Jump to content

Computer slow and can't start in safe mode


Recommended Posts

Hello, i had a Trojan before and malwarebyte removed it, but i seems to me that it came back i think because my computer is slower (i have to wait for it to load before it can execute programs properly). I also have Trend Mirco, but it doesn't work properly and there is no way to exit the program to run combofix properly. I also have hijack.regedit and hijack.taskmanager which malware byte picks up and can delete but i just comes back. I have Task Killer and have been tld to use FixPolitics but it doesn't work after you restart the computer. When i ran ComboFix today, after it done the stages, it said couln't run something because it wasn't a batch or something. I think my "Trojan" infected it already when i ran it.

ComboFix log:

ComboFix 09-03-31.01 - User 2009-04-01 15:52:57.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1545 [GMT 10:00]

Running from: c:\documents and settings\User\Desktop\ComboFix.exe

AV: Trend Micro Internet Security Pro *On-access scanning enabled* (Updated)

FW: Trend Micro Personal Firewall *enabled*

* Created a new restore point

.

((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))

.

2009-03-29 19:40 . 2009-03-29 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet

2009-03-29 19:07 . 2007-02-20 16:04 2,463,976 --a------ c:\windows\system32\NPSWF32.dll

2009-03-29 19:07 . 2007-02-20 16:04 190,696 --a------ c:\windows\system32\NPSWF32_FlashUtil.exe

2009-03-29 18:56 . 2009-03-29 18:56 <DIR> d-------- c:\program files\Common Files\Macrovision Shared

2009-03-15 19:34 . 2008-04-14 05:41 21,504 --a------ c:\windows\system32\hidserv.dll

2009-03-15 19:34 . 2008-04-14 05:41 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-31 23:30 --------- d-----w c:\program files\Lx_cats

2009-03-31 06:30 3,738 ----a-w c:\documents and settings\User\Application Data\wklnhst.dat

2009-03-29 09:13 --------- d-----w c:\program files\Common Files\Adobe

2009-02-23 08:12 40,000 ----a-w c:\documents and settings\User\Application Data\GDIPFONTCACHEV1.DAT

2009-02-14 02:49 --------- d-----w c:\program files\Malwarebytes' Anti-Malware

2009-02-14 00:44 --------- d-----w c:\program files\Windows Live Safety Center

2009-02-13 07:58 --------- d--h--w c:\program files\InstallShield Installation Information

2009-02-13 07:58 --------- d-----w c:\program files\EA GAMES

2009-02-11 00:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-11 00:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-02-07 00:50 --------- d-----w c:\program files\iTunes

2009-02-07 00:50 --------- d-----w c:\program files\iPod

2009-02-07 00:50 --------- d-----w c:\program files\Common Files\Apple

2009-02-07 00:50 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer

2009-02-07 00:50 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-07 00:49 --------- d-----w c:\program files\QuickTime

2009-02-06 10:28 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2

2009-02-05 07:03 --------- d-----w c:\program files\Lexmark 7100 Series

2009-02-05 07:02 --------- d-----w c:\program files\Microsoft Works

2009-02-05 07:01 --------- d-----w c:\program files\Metin2.us

2009-02-05 07:00 --------- d-----w c:\program files\PC Connectivity Solution

2009-02-05 07:00 --------- d-----w c:\program files\My Tribe

2009-02-05 06:27 --------- d-----w c:\documents and settings\All Users\Application Data\Trend Micro

2009-02-04 11:38 --------- d-----w c:\program files\Trend Micro

2009-02-04 10:50 --------- d-----w c:\documents and settings\User\Application Data\Malwarebytes

2009-02-04 10:50 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-10 212216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-01-27 29833347]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]

"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]

"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2009-01-27 301056]

"LXBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-08-20 65536]

"lxbxmon.exe"="c:\program files\Lexmark 7100 Series\lxbxmon.exe" [2004-08-26 188416]

"FaxCenterServer4_in_1"="c:\program files\Lexmark 7100 Series\fm3032.exe" [2004-08-25 356352]

"EzPrint"="c:\program files\Lexmark 7100 Series\ezprint.exe" [2004-08-25 131072]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]

"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 110658]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 491520]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 372008]

"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1818624]

c:\documents and settings\User\Start Menu\Programs\Startup\

Bandwidth Meter.lnk - c:\program files\BandwidthMeter\BandwidthMeter.exe [2007-12-09 275968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 152992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.tscc"= c:\docume~1\User\Desktop\linh\MpcStar\Codecs\tscc\tsccvid.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.0.game"=

"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.4.game"=

"c:\\WINDOWS\\system32\\nwiz.exe"=

"c:\\WINDOWS\\system32\\dumprep.exe"=

"c:\\Program Files\\Microsoft Office\\Office10\\OSA.EXE"=

"c:\\WINDOWS\\system32\\userinit.exe"=

"c:\\Program Files\\VIA\\VIAudioi\\HDADeck\\HDeck.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=

"c:\\Program Files\\PC Connectivity Solution\\NclInstaller.exe"=

"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=

"c:\\WINDOWS\\system32\\lxbxcoms.exe"=

"c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

"c:\\Program Files\\Trend Micro\\TrendSecure\\TSCFCommander.exe"=

"c:\\Program Files\\Trend Micro\\Internet Security\\UfNavi.exe"=

"c:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Trend Micro\\TrendSecure\\TISProToolbar\\PlatformDependent\\ProToolbarComm.exe"=

"c:\\Program Files\\iTunes\\iTunesHelper.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"c:\\Program Files\\Microsoft Works\\WkDStore.exe"=

"c:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\Program Files\\Lexmark 7100 Series\\fm3032.exe"=

"c:\\Program Files\\BandwidthMeter\\BandwidthMeter.exe"=

"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"=

"c:\\Program Files\\Trend Micro\\BM\\TMBMSRV.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"=

"c:\\WINDOWS\\system32\\wuauclt.exe"=

"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=

"c:\\Program Files\\Trend Micro\\TrendSecure\\TSCFPlatformCOMSvr.exe"=

"c:\\ComboFix\\nircmd.com"=

"c:\\Program Files\\QuickTime\\QTTask.exe"=

"c:\\Program Files\\Adobe\\Acrobat 5.0\\Reader\\AcroRd32.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

"10475:TCP"= 10475:TCP:BitComet 10475 TCP

"10475:UDP"= 10475:UDP:BitComet 10475 UDP

"58436:TCP"= 58436:TCP:Pando Media Booster

"58436:UDP"= 58436:UDP:Pando Media Booster

R2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2009-02-04 181584]

R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-02-04 49680]

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-08-15 36368]

R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\gnrnin.sys --> c:\windows\system32\drivers\gnrnin.sys [?]

R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-08-15 334352]

R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-10-24 238080]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0217854c-a32b-11dd-856e-002215ca1588}]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wiskcpy.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3255fa90-d484-11dd-85c9-002215ca1588}]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wokaye.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70ea0947-ec26-11dd-8621-002215ca1588}]

\Shell\AutoRun\command - E:\LaunchU3.exe -a

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-OE - c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

HKLM-Run-UfSeAgnt.exe - c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe

HKU-Default-Run-OE - c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com.au/

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - c:\program files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll

FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\2h576wc2.default\

FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=10&ct=1233469709&rver=5.5.4177.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx%3Fn%3D943640088&id=64855

FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll

FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll

.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-01 15:54:36

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

LXBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1844237615-1343024091-1801674531-1003\Software\SecuROM\License information*]

"datasecu"=hex:31,da,da,37,3b,76,3e,d3,73,16,26,51,07,40,a2,bd,e9,15,0f,27,63,

79,52,b8,52,02,33,ba,b7,6c,13,85,3e,27,e3,7b,d0,b3,0c,d0,fc,e8,cc,ad,08,cb,\

"rkeysecu"=hex:89,16,62,15,e9,99,34,d0,66,54,ab,b5,1c,45,da,58

.

Completion time: 2009-04-01 15:56:21

ComboFix-quarantined-files.txt 2009-04-01 05:56:18

ComboFix2.txt 2009-02-27 08:26:31

Pre-Run: 426,397,032,448 bytes free

Post-Run: 427,915,059,200 bytes free

203 --- E O F --- 2009-03-11 08:26:11

ComboFix.txt

ComboFix.txt

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.