Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Malware
  New Posts New Posts RSS Feed: f3.cookingluck.com please help!
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

f3.cookingluck.com please help!

 Post Reply Post Reply Page  12>
Author
Message Reverse Sort Order
controler View Drop Down
Senior Member
Senior Member


Joined: 01 October 2006
Online Status: Offline
Posts: 222
Post Options Post Options   Quote controler Quote  Post ReplyReply Direct Link To This Post Topic: f3.cookingluck.com please help!
    Posted: 21 April 2008 at 7:05am

In addition to those listed above i would wonder about these too.

+ 0JwMIe0wvR   c:\documents and settings\all users\application data\elorexqx\uvqbmtch.exe


+ nnnlljkj.dll   c:\windows\system32\nnnlljkj.dll


+ nnnlljkJ   c:\windows\system32\nnnlljkj.dll

+ C:\WINDOWS\system32\efcAtrPi   c:\windows\system32\efcatrpi.dll


 

Back to Top
Revelations View Drop Down
Newbie
Newbie


Joined: 15 April 2008
Online Status: Offline
Posts: 13
Post Options Post Options   Quote Revelations Quote  Post ReplyReply Direct Link To This Post Posted: 20 April 2008 at 12:29am
popdisplay

The only strange i see in you log is

+ 49bc0447   c:\windows\system32\guoyssjw.dll

+ pilsonwi   c:\windows\system32\snsxmxyd.exe
+ uwnbpepb   c:\windows\system32\uvqtalod.exe
+ wybjyzgr   c:\windows\system32\totyhets.exe

+ {B504867A-C776-4FC4-BC23-7E15DB90B612}   c:\windows\system32\efcatrpi.dll
+ {C14E6230-757D-4246-81CE-B34E2940C722}   c:\windows\system32\nnnlljkj.dll



UPLOAD TO VIRUS TOTAL

And post link

Google has no info on those files

MUST BE - Malware related.

But it must be scanned first. If infected

That's out hint! and clue!
Back to Top
popdisplay View Drop Down
Newbie
Newbie


Joined: 17 April 2008
Location: United States
Online Status: Offline
Posts: 1
Post Options Post Options   Quote popdisplay Quote  Post ReplyReply Direct Link To This Post Posted: 17 April 2008 at 6:07am
cookingluck virus
 
here is my log. PLEASE HELP!!!
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run   
+ !AVG Anti-Spyware AVG Anti-Spyware (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe
+ 49bc0447   c:\windows\system32\guoyssjw.dll
+ Ad-Watch Ad-Watch Realtime Malware Protection (Verified) Lavasoft AB c:\program files\lavasoft\ad-aware 2007\ad-watch2007.exe
+ Adobe Reader Speed Launcher Adobe Acrobat SpeedLauncher (Verified) Adobe Systems, Incorporated c:\program files\adobe\reader 8.0\reader\reader_sl.exe
+ HPBootOp HP Boot Optimizer (Not verified) Hewlett-Packard Company c:\program files\hewlett-packard\hp boot optimizer\hpbootop.exe
+ HPHmon06 HPHmon06 (Not verified) Hewlett-Packard c:\windows\system32\hphmon06.exe
+ QuickTime Task QuickTime Task (Not verified) Apple Inc. c:\program files\quicktime\qttask.exe
+ SunJavaUpdateSched Java(TM) Platform SE binary (Verified) Sun Microsystems, Inc. c:\program files\java\jre1.6.0_05\bin\jusched.exe
+ TkBellExe RealNetworks Scheduler (Not verified) RealNetworks, Inc. c:\program files\common files\real\update_ob\realsched.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup   
+ Acrobat Assistant.lnk AcroTray (Not verified) Adobe Systems Inc. c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
+ Logitech Desktop Messenger.lnk Logitech Desktop Messenger (Not verified) Logitech Inc. c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe
+ Logitech SetPoint.lnk Logitech SetPoint Event Manager (UNICODE) (Verified) Logitech c:\program files\logitech\setpoint\setpoint.exe
+ Microsoft Office.lnk Microsoft Office 2000 component (Not verified) Microsoft Corporation c:\program files\microsoft office\office\osa9.exe
+ UPS WorldShip Messaging Utility.lnk WSDMessaging MFC Application  c:\ups\uows\messages\wsdmessaging.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run   
+ 0JwMIe0wvR   c:\documents and settings\all users\application data\elorexqx\uvqbmtch.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run   
+ LDM Logitech Desktop Messenger (Not verified) Logitech Inc. c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe
+ pilsonwi   c:\windows\system32\snsxmxyd.exe
+ uwnbpepb   c:\windows\system32\uvqtalod.exe
+ wybjyzgr   c:\windows\system32\totyhets.exe
+ Yahoo! Pager Yahoo! Messenger (Verified) Yahoo! Inc. c:\program files\yahoo!\messenger\yahoomessenger.exe
HKLM\SOFTWARE\Classes\Protocols\Handler   
+ bwfile-8876480 Logitech Desktop Messenger (Not verified) Logitech Inc. c:\program files\logitech\desktop messenger\8876480\program\gaplugprotocol-8876480.dll
+ ms-itss Microsoft® InfoTech Storage System Library (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\information retrieval\msitss.dll
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components   
+ 0   File not found: About:Home
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad   
+ SysBoot   c:\windows\resources\sysboot.dll
+ zip   c:\windows\installer\{6783984e-5308-4ccc-aa76-15cbd42fe640}\zip.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks   
+ AVG Anti-Spyware 7.5 AVG Anti-Spyware shellexecutehook (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll
+ nnnlljkj.dll   c:\windows\system32\nnnlljkj.dll
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers   
+ Adobe.Acrobat.ContextMenu Adobe Acrobat Elements (Not verified) Adobe Systems Inc. c:\program files\adobe\acrobat 6.0\acrobat elements\contextmenu.dll
+ Autodesk.DWF.ContextMenu Autodesk DWF ShellExtension Module (Verified) Autodesk, Inc. c:\program files\common files\autodesk shared\dwf common\dwfshellextension.dll
+ AVG Anti-Spyware Context-Menu (Shell Extension) (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\context.dll
+ Yahoo! Mail YMMAPI Module (Verified) Yahoo! Inc. c:\program files\yahoo!\common\ymmapi.dll
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers   
+ AVG Anti-Spyware Context-Menu (Shell Extension) (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\context.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers   
+ AcColumnHandler AutoCAD Dwg common shell extension handler (Verified) Autodesk, Inc c:\program files\common files\autodesk shared\acshellex\acshellextension.dll
+ PDF Shell Extension PDF Shell Extension (Not verified) Adobe Systems, Inc. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers   
+ AutoCAD Digital Signatures Icon Overlay Handler AutoCAD component (Not verified) Autodesk, Inc. c:\windows\system32\acsignicon.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved   
+ Adobe.Acrobat.ContextMenu Adobe Acrobat Elements (Not verified) Adobe Systems Inc. c:\program files\adobe\acrobat 6.0\acrobat elements\contextmenu.dll
+ AutoCAD Digital Signatures Icon Overlay Handler AutoCAD component (Not verified) Autodesk, Inc. c:\windows\system32\acsignicon.dll
+ AutoCAD DWG Column Handler AutoCAD Dwg common shell extension handler (Verified) Autodesk, Inc c:\program files\common files\autodesk shared\acshellex\acshellextension.dll
+ AutoCAD DWG InfoTip Handler AutoCAD Dwg common shell extension handler (Verified) Autodesk, Inc c:\program files\common files\autodesk shared\acshellex\acshellextension.dll
+ Autodesk Dgn File Preview AcDgnCOM Module (Verified) Autodesk, Inc c:\program files\common files\autodesk shared\acdgncom17.dll
+ Autodesk Drawing Preview AutoCAD component (Verified) Autodesk, Inc c:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll
+ Display Panning CPL Extension   File not found: deskpan.dll
+ Edrawings Document Thumbnail Handler edrwthumbnailprovider Module (Not verified) Solidworks c:\program files\common files\edrawings2008\edrwthumbnailprovider.dll
+ Logitech Setpoint Extension Logitech SetPoint Event Manager (Verified) Logitech c:\program files\logitech\setpoint\mcplext.dll
+ Logitech Setpoint Extension Logitech SetPoint Event Manager (Verified) Logitech c:\program files\logitech\setpoint\kbcplext.dll
+ Microsoft Outlook Custom Icon Handler Microsoft Outlook Shell Hook for Start/Find (Not verified) Microsoft Corporation c:\program files\microsoft office\office\olkfstub.dll
+ My Logitech Pictures Logitech Namespace2 (Not verified) Logitech Inc. c:\program files\logitech\video\namespc2.dll
+ QBVersionTool QBVersionTool (Not verified) Intuit, Inc. c:\program files\common files\intuit\quickbooks\qbversiontool.dll
+ SampleView ShellvRTF (Not verified) XSS c:\windows\system32\shellvrtf.dll
+ Shell Extensions for RealOne Player RealPlayer Shell Extensions (Not verified) RealNetworks, Inc. c:\program files\real\realplayer\rpshell.dll
+ Yahoo! Mail YMMAPI Module (Verified) Yahoo! Inc. c:\program files\yahoo!\common\ymmapi.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects   
+ AcroIEToolbarHelper Class   c:\program files\adobe\acrobat 6.0\acrobat\acroiefavclient.dll
+ Adobe PDF Reader Link Helper Adobe PDF Helper for Internet Explorer (Verified) Adobe Systems, Incorporated c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
+ Google Toolbar Helper Google IE Client Toolbar (Verified) Google Inc c:\program files\google\googletoolbar1.dll
+ Google Toolbar Notifier BHO GoogleToolbarNotifier (Verified) Google Inc c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
+ SSVHelper Class Java(TM) Platform SE binary (Verified) Sun Microsystems, Inc. c:\program files\java\jre1.6.0_05\bin\ssv.dll
+ UberButton Class Yahoo! IE Services (Verified) Yahoo! Inc. c:\program files\yahoo!\common\yiesrvc.dll
+ Yahoo! Toolbar Helper Yahoo! Toolbar (Verified) Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn1\yt.dll
+ YahooTaggedBM Class IE Shortcuts (Verified) Yahoo! Inc. c:\program files\yahoo!\common\yietagbm.dll
+ {53707962-6F74-2D53-2644-206D7942484F} Bad download blocker (Verified) Safer Networking Ltd. c:\program files\spybot - search & destroy\sdhelper.dll
+ {ace7be75-6ce9-47a3-bb32-1172133ad83f}   File not found: C:\WINDOWS\system32\mgm12n.dll
+ {B504867A-C776-4FC4-BC23-7E15DB90B612}   c:\windows\system32\efcatrpi.dll
+ {C14E6230-757D-4246-81CE-B34E2940C722}   c:\windows\system32\nnnlljkj.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks   
+ Yahoo! Toolbar Yahoo! Toolbar (Verified) Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn1\yt.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar   
+ &Google Google IE Client Toolbar (Verified) Google Inc c:\program files\google\googletoolbar1.dll
+ Adobe PDF   c:\program files\adobe\acrobat 6.0\acrobat\acroiefavclient.dll
+ HP view hp view toolbar (Not verified) Hewlett-Packard Company c:\program files\hp\digital imaging\bin\hpdtlk02.dll
+ qtvglped   c:\windows\qtvglped.dll
+ Yahoo! Toolbar Yahoo! Toolbar (Verified) Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn1\yt.dll
HKCU\Software\Microsoft\Internet Explorer\Extensions   
+ Connection Help   c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
HKLM\Software\Microsoft\Internet Explorer\Extensions   
+ Connection Help   c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
Task Scheduler   
+ AppleSoftwareUpdate.job Software Application (Verified) Apple Computer, Inc. c:\program files\apple software update\softwareupdate.exe
+ SDMsgUpdate (SmartDrawTrial).job SDMessaging Application  c:\program files\smartdraw 7\messages\sdnotify.exe
HKLM\System\CurrentControlSet\Services   
+ aawservice Ad-Aware service (Verified) Lavasoft AB c:\program files\lavasoft\ad-aware 2007\aawservice.exe
+ AVG Anti-Spyware Guard AVG Anti-Spyware guard (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
+ LightScribeService Used by the LightScribe software components to support 3rd party disc labeling applications using the LightScribe COM Application Programming Interface (LSCAPI). This service needs to run for LightScribe direct disc labeling to work. (Not verified) Hewlett-Packard Company c:\program files\common files\lightscribe\lssrvc.exe
+ Pml Driver HPZ12 PML Driver (Not verified) HP c:\windows\system32\hpzipm12.exe
+ Viewpoint Manager Service Ensures Viewpoint 3D and Rich Media Technologies are up to date (Not verified) Viewpoint Corporation c:\program files\viewpoint\common\viewpointservice.exe
HKLM\System\CurrentControlSet\Services   
+ Ad-Watch Connect Filter Driver for Ad-Watch network monitoring (Not verified) Lavasoft AB c:\windows\system32\drivers\nsdriver.sys
+ Ad-Watch Real-Time Scanner Driver for Ad-Watch Real-Time Process protection (Not verified) Lavasoft AB c:\windows\system32\drivers\awrtpd.sys
+ Ad-Watch Registry Filter Driver for Ad-Watch Real-Time Registry Protection (Not verified) Lavasoft AB c:\windows\system32\drivers\awrtrd.sys
+ AVG Anti-Spyware Driver  (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\guard.sys
+ AvgAsCln AVG7 Clean Driver (Verified) GRISOFT LTD c:\windows\system32\drivers\avgascln.sys
+ Changer   File not found: C:\WINDOWS\System32\Drivers\Changer.sys
+ GEARAspiWDM CD/DVD Class Filter Driver (Verified) GEAR Software Inc. c:\windows\system32\drivers\gearaspiwdm.sys
+ i2omgmt   File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys
+ intelppm   File not found: system32\DRIVERS\intelppm.sys
+ L8042mou Logitech PS/2 Mouse Filter Driver. (Not verified) Logitech, Inc. c:\windows\system32\drivers\l8042mou.sys
+ lbrtfdc   File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys
+ LHidKe Logitech HID Filter Driver. (Not verified) Logitech, Inc. c:\windows\system32\drivers\lhidke.sys
+ LHidUsbK Logitech SetPoint USB Receiver (Not verified) Logitech, Inc. c:\windows\system32\drivers\lhidusbk.sys
+ LMouKE Logitech Filter Driver for Mouse Class. (Not verified) Logitech, Inc. c:\windows\system32\drivers\lmouke.sys
+ PCIDump   File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys
+ PDCOMP   File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys
+ PDFRAME   File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys
+ PDRELI   File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys
+ PDRFRAME   File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys
+ PxHelp20 Px Engine Device Driver for Windows 2000/XP (Not verified) Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys
+ rt2500usb Sample Driver for Ralink 802.11g Wireless USB Adapters (Not verified) Ralink Technology Inc. c:\windows\system32\drivers\rt2500usb.sys
+ WDICA   File not found: C:\WINDOWS\System32\Drivers\WDICA.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute   
+ lsdelete  (Verified) Lavasoft AB c:\windows\system32\lsdelete.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify   
+ LBTWlgn Logitech Bluetooth Service (Verified) Logitech c:\program files\common files\logitech\bluetooth\lbtwlgn.dll
+ mgm12n   File not found: mgm12n.dll
+ nnnlljkJ   c:\windows\system32\nnnlljkj.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors   
+ Adobe PDF Port Acrobat ® PDF Port (Not verified) Adobe Systems Incorporated. c:\windows\system32\adobepdf.dll
+ EPL Language Monitor ZUDDCL (Not verified) Number Five Software c:\windows\system32\zsdepl.dcl
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages   
+ C:\WINDOWS\system32\efcAtrPi   c:\windows\system32\efcatrpi.dll
Back to Top
weiz View Drop Down
Newbie
Newbie


Joined: 11 April 2008
Online Status: Offline
Posts: 6
Post Options Post Options   Quote weiz Quote  Post ReplyReply Direct Link To This Post Posted: 15 April 2008 at 10:49pm
i hv uninstall MyWebSearch from Add/Remove
Back to Top
Elite View Drop Down
Senior Member
Senior Member
Avatar

Joined: 15 April 2007
Location: United States
Online Status: Offline
Posts: 175
Post Options Post Options   Quote Elite Quote  Post ReplyReply Direct Link To This Post Posted: 15 April 2008 at 9:46am
Try uninstalling MyWebSearch from Add/Remove.


Edited by Elite - 15 April 2008 at 9:46am
4 > 1
Back to Top
weiz View Drop Down
Newbie
Newbie


Joined: 11 April 2008
Online Status: Offline
Posts: 6
Post Options Post Options   Quote weiz Quote  Post ReplyReply Direct Link To This Post Posted: 15 April 2008 at 7:32am

so wat should i do now???

Back to Top
Elite View Drop Down
Senior Member
Senior Member
Avatar

Joined: 15 April 2007
Location: United States
Online Status: Offline
Posts: 175
Post Options Post Options   Quote Elite Quote  Post ReplyReply Direct Link To This Post Posted: 13 April 2008 at 11:33am
I figured it was the half-open connection limit (I patch it myself). Always good to make sure though.
4 > 1
Back to Top
EP_X0FF View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 4753
Post Options Post Options   Quote EP_X0FF Quote  Post ReplyReply Direct Link To This Post Posted: 13 April 2008 at 9:34am
Your tcpip.sys can be patched to extend number of supported connections.
Ring0 - the source of inspiration
Back to Top
weiz View Drop Down
Newbie
Newbie


Joined: 11 April 2008
Online Status: Offline
Posts: 6
Post Options Post Options   Quote weiz Quote  Post ReplyReply Direct Link To This Post Posted: 13 April 2008 at 3:58am
analisis/66870f5e11f96e9eed0a0348b4685bea
 
sory for late reply


Edited by weiz - 13 April 2008 at 3:59am
Back to Top
Elite View Drop Down
Senior Member
Senior Member
Avatar

Joined: 15 April 2007
Location: United States
Online Status: Offline
Posts: 175
Post Options Post Options   Quote Elite Quote  Post ReplyReply Direct Link To This Post Posted: 12 April 2008 at 12:00am
+ My Web Search Bar Search Scope Monitor    MyWebSearch SearchScope Monitor    (Not verified) MyWebSearch.com    c:\program files\mywebsearch\bar\1.bin\m3srchmn.exe

+ MyWebSearch Search Assistant BHO    MyWebSearch Search Assistant    (Not verified) MyWebSearch.com    c:\program files\mywebsearch\srchastt\1.bin\mwssrcas.dll

+ mwssrcas.dll    MyWebSearch Search Assistant    (Not verified) MyWebSearch.com    c:\program files\mywebsearch\srchastt\1.bin\mwssrcas.dll

+ My Web Search    My Web Search Bar    (Not verified) MyWebSearch.com    c:\program files\mywebsearch\bar\1.bin\mwsbar.dll

You have a lot of sh*t installed.

Additionally, why isn't your tcpip.sys verifying?

Please upload C:\WINDOWS\System32\drivers\tcpip.sys to www.virustotal.com and post the results link.
4 > 1
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down