------- dc----w C:\Documents and Settings\Owner\Application Data\AdobeUM

2008-08-26 03:36 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-08-25 13:59 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-08-25 12:42 --------- dc----w C:\Program Files\Eusing Free Registry Cleaner

2008-08-07 00:05 --------- dc----w C:\Program Files\MozyHome

2008-08-04 15:35 --------- dc----w C:\Program Files\Common Files\Adobe

2008-07-30 12:31 --------- dc----w C:\Program Files\Avery Wizard 3.1

2008-07-27 13:47 --------- dc----w C:\Documents and Settings\Owner\Application Data\ArcSoft

2008-07-27 11:19 --------- dc----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound

2008-07-18 01:18 --------- dc----w C:\Documents and Settings\Owner\Application Data\PACE Anti-Piracy

2008-07-18 01:18 --------- dc----w C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy

2008-07-18 01:17 --------- dc----w C:\Program Files\Common Files\PACE Anti-Piracy

2008-07-18 01:00 --------- dc----w C:\Program Files\Write Brothers, Inc

2008-07-14 23:47 --------- dc-h--w C:\Program Files\InstallShield Installation Information

2008-07-14 23:44 --------- dc----w C:\Program Files\Common Files\Avery

2008-07-14 15:25 53,752 -c--a-w C:\WINDOWS\system32\drivers\mozy.sys

2008-07-09 10:27 124,168 -c--a-w C:\WINDOWS\system32\WPPFilt.dll

2008-07-07 20:26 253,952 -c--a-w C:\WINDOWS\system32\es.dll

2008-07-02 19:31 86,792 -c--a-w C:\WINDOWS\system32\drivers\bdfndisf.sys

2008-06-24 16:43 74,240 -c--a-w C:\WINDOWS\system32\mscms.dll

2008-06-23 16:57 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll

2008-06-20 17:46 245,248 -c--a-w C:\WINDOWS\system32\mswsock.dll

2007-07-04 12:14 25,715 -c--a-w C:\Program Files\ICOFormat-1.6f9-win.zip

2005-05-26 19:35 1,422 -c--a-w C:\Program Files\ReadMe.txt

2004-04-14 12:47 2,095,388 -c--a-w C:\Program Files\TaxCut_2003_California_InstallerC.exe

2004-04-14 12:20 17,462,272 -c--a-w C:\Program Files\TaxCut2003FederalEZB.exe

2004-04-13 10:46 219,840 -c--a-w C:\Program Files\MSNToolbarSetup_en-us_PPD.exe

2004-04-13 09:44 403,968 -c--a-w C:\Program Files\JustZIPit.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]

@="{747E722C-CB46-4A9D-BDFE-192AAD5099B1}"

[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4A9D-BDFE-192AAD5099B1}]

2008-07-14 10:26 2405680 --a--c--- C:\Program Files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]

@="{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}"

[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}]

2008-07-14 10:26 2405680 --a--c--- C:\Program Files\MozyHome\mozyshell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]

"RCUI"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCUI.exe" [2007-11-29 19:48 380928]

"RCHotKey"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2007-11-29 19:44 18944]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 14:32 94208]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 10:01 110592]

"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 23:42 212992]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 07:03 221184]

"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 16:55 155648]

"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]

"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 04:55 483328]

"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-03-09 15:30 188416]

"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54 241664]

"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 16:51 118784]

"CamMonitor"="c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 09:23 90112]

"FileZilla Server Interface"="C:\Program Files\FileZilla Server\FileZilla Server Interface.exe" [2007-10-19 13:05 937984]

"RCHotKey"="C:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2007-11-29 19:44 18944]

"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]

"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]

"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-07-02 14:31 368640]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-24 18:49 1232152]

"LTMSG"="LTMSG.exe" [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 23:37:56 217194]

Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]

HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 10:20:40 233472]

MozyHome Status.lnk - C:\Program Files\MozyHome\mozystat.exe [2008-04-16 00:47:12 2311472]

TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-06-12 04:30:12 270336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dllzwebauth.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]

backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\WINDOWS\\system32\\sessmgr.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\RingCentral\\RingCentral Call Controller\\RCUI.exe"=

"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=

"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-24 18:49]

R1 HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1;HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1;C:\WINDOWS\system32\drivers\HMFAxCoreace37e6ed7bc6b8f8ec8ba8a5fc5b2b1.sys [2007-09-01 03:28]

R1 mozyFilter;mozyFilter;C:\WINDOWS\system32\DRIVERS\mozy.sys [2008-07-14 10:25]

R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-24 18:48]

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-07-02 14:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bdx REG_MULTI_SZ scan

.

- - - - ORPHANS REMOVED - - - -

BHO-{3F5E9987-FD12-408E-3612-018845CDF059} - (no file)

BHO-{EBF8AC57-E6F6-4041-8A3F-9F5B9E61407C} - (no file)

Toolbar-{18C388BB-5014-4906-AE38-E62BA5AA7387} - (no file)

HKLM-Run-NWEReboot - (no file)

Notify-efcbyyv - efcbyyv.dll

MSConfigStartUp-CTDrive - C:\WINDOWS\system32\drvbaz.dll

MSConfigStartUp-jihqvazg - C:\Program Files\jihqvazg\ngrehcdg.dll

MSConfigStartUp-khalypah - C:\Program Files\khalypah\cfarkpwl.dll

MSConfigStartUp-ojobmrwb - C:\Documents and Settings\All Users\Application Data\ojobmrwb.dll



.

------- Supplementary Scan -------

.

FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qawgis31.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com

.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-27 03:52:08

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe

-> C:\Program Files\MozyHome\mozyshell.dll

.

------------------------ Other Running Processes ------------------------

.

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\Program Files\FileZilla Server\FileZilla server.exe

C:\Program Files\MozyHome\mozybackup.exe

C:\WINDOWS\system32\hpzipm12.exe

C:\WINDOWS\system32\tcpsvcs.exe

C:\WINDOWS\system32\snmp.exe

C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe

C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

.

**************************************************************************

.

Completion time: 2008-08-27 4:10:37 - machine was rebooted

ComboFix-quarantined-files.txt 2008-08-27 09:09:59

Pre-Run: 44,156,293,120 bytes free

Post-Run: 44,101,390,336 bytes free

236 --- E O F --- 2008-08-21 11:05:00
Helllo tagore,

You posted in 72 hours bump room, which is for users which didn't have a reply yet after 72 hours.

Please open a thread here so you may get help:
viewforum.php?f=11
----------------------------------------------
Your Combofix is unreadable.

This is caused by having Word Wrap checked.

1. Click Start > All Programs > Accessories > Notepad
2. On the menu bar in Notepad select Format and click on WordWrap so it appears un-checked and then post Combofix report again.

Also read here and post HijackThis with your Combofix report.

Re-install immediately your Anti-Virus.