Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Outerinfo Combofix log


  • Please log in to reply

#1
Inglenook23

Inglenook23

    New Member

  • Member
  • Pip
  • 1 posts
I used your instructions to remove Outerinfo from my computer. The instructions requested a copy of the ComboFix log. Here it is. I don't know what a HiJackThis log is. If you will tell me I will copy it to you. Thanks for the help. I am new to your site.
ComboFix 08-01-16.4 - Jordan 2002-01-02 7:01:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.90 [GMT -6:00]
Running from: C:\Documents and Settings\Jordan\Local Settings\Temporary Internet Files\Content.IE5\52RJ78GH\ComboFix[1].exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\000070.exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\mcrh.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 05:08 6,514 --sha-w C:\WINDOWS\system32\gjllm.ini2
2008-01-16 05:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-16 05:04 755,712 ----a-w C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-16 05:04 339,968 ----a-w C:\WINDOWS\system32\mlljg.exe
2008-01-16 05:03 406,016 ----a-w C:\WINDOWS\system32\PSDrvCheck .exe
2008-01-16 05:03 --------- d-----w C:\Program Files\Zune
2008-01-16 05:03 --------- d-----w C:\Program Files\QuickTime
2008-01-16 05:03 --------- d-----w C:\Program Files\CursorXP
2007-11-30 14:21 --------- d-----w C:\Program Files\Windows Installer Clean Up
2007-11-30 14:20 --------- d-----w C:\Program Files\MSECACHE
2003-09-17 19:10 42 ----a-w C:\Program Files\readme.txt
2003-09-17 18:14 27,217,213 ----a-w C:\Program Files\fwmx_2004_en.exe
2003-09-17 16:35 65,924,243 ----a-w C:\Program Files\dwmx2004_trial_en_win.exe
2002-07-26 23:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
2006-08-30 00:07 1,056 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
<pre>
----a-w		 2,664,448 2008-01-16 05:03:13  C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite .exe
----a-w		   185,896 2008-01-16 05:03:00  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w		   128,000 2008-01-16 05:03:19  C:\Program Files\CursorXP\CursorXP .exe
----a-w			68,856 2008-01-16 05:03:19  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w		 6,731,312 2008-01-16 05:03:42  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas   .exe
----a-w		 7,477,760 2002-01-02 06:01:40  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas  .exe
----a-w		 6,731,312 2002-01-02 12:21:21  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
----a-w		   579,072 2008-01-16 05:03:03  C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w			49,152 2008-01-16 05:02:58  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w		   132,496 2008-01-16 05:02:58  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w			67,128 2008-01-16 05:03:19  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
----a-w			53,248 2008-01-16 05:02:58  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask .exe
----a-w		   196,608 2008-01-16 05:03:07  C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
----a-w		   448,512 2008-01-16 05:03:40  C:\Program Files\QuickTime\qttask	.exe
----a-w		   448,512 2002-01-02 06:01:29  C:\Program Files\QuickTime\qttask   .exe
----a-w		   448,512 2002-01-02 14:46:07  C:\Program Files\QuickTime\qttask  .exe
----a-w		   448,512 2002-01-02 06:04:20  C:\Program Files\QuickTime\qttask .exe
----a-w			24,104 2008-01-16 05:02:59  C:\Program Files\Zune\ZuneLauncher .exe
----a-w		   406,016 2008-01-16 05:03:02  C:\WINDOWS\system32\PSDrvCheck .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A851C5D7-4318-44C4-AB17-E6A997C27216}]
2002-01-02 05:02 336384 --a------ C:\WINDOWS\system32\mlljg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-01-16 07:02 434688]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2002-01-02 00:01 436736]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2002-01-02 00:01 516608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2002-01-02 00:01 476672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-15 23:03 448512]
"nwiz"="nwiz.exe" [2002-12-27 01:48 315392 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2002-12-27 01:48 4263936]
"nForce Tray Options"="sstray.exe" [2002-01-03 05:04 73728 C:\WINDOWS\system32\sstray.exe]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2002-01-02 00:01 394240]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2002-01-02 00:01 391168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2002-01-02 00:01 526848]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-01-15 23:03 365056]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2002-01-02 00:01 1116672]
"TalkAndWrite"="C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe" [2002-01-02 00:01 3009024]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2008-01-15 23:04 755712]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2004-09-21 02:22 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2002-01-02 00:01 569856]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2002-01-02 00:01 7477760]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 16:18 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-31 12:48:44]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-08-02 11:59:41]
restore.bat [2007-06-28 17:09:29]
Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe [2005-07-19 20:17:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvsrq]
vtuvsrq.dll

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\mlljg.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\mlljg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ewido anti-spyware 4.0 guard"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Symantec AntiVirus"=2 (0x2)
"SNDSrvc"=3 (0x3)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"MSIServer"=3 (0x3)

R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 17:07]
R3 ehcifltr;NVIDIA EHCI Debugging Filter;C:\WINDOWS\system32\DRIVERS\usbfltr.sys [2002-09-18 05:48]
R3 wg121;NETGEAR WG121 802.11g Wireless USB2.0 Adapter;C:\WINDOWS\system32\DRIVERS\wg121nd5.sys [2003-11-28 09:18]
S2 NETAPI;Microsoft Net API;"C:\WINDOWS\system32\msapi.exe" []
S3 LUsbKbd;Logitech SetPoint USB Filter Driver;C:\WINDOWS\system32\drivers\LUsbKbd.sys [2005-03-10 12:08]
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2003-01-27 13:47]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 23:09:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\system32\mlljg.dll
.
Completion time: 2008-01-15 23:13:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 05:13:37
.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP