![]() |
|
|||||||
| Notices |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Newbie
Join Date: Sep 2009
Age: 18
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
![]() OS:
|
Help me.. Can't access microsoft and any antivirus websites..
here's the log from Combofix.exe
ComboFix 09-09-05.02 - Julius Canto 09/06/2009 16:44.3.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1555 [GMT 8:00] Running from: D:\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 ))))))))))))))))))))))))))))))) . 2011-08-08 12:14 . 2009-08-22 18:51 -------- d-----w- c:\program files\PhotoScape 2011-08-08 12:12 . 2009-09-03 15:10 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\FxFotoDB 2011-08-08 12:12 . 2011-08-10 18:52 -------- d-----w- c:\program files\FxFoto 2011-07-31 14:05 . 2011-07-31 14:05 -------- d-----w- c:\documents and settings\Julius Canto\Local Settings\Application Data\Help 2011-07-28 01:35 . 2011-07-29 08:47 108530 --sh--r- C:\mb9x.exe 2011-07-28 01:27 . 2011-07-30 10:16 112212 --sh--r- C:\qr.exe 2011-07-27 16:05 . 2011-07-27 16:05 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\Leawo 2011-07-27 16:04 . 2011-07-27 16:04 -------- d-----w- c:\program files\Leawo 2011-07-27 15:47 . 2011-07-27 15:48 1 ----a-w- c:\windows\system32\Syspspjukebox.dat 2011-07-27 15:41 . 2011-07-27 15:44 -------- d-----w- C:\My PSP 2011-07-27 15:39 . 2011-07-27 15:39 1 ----a-w- c:\windows\system32\SysAVItoPSP.dat 2011-07-21 15:19 . 2011-07-21 15:19 -------- d--h--w- C:\$AVG8.VAULT$ 2011-07-18 13:04 . 2011-07-18 13:04 -------- d-----w- c:\program files\MSXML 6.0 2011-07-17 05:09 . 2009-08-18 02:17 -------- d-----w- c:\windows\$hf_mig$ 2011-07-17 04:57 . 2011-07-17 08:56 -------- d-----w- c:\program files\Google 2011-07-17 04:50 . 2011-07-17 08:56 -------- d-----w- c:\windows\system32\Adobe 2011-07-17 03:40 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys 2011-07-17 03:40 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys 2011-07-17 03:39 . 2009-02-06 10:29 2142720 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe 2011-07-17 03:39 . 2009-02-06 10:32 2186112 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe 2011-07-17 03:39 . 2009-02-06 09:49 2020864 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe 2011-07-17 03:39 . 2009-02-06 09:49 2062976 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe 2011-07-17 03:25 . 2008-10-24 11:25 455936 -c----w- c:\windows\system32\dllcache\mrxsmb.sys 2011-07-12 02:54 . 2011-07-12 02:54 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\fltk.org 2009-09-06 02:55 . 2009-09-06 02:55 664 ----a-w- c:\windows\system32\d3d9caps.dat 2009-09-06 02:42 . 2009-09-06 02:43 -------- d-----w- c:\windows\ERUNT 2009-09-04 15:08 . 2009-09-04 16:19 117153 --sh--r- C:\cj3k.exe 2009-09-04 06:03 . 2009-09-06 02:59 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\BitDefender Deployment Tool 2009-09-04 06:03 . 2009-09-04 06:03 -------- d-----w- c:\program files\BitDefender 2009-09-04 06:02 . 2009-09-04 06:02 -------- d-----w- c:\program files\Common Files\BitDefender 2009-09-04 05:44 . 2009-09-04 05:44 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\Uniblue 2009-09-04 04:21 . 2009-09-04 05:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-09-04 04:21 . 2009-09-04 04:25 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-09-04 04:20 . 2009-09-04 04:20 -------- d-----w- c:\documents and settings\Julius Canto\Local Settings\Application Data\ESET 2009-09-04 04:02 . 2009-09-04 05:16 112699 --sh--r- C:\o9bxu.exe 2009-09-03 03:37 . 2009-09-03 03:43 71993 ----a-w- c:\windows\War3Unin.dat 2009-09-03 03:37 . 2009-09-03 03:39 2829 ----a-w- c:\windows\War3Unin.pif 2009-09-03 03:37 . 2009-09-03 03:39 139264 ----a-w- c:\windows\War3Unin.exe 2009-09-03 03:35 . 2009-09-06 06:19 -------- d-----w- c:\program files\Warcraft III 2009-09-02 13:57 . 2009-09-02 01:53 113455 --sh--r- C:\i0yva6.exe 2009-08-31 16:25 . 2009-09-01 09:30 112442 --sh--r- C:\mt2.exe 2009-08-31 11:13 . 2009-08-31 11:13 -------- d-----w- c:\program files\RMVB Converter 2009-08-31 11:03 . 2009-08-31 11:03 -------- d-----w- c:\program files\RMVB Player 2009-08-31 08:42 . 2009-09-06 08:01 -------- d-----w- C:\SDFix 2009-08-31 08:26 . 2009-08-31 08:26 112679 --sh--r- C:\pkkwng.exe 2009-08-31 08:22 . 2009-08-31 08:22 -------- d-----w- c:\windows\system32\wbem\Repository 2009-08-31 08:21 . 2009-08-31 08:21 -------- d-----w- C:\output 2009-08-31 07:16 . 2009-08-31 08:21 -------- dc----w- c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E} 2009-08-30 07:24 . 2009-08-30 07:24 -------- d-----w- c:\windows\system32\NtmsData 2009-08-26 01:30 . 2009-08-26 01:30 114124 --sh--r- C:\hx.exe 2009-08-17 14:42 . 2009-08-17 14:42 -------- d-----w- c:\windows\ServicePackFiles 2009-08-17 14:32 . 2009-06-09 14:53 53248 -c----w- c:\windows\system32\dllcache\tsgqec.dll 2009-08-17 14:32 . 2009-06-09 14:53 290816 -c----w- c:\windows\system32\dllcache\rhttpaa.dll 2009-08-17 14:32 . 2009-06-09 14:53 136192 -c----w- c:\windows\system32\dllcache\aaclient.dll 2009-08-11 11:19 . 2009-08-20 08:34 -------- d-----w- c:\windows\system32\CatRoot_bak . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2011-07-21 15:50 . 2009-06-07 12:20 -------- d-----w- c:\program files\Common Files\Nikon 2011-07-21 15:50 . 2009-06-07 12:20 0 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT 2011-07-21 15:50 . 2009-06-07 12:20 -------- d-----w- c:\program files\Nikon 2011-07-21 15:49 . 2009-06-06 15:57 -------- d-----w- c:\program files\iTunes 2011-07-21 15:49 . 2009-06-06 15:57 -------- d-----w- c:\program files\iPod 2011-07-21 15:47 . 2009-06-08 06:22 -------- d-----w- c:\documents and settings\All Users\Application Data\YAHOO 2011-07-21 15:47 . 2009-06-03 17:17 -------- d-----w- c:\program files\Yahoo! 2011-07-18 13:01 . 2011-07-18 13:01 -------- d-----w- c:\program files\MSXML 4.0 2009-09-06 08:42 . 2009-06-02 10:37 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\DNA 2009-09-06 08:01 . 2009-06-03 17:17 -------- d-----w- c:\program files\DNA 2009-09-06 05:46 . 2009-06-03 08:53 -------- d-----w- c:\program files\Garena 2009-09-03 16:55 . 2009-06-02 10:38 -------- d-----w- c:\documents and settings\Julius Canto\Application Data\BitTorrent 2009-08-21 03:09 . 2009-06-06 15:56 -------- d-----w- c:\program files\QuickTime 2009-08-17 14:41 . 2009-06-02 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-08-05 09:11 . 2004-08-03 23:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-29 04:20 . 2007-06-24 07:40 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-07-29 04:20 . 2007-06-24 07:38 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-07-17 18:55 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\atl.dll 2009-07-13 15:43 . 2007-06-24 07:41 286208 ----a-w- c:\windows\system32\wmpdxm.dll 2009-07-05 16:25 . 2009-07-05 16:25 45056 ----a-w- c:\windows\system32\UTSCSI.EXE 2009-06-25 18:36 . 2004-08-03 23:56 95744 ----a-w- c:\windows\system32\mqsec.dll 2009-06-25 18:36 . 2004-08-03 23:56 661504 ----a-w- c:\windows\system32\mqqm.dll 2009-06-25 18:36 . 2004-08-03 23:56 517120 ----a-w- c:\windows\system32\mqsnap.dll 2009-06-25 18:36 . 2004-08-03 23:56 48640 ----a-w- c:\windows\system32\mqupgrd.dll 2009-06-25 18:36 . 2004-08-03 23:56 471552 ----a-w- c:\windows\system32\mqutil.dll 2009-06-25 18:36 . 2004-08-03 23:56 47104 ----a-w- c:\windows\system32\mqdscli.dll 2009-06-25 18:36 . 2004-08-03 23:56 225280 ----a-w- c:\windows\system32\mqoa.dll 2009-06-25 18:36 . 2004-08-03 23:56 186880 ----a-w- c:\windows\system32\mqtrig.dll 2009-06-25 18:36 . 2004-08-03 23:56 177152 ----a-w- c:\windows\system32\mqrt.dll 2009-06-25 18:36 . 2004-08-03 23:56 16896 ----a-w- c:\windows\system32\mqise.dll 2009-06-25 18:36 . 2004-08-03 23:56 138240 ----a-w- c:\windows\system32\mqad.dll 2009-06-25 18:36 . 2004-08-03 23:56 123392 ----a-w- c:\windows\system32\mqrtdep.dll 2009-06-25 08:17 . 2007-06-24 07:40 59392 ----a-w- c:\windows\system32\wdigest.dll 2009-06-25 08:17 . 2007-06-24 07:39 168448 ----a-w- c:\windows\system32\schannel.dll 2009-06-25 08:17 . 2007-06-24 07:38 729600 ----a-w- c:\windows\system32\lsasrv.dll 2009-06-25 08:17 . 2007-06-24 07:38 301568 ----a-w- c:\windows\system32\kerberos.dll 2009-06-25 08:17 . 2004-08-03 23:56 56320 ----a-w- c:\windows\system32\secur32.dll 2009-06-25 08:17 . 2004-08-03 23:56 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-06-22 11:49 . 2004-08-03 23:56 19968 ----a-w- c:\windows\system32\mqbkup.exe 2009-06-22 11:49 . 2004-08-03 23:56 117248 ----a-w- c:\windows\system32\mqtgsvc.exe 2009-06-22 11:49 . 2004-08-03 23:56 4608 ----a-w- c:\windows\system32\mqsvc.exe 2009-06-22 11:48 . 2004-08-03 21:58 91776 ----a-w- c:\windows\system32\drivers\mqac.sys 2009-06-22 11:35 . 2004-08-03 21:59 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2009-06-12 11:49 . 2004-08-03 23:56 80896 ----a-w- c:\windows\system32\tlntsess.exe 2009-06-12 11:49 . 2005-05-10 23:51 76288 ----a-w- c:\windows\system32\telnet.exe 2009-06-10 14:21 . 2004-08-03 23:56 84992 ----a-w- c:\windows\system32\avifil32.dll 2009-06-10 06:26 . 2007-06-24 07:40 134144 ----a-w- c:\windows\system32\wkssvc.dll 2009-06-09 14:53 . 2007-06-24 07:40 53248 ----a-w- c:\windows\system32\tsgqec.dll 2009-06-09 14:53 . 2007-06-24 07:39 290816 ----a-w- c:\windows\system32\rhttpaa.dll 2009-06-09 14:53 . 2009-06-02 08:32 2067968 ----a-w- c:\windows\system32\mstscax.dll 2009-06-09 14:53 . 2007-06-24 07:38 136192 ----a-w- c:\windows\system32\aaclient.dll 2009-06-09 09:12 . 2009-06-02 08:32 677888 ----a-w- c:\windows\system32\mstsc.exe 2006-05-03 10:06 . 2009-06-05 00:13 163328 --sh--r- c:\windows\system32\flvDX.dll 2009-03-21 13:54 . 2007-06-24 07:38 170956 --sha-r- c:\windows\system32\iildgk.dll 2007-02-21 11:47 . 2009-06-05 00:13 31232 --sh--r- c:\windows\system32\msfDX.dll 2008-03-16 13:30 . 2009-06-05 00:13 216064 --sh--r- c:\windows\system32\nbDX.dll . ((((((((((((((((((((((((((((( SnapShot@2009-09-06_03.11.19 ))))))))))))))))))))))))))))))))))))))))) . - 2009-09-06 02:43 . 2009-09-06 02:43 172032 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat + 2009-09-06 07:54 . 2009-09-06 07:54 172032 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat + 2009-09-06 07:54 . 2009-09-06 07:54 4653056 c:\windows\ERUNT\SDFIX\Users\00000001\ntuser.dat - 2009-09-06 02:43 . 2009-09-06 02:43 4653056 c:\windows\ERUNT\SDFIX\Users\00000001\ntuser.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "Messenger (Yahoo!)"="c:\program files\Yahoo Messenger\Messenger\YahooMessenger.exe" [2009-05-26 4351216] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-06-02 321344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-08 13680640] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 1232896] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce] "ShowDeskFix"="shell32" [X] c:\documents and settings\Julius Canto\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632] [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Yahoo Messenger\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\Garena\\Garena.exe"= "c:\\Program Files\\Warcraft III\\Warcraft III.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List] "4319:TCP"= 4319:TCP:gwecth R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfw tdir.sys [12/21/2007 8:21 AM 33800] R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12/21/2007 8:21 AM 468224] S2 lvwmh;Security Manager;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 7:56 AM 14336] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JULIUS ~1\LOCALS~1\Temp\VGJ619.tmp --> c:\docume~1\JULIUS~1\LOCALS~1\Temp\VGJ619.tmp [?] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs lvwmh . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {2AB24A7A-79FE-4B29-8E0E-1A4F22B82B30} = 58.69.254.70 58.69.254.137 FF - ProfilePath - c:\documents and settings\Julius Canto\Application Data\Mozilla\Firefox\Profiles\im4ctikt.default\ FF - plugin: c:\program files\Mozilla Firefox\plugins\NPFxViewer.dll . ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2009-09-06 16:45 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\G arenaPEngine] "ImagePath"="\??\c:\docume~1\JULIUS~1\LOCALS~1\Tem p\VGJ619.tmp" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\l vwmh] "ServiceDll"="c:\windows\system32\iildgk.dll" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(2068) c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll c:\windows\system32\hnetcfg.dll c:\program files\Bonjour\mdnsNSP.dll c:\windows\system32\browselc.dll c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll c:\windows\system32\wpdshext.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll . Completion time: 2009-09-06 16:47 ComboFix-quarantined-files.txt 2009-09-06 08:47 ComboFix2.txt 2009-09-06 08:22 ComboFix3.txt 2009-09-06 03:13 Pre-Run: 11,483,029,504 bytes free Post-Run: 11,474,219,008 bytes free 215 --- E O F --- 2009-09-06 07:44 |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
< Windows Help - MS Office Help - Hardware Support >
| New To Site? | Need Help? |