Hi ALl,
Here is the log of ComboFix, i am facing lots of issues with my machines, popup windows, slow, lot of torjons are there. Need help fixing them.
Please help..
Best Regards,
Ketsh
Following is the log of ComboFix
"ketans" - 2007-07-15 12:37:58 - ComboFix 07-07-04.4 - Service Pack 2 [SAFE MODE]
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\nnnmjii.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\nnnmjii.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ketans\APPLIC~1.\mcroso~1.net
C:\DOCUME~1\ketans\APPLIC~1.\mcroso~1.net\winlogon.exe
C:\DOCUME~1\ketans\Desktop.\Install WinAntiSpyware 2007 .lnk
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\ComPlus Applications\lazuq.dll
C:\Program Files\mmsassist
C:\Program Files\mmsassist\mms.ini
C:\Program Files\Outlook Express\honewazeh83122.dll
C:\WINDOWS\offun.exe
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\?hkntfs.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\ioncce.dll
C:\WINDOWS\system32\wincom32.ini
C:\WINDOWS\system32\wincom32.sys
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_NET_AGENT
-------\LEGACY_WINCOM32
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\core
-------\Net Agent
-------\WINCOM32
((((((((((((((((((((((((( Files Created from 2007-06-15 to 2007-07-15 )))))))))))))))))))))))))))))))
2007-07-15 12:37 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-15 00:57 626,352 -r-hs---- C:\WINDOWS\kqrysjyA.exe
2007-07-15 00:56 31,254 --------- C:\WINDOWS\system32\nnnmjii.dll
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B5
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B4
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B3
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B2
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\b10FdUe
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B1
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B0
2007-07-05 23:27 <DIR> d-------- C:\Program Files\MTV Networks
2007-07-05 22:23 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-04 10:30 <DIR> d-------- C:\VundoFix Backups
2007-06-29 12:07 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-06-29 10:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-27 23:04 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Yahoo!
2007-06-26 22:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-06-26 18:47 <DIR> d-------- C:\Temp
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 06:20:18 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-07-04 17:48:43 -------- d-----w C:\Program Files\PCFriendly
2007-07-04 02:56:16 -------- d--h--w C:\Program Files\WindowsUpdate
2007-06-29 23:10:06 -------- d-----w C:\Program Files\Google
2007-06-27 05:41:56 -------- d-----w C:\DOCUME~1\ketans\APPLIC~1\Yahoo!
2007-06-27 05:40:17 -------- d-----w C:\Program Files\Yahoo!
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:43:44 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:43:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-13 13:26 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-30 12:34 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-11-09 16:21 440056 --a------ C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{941508F8-CCD9-44E0-AC29-4F1E141373F7}]
2007-07-15 00:56 31254 --------- C:\WINDOWS\system32\nnnmjii.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E}]
C:\WINDOWS\system32\WinNB57.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 23:55 2403392 -ra------ c:\program files\google\googletoolbar1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
2006-07-07 17:27 493856 --a------ C:\Program Files\Windows Live Toolbar\msntb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2005-07-04 04:17]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 00:54]
"PRONoMgr.exe"="c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2004-02-05 04:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"UserFaultCheck"="%systemroot%\system32\dumprep 0 -u" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-07 19:01]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-07 18:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-30 12:34]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2005-04-27 13:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 12:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{941508F8-CCD9-44E0-AC29-4F1E141373F7}"="C:\WINDOWS\system32\nnnmjii.dll" [2007-07-15 00:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnmjii]
nnnmjii.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\tmp_6.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
Contents of the 'Scheduled Tasks' folder
2007-07-15 17:32:00 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 12:43:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-15 12:46:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-15 12:46
--- E O F ---
Here is the log of ComboFix, i am facing lots of issues with my machines, popup windows, slow, lot of torjons are there. Need help fixing them.
Please help..
Best Regards,
Ketsh
Following is the log of ComboFix
"ketans" - 2007-07-15 12:37:58 - ComboFix 07-07-04.4 - Service Pack 2 [SAFE MODE]
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\nnnmjii.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\nnnmjii.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ketans\APPLIC~1.\mcroso~1.net
C:\DOCUME~1\ketans\APPLIC~1.\mcroso~1.net\winlogon.exe
C:\DOCUME~1\ketans\Desktop.\Install WinAntiSpyware 2007 .lnk
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\ComPlus Applications\lazuq.dll
C:\Program Files\mmsassist
C:\Program Files\mmsassist\mms.ini
C:\Program Files\Outlook Express\honewazeh83122.dll
C:\WINDOWS\offun.exe
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\?hkntfs.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\ioncce.dll
C:\WINDOWS\system32\wincom32.ini
C:\WINDOWS\system32\wincom32.sys
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_NET_AGENT
-------\LEGACY_WINCOM32
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\core
-------\Net Agent
-------\WINCOM32
((((((((((((((((((((((((( Files Created from 2007-06-15 to 2007-07-15 )))))))))))))))))))))))))))))))
2007-07-15 12:37 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-15 00:57 626,352 -r-hs---- C:\WINDOWS\kqrysjyA.exe
2007-07-15 00:56 31,254 --------- C:\WINDOWS\system32\nnnmjii.dll
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\driver
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B5
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B4
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B3
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B2
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\b10FdUe
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B1
2007-07-15 00:56 <DIR> d-------- C:\WINDOWS\system32\B0
2007-07-05 23:27 <DIR> d-------- C:\Program Files\MTV Networks
2007-07-05 22:23 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-04 10:30 <DIR> d-------- C:\VundoFix Backups
2007-06-29 12:07 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-06-29 10:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-27 23:04 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Yahoo!
2007-06-26 22:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-06-26 18:47 <DIR> d-------- C:\Temp
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 06:20:18 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-07-04 17:48:43 -------- d-----w C:\Program Files\PCFriendly
2007-07-04 02:56:16 -------- d--h--w C:\Program Files\WindowsUpdate
2007-06-29 23:10:06 -------- d-----w C:\Program Files\Google
2007-06-27 05:41:56 -------- d-----w C:\DOCUME~1\ketans\APPLIC~1\Yahoo!
2007-06-27 05:40:17 -------- d-----w C:\Program Files\Yahoo!
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:43:44 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:43:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-13 13:26 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-30 12:34 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-11-09 16:21 440056 --a------ C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{941508F8-CCD9-44E0-AC29-4F1E141373F7}]
2007-07-15 00:56 31254 --------- C:\WINDOWS\system32\nnnmjii.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E}]
C:\WINDOWS\system32\WinNB57.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 23:55 2403392 -ra------ c:\program files\google\googletoolbar1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
2006-07-07 17:27 493856 --a------ C:\Program Files\Windows Live Toolbar\msntb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2005-07-04 04:17]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 00:54]
"PRONoMgr.exe"="c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2004-02-05 04:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"UserFaultCheck"="%systemroot%\system32\dumprep 0 -u" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-07 19:01]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-07 18:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-30 12:34]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2005-04-27 13:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 12:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{941508F8-CCD9-44E0-AC29-4F1E141373F7}"="C:\WINDOWS\system32\nnnmjii.dll" [2007-07-15 00:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnmjii]
nnnmjii.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\tmp_6.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
Contents of the 'Scheduled Tasks' folder
2007-07-15 17:32:00 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-15 12:43:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-15 12:46:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-15 12:46
--- E O F ---