Computing.Net > Forums > Security and Virus > The Red x on the C drive--part 2

The Red x on the C drive--part 2

Reply to Message Icon

Original Message
Name: dmoose
Date: February 11, 2008 at 11:25:05 Pacific
Subject: The Red x on the C drive--part 2
OS: XP SP2
CPU/Ram: Intel Celeron 2.4 GHz/ 76
Comment:

I just wanted to make another post, because my first was becoming very long and long wait time for it toload because of log files. below is my combo log that was requested.


Report Offensive Message For Removal


Response Number 1
Name: dmoose
Date: February 11, 2008 at 11:25:41 Pacific
Reply: (edit)

ComboFix 08-02.05.3 - The Parents 2008-02-11 13:52:58.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.428 [GMT -5:00]
Running from: C:\Documents and Settings\The Parents\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\The Parents\Desktop\CFScript.txt
* Created a new restore point

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]

FILE
C:\WINDOWS\DUMP4863.tmp
C:\WINDOWS\hegames.ini
C:\WINDOWS\system32\Drivers\PsSdk30.drv
C:\WINDOWS\system32\GameFly_2.ico
C:\WINDOWS\system32\grjkoofy.tmp
C:\WINDOWS\system32\pwnifkxt.dll
C:\WINDOWS\system32\tfsqlgcn.ini
C:\WINDOWS\system32\windhogs.ini
C:\WINDOWS\system32\xjumuius.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Qoobox
C:\Qoobox\BackEnv\appdata.folder.dat
C:\Qoobox\BackEnv\cache.folder.dat
C:\Qoobox\BackEnv\desktop.folder.dat
C:\Qoobox\BackEnv\favorites.folder.dat
C:\Qoobox\BackEnv\local appdata.folder.dat
C:\Qoobox\BackEnv\local settings.folder.dat
C:\Qoobox\BackEnv\my pictures.folder.dat
C:\Qoobox\BackEnv\personal.folder.dat
C:\Qoobox\BackEnv\profiles.folder.dat
C:\Qoobox\BackEnv\programs.folder.dat
C:\Qoobox\BackEnv\setpath.bat
C:\Qoobox\BackEnv\setpath.dat
C:\Qoobox\BackEnv\start menu.folder.dat
C:\Qoobox\BackEnv\startup.folder.dat
C:\Qoobox\BackEnv\templates.folder.dat
C:\Qoobox\CFScript_used_2008-02-10@12.11.txt
C:\Qoobox\CFScript_used_2008-02-11@13.52.txt
C:\Qoobox\ComboFix-quarantined-files.txt
C:\Qoobox\ComboFix2.txt
C:\Qoobox\ComboFix3.txt
C:\Qoobox\ComboFix4.txt
C:\Qoobox\snapshot@2008-02-09_14.58.39.98.dat
C:\Qoobox\snapshot@2008-02-09_14.58.39.98_B.dat
C:\VundoFix Backups
C:\VundoFix Backups\awtqnkk.dll.bad
C:\VundoFix Backups\awttttu.dll.bad
C:\VundoFix Backups\dpthhkff.dll.bad
C:\VundoFix Backups\gesfqmqp.dllbox.bad
C:\VundoFix Backups\iifdbxu.dll.bad
C:\VundoFix Backups\kdlmjfgn.dll.bad
C:\VundoFix Backups\kjddcath.dll.bad
C:\VundoFix Backups\ltvlmubc.dllbox.bad
C:\VundoFix Backups\ngfjmldk.ini.bad
C:\VundoFix Backups\qqqvmobl.dll.bad
C:\VundoFix Backups\rawktqst.dll.bad
C:\VundoFix Backups\rqrrppo.dll.bad
C:\VundoFix Backups\ssqonkk.dll.bad
C:\VundoFix Backups\tgacbnfw.dll.bad
C:\VundoFix Backups\tsqtkwar.ini.bad
C:\VundoFix Backups\wivyygas.dll.bad
C:\VundoFix Backups\xetvlnsh.dll.bad
C:\WINDOWS\DUMP4863.tmp
C:\WINDOWS\hegames.ini
C:\WINDOWS\system32\GameFly_2.ico
C:\WINDOWS\system32\grjkoofy.tmp
C:\WINDOWS\system32\pwnifkxt.dll
C:\WINDOWS\system32\tfsqlgcn.ini
C:\WINDOWS\system32\windhogs.ini
C:\WINDOWS\system32\xjumuius.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_PSSDK30
-------\PsSdk30


((((((((((((((((((((((((( Files Created from 2008-01-11 to 2008-02-11 )))))))))))))))))))))))))))))))
.

2008-02-10 16:05 . 2004-08-03 19:56 388,608 --a------ C:\kmd.exe
2008-02-10 12:22 . 2008-02-10 12:22 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-10 12:22 . 2008-02-10 12:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-09 18:03 . 2008-02-09 18:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-02-09 17:30 . 2008-02-09 17:30 <DIR> d-------- C:\Program Files\iTunes
2008-02-09 14:24 . 2008-02-09 14:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-08 18:53 . 2008-02-08 18:53 <DIR> d---s---- C:\Documents and Settings\Aszure\UserData
2008-02-08 16:19 . 2008-02-08 16:19 <DIR> d-------- C:\Documents and Settings\The Parents\Server Setups
2008-02-06 21:20 . 2008-02-08 22:50 575 --a------ C:\WINDOWS\wininit.ini
2008-02-06 19:27 . 2008-02-06 19:27 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-06 19:27 . 2008-02-06 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-29 22:15 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2008-01-29 22:15 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2008-01-27 17:35 . 2008-01-27 17:35 <DIR> d-------- C:\Documents and Settings\Mars\Application Data\DivX
2008-01-26 18:05 . 2008-01-26 18:05 <DIR> d-------- C:\Program Files\DivX
2008-01-22 01:00 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-01-22 01:00 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 01:30 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-02-11 18:28 --------- d-----w C:\Program Files\McAfee
2008-02-11 12:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-10 21:43 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-10 21:35 --------- d-----w C:\Program Files\America's Army
2008-02-09 23:02 --------- d-----w C:\Program Files\Yahoo! Games
2008-02-09 22:30 --------- d-----w C:\Program Files\iPod
2008-02-08 00:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-08 00:16 --------- d--h--r C:\Documents and Settings\The Parents\Application Data\yahoo!
2008-02-08 00:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-21 15:04 --------- d-----w C:\Documents and Settings\Aszure\Application Data\Yahoo!
2008-01-13 19:08 --------- d-----w C:\Documents and Settings\The Parents\Application Data\McAfee
2008-01-13 19:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-04 21:58 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-04 21:58 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-04 21:58 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-02 03:47 --------- d-----w C:\Program Files\America's Army Server Manager
2008-01-01 16:54 --------- d-----w C:\Documents and Settings\The Parents\Application Data\SiteAdvisor
2008-01-01 15:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-01 15:09 --------- d-----w C:\Program Files\Apple Software Update
2008-01-01 15:08 --------- d-----w C:\Program Files\Common Files\Apple
2008-01-01 15:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-31 11:28 --------- d-----w C:\Program Files\RainbowSoft
2007-12-29 00:43 --------- d-----w C:\Program Files\XBC
2007-12-28 00:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-28 00:14 --------- d-----w C:\Program Files\ATI Technologies
2007-12-27 23:17 --------- d-----w C:\Program Files\LucasArts
2007-12-27 23:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-26 02:43 --------- d-----w C:\Program Files\XLink Kai Evolution VII
2007-12-24 02:00 --------- d-----w C:\Program Files\WinPcap
2007-12-21 21:28 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-20 23:43 --------- d-----w C:\Documents and Settings\Mars\Application Data\SiteAdvisor
2007-12-20 01:28 --------- d-----w C:\Documents and Settings\Aszure\Application Data\SiteAdvisor
2007-12-20 01:28 --------- d-----w C:\Documents and Settings\Aszure\Application Data\McAfee
2007-12-18 00:03 737,581,072 ----a-w C:\MSSetup.exe
2007-12-15 15:46 --------- d-----w C:\Documents and Settings\Mars\Application Data\IGN_DLM
2007-12-15 03:09 --------- d-----w C:\Program Files\Microsoft Games
2007-12-05 22:52 24,368 ----a-w C:\Documents and Settings\Mars\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-05-10 03:37 614489]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 17:53 153136]
"MWLExe"="C:\Program Files\Mcafee\MWL\MWLGuiSt.exe" [2007-07-28 09:32 206184]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-24 16:57 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-07-22 20:29 1160480]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 12:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 10:22 20480]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-03 19:56 388608]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

R0 viasraid;viasraid;C:\WINDOWS\system32\drivers\viasraid.sys [2003-10-31 06:22]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;C:\WINDOWS\system32\DRIVERS\SWUSBFLT.sys [2001-08-17 13:02]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 19:07:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-15 06:15:11 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2007-10-06 16:24:04 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 14:02:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
r Running Proce
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2008-02-11 14:05:42 - machine was rebooted


Report Offensive Follow Up For Removal

Response Number 2
Name: jabuck
Date: February 11, 2008 at 15:22:01 Pacific
Reply: (edit)

The log appears to be clean.

This should fix the red X.

Go to start> run> type in notepad > ok. Copy paste the following into notepad making [autorun] the very top line:

[autorun]

ICON=C:\WINDOWS\SYSTEM\SHELL32.DLL,8

Click "save as"> then using the drop down arrow on the far right of the "save in" window select Local Disk C: to be displayed in the "save in" window.

Next type "C:\autorun.inf" (you must use the quotes) in the file name window> click save.

Restart the computer.

How is the computer operating?


Report Offensive Follow Up For Removal

Response Number 3
Name: dmoose
Date: February 11, 2008 at 16:25:40 Pacific
Reply: (edit)

You guys are great!!! Everything looks ok right now. My question to you is there anything you recommend I should run on the computer to help prevent this. I have McAfee Security (virus/firewall/etc), and also run Spybot.
But seeing you guys are the experts please let me know what you recommend!! Thanks again, and if I see anything weird I will let you know.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: The Red x on the C drive--part 2

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge