AdvancedHominid
Newbie



Posts: 13
|
 |
Re: mljiigd.dll [Generic.Vundo.A] not quarantined!
« Reply #14 on: Nov 15th, 2007, 4:32pm » |
Quote Modify
|
ComboFix Log: ComboFix 07-11-08.1 - Administrator 2007-11-15 14:50:01.1 - NTFSx86 MINIMAL Running from: C:\Program Files\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data.\pgdkdgrg.dll C:\Documents and Settings\Benjamin\Application Data\Install.dat C:\Documents and Settings\Benjamin\Start Menu\Programs\Startup\findfast.exe C:\Documents and Settings\Jonathan\Start Menu\Programs\Startup\findfast.exe C:\Documents and Settings\Jonathan\Start Menu\Programs\Startup\infos.exe C:\Documents and Settings\Scott\Application Data\install.dat C:\Documents and Settings\Scott\Start Menu\Programs\Startup\findfast.exe C:\Documents and Settings\Yvette\Application Data\install.dat C:\Documents and Settings\Yvette\Start Menu\Programs\Startup\findfast.exe C:\Documents and Settings\Yvette\Start Menu\Programs\Startup\infos.exe C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\WINDOWS\cookies.ini C:\WINDOWS\system32\away.exe.exe C:\WINDOWS\system32\m2 C:\WINDOWS\system32\ntio256.sys C:\WINDOWS\system32\ntsystem.exe C:\WINDOWS\system32\o1 C:\WINDOWS\system32\pac.txt C:\WINDOWS\system32\protector.exe C:\WINDOWS\system32\svcp.csv C:\WINDOWS\system32\v4 C:\WINDOWS\system32\winsub.xml C:\WINDOWS\xlavba8.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_CMDSERVICE -------\LEGACY_DOMAINSERVICE -------\LEGACY_NETWORK_MONITOR -------\LEGACY_NTIO256 -------\LEGACY_XLAVBA8 -------\ntio256 -------\xlavba8 ((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 ))))))))))))))))))))))))))))))) . 2007-11-15 14:4851,200--a------C:\WINDOWS\NirCmd.exe 2007-11-15 14:20592--a------C:\WINDOWS\SYSTEM32\tmp.reg 2007-11-15 14:1626,815,520--a------C:\Program Files\kis7.0.0.125en.exe 2007-11-15 14:121,539,258--a------C:\Program Files\ComboFix.exe 2007-11-15 14:121,043,644--a------C:\Program Files\SmitfraudFix.exe 2007-11-13 12:01289,280--a------C:\WINDOWS\SYSTEM32\libcurl.dll 2007-11-13 12:0155,808--a------C:\WINDOWS\SYSTEM32\spoolv.exe 2007-11-13 12:017,863--a------C:\WINDOWS\drabste.exe 2007-11-13 12:0016,384--a------C:\WINDOWS\xlaherx.exe 2007-11-13 11:46<DIR>d--------C:\VundoFix Backups 2007-11-13 11:40812,344--a------C:\Program Files\HJTInstall.exe 2007-11-13 11:40401,720--a------C:\Program Files\HiJackThis.exe 2007-11-13 11:40318,369--a------C:\Program Files\HiJackThis.zip 2007-11-13 11:40115,712--a------C:\Program Files\VundoFix.exe 2007-11-13 11:4096,978--a------C:\Program Files\VirtumundoBeGone.exe 2007-11-07 14:13<DIR>d--------C:\Documents and Settings\Administrator.GAMEROOM\Application Data\TrojanHunter 2007-11-06 18:25<DIR>d--------C:\Documents and Settings\Yvette\Application Data\ultra 2007-11-06 15:09130,743--a------C:\WINDOWS\noskrnl.exe 2007-11-06 15:097,530--a------C:\WINDOWS\porkaa.exe 2007-11-05 22:03<DIR>d--------C:\Program Files\MSXML 4.0 2007-11-05 21:47584,192---------C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll 2007-11-05 21:46683,520---------C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll 2007-11-05 21:28297,984---------C:\WINDOWS\SYSTEM32\DLLCACHE\msctf.dll 2007-11-05 19:55296,813---hs----C:\WINDOWS\SYSTEM32\egjlm.bak2 2007-11-05 16:56<DIR>d--------C:\Documents and Settings\Scott\Application Data\ultra 2007-11-05 16:5669--a------C:\Documents and Settings\Scott\Application Data\trant.exe 2007-11-05 14:53<DIR>d--------C:\Documents and Settings\Benjamin\Application Data\TrojanHunter 2007-11-05 13:33<DIR>d--------C:\Program Files\TrojanHunter 5.0 2007-11-05 12:03<DIR>d--------C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-11-04 21:51<DIR>d--------C:\Documents and Settings\Benjamin\Application Data\SpywareBot 2007-11-04 19:55281,941---hs----C:\WINDOWS\SYSTEM32\egjlm.bak1 2007-11-04 18:51<DIR>d--------C:\Program Files\a-squared Anti-Malware 2007-11-04 17:06577,025--a------C:\WINDOWS\SYSTEM32\hajhujno.ini.ren 2007-11-04 16:07<DIR>d--------C:\Documents and Settings\Scott\Application Data\Simply Super Software 2007-11-04 15:39<DIR>d--------C:\Documents and Settings\Benjamin\Application Data\Simply Super Software 2007-11-04 15:39<DIR>d-a------C:\Documents and Settings\All Users\Application Data\TEMP 2007-11-04 15:01576,941--a------C:\WINDOWS\SYSTEM32\gekjewhl.ini.ren 2007-11-04 14:55282,046--a------C:\WINDOWS\SYSTEM32\egjlm.bak2.ren 2007-11-04 14:29282,799--a------C:\WINDOWS\SYSTEM32\egjlm.bak1.ren 2007-11-04 14:28288,308--ahs----C:\WINDOWS\SYSTEM32\egjlm.ini.ren 2007-11-03 21:36<DIR>d--hs----C:\WINDOWS\U2NvdHQ 2007-11-03 21:36<DIR>d--------C:\WINDOWS\SYSTEM32\Mz02r 2007-11-03 21:36<DIR>d--------C:\Temp\mZOr 2007-11-03 21:36<DIR>d--------C:\Temp . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-15 19:45---------d-----wC:\Program Files\SmitfraudFix 2007-11-13 20:444,050----a-wC:\Program Files\hijackthis_11_13_07_PostCleaning Snapshot.txt 2007-11-13 20:434,050----a-wC:\Program Files\hijackthis.log 2007-11-06 20:18---------d-----wC:\Documents and Settings\Benjamin\Application Data\MSNInstaller 2007-11-05 17:36---------d-----wC:\Program Files\Common Files\Wise Installation Wizard 2007-10-13 23:30---------d-----wC:\Documents and Settings\Scott\Application Data\ChessBase 2007-10-05 00:16---------d-----wC:\Program Files\BabasChess 2006-05-13 15:1912,345,008-c--a-wC:\Program Files\PlayChessSetup.exe 2005-05-01 01:092,758,380----a-wC:\Program Files\light.zip 2005-04-24 18:226,224,944-c--a-wC:\Program Files\pkr80018en.EXE 2005-04-17 15:455,629,711-c--a-wC:\Program Files\winboard-4_2_7a.exe 2005-07-29 21:24:26472--sha-rC:\WINDOWS\U2NvdHQ\oZhSxJk.vbs . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}] C:\Program Files\fwxkhglp\hgfvlkhx.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7DE7AB1D-AFE9-46D7-845F-909EA229DAE3}] C:\WINDOWS\system32\mljge.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a118d1b1-6d9c-4e95-b4df-f816038c36ac}] C:\WINDOWS\system32\qutteavn.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2007-09-09 09:31] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 05:00] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "AllowLegacyWebView"=1 (0x1) "AllowUnhashedWebView"=1 (0x1) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator.GAMEROOM^Start Menu^Programs^Startup^findfast.exe] path=C:\Documents and Settings\Administrator.GAMEROOM\Start Menu\Programs\Startup\findfast.exe backup=C:\WINDOWS\pss\findfast.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator.GAMEROOM^Start Menu^Programs^Startup^infos.exe] path=C:\Documents and Settings\Administrator.GAMEROOM\Start Menu\Programs\Startup\infos.exe backup=C:\WINDOWS\pss\infos.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk backup=C:\WINDOWS\pss\AOL 9.0 Tray Icon.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autorun.exe] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe backup=C:\WINDOWS\pss\autorun.exeCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autos.exe] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autos.exe backup=C:\WINDOWS\pss\autos.exeCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk backup=C:\WINDOWS\pss\Office Startup.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless USB 2.0 WLAN Card Utility.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless USB 2.0 WLAN Card Utility.lnk backup=C:\WINDOWS\pss\Wireless USB 2.0 WLAN Card Utility.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Benjamin^Start Menu^Programs^Startup^findfast.exe] path=C:\Documents and Settings\Benjamin\Start Menu\Programs\Startup\findfast.exe backup=C:\WINDOWS\pss\findfast.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Benjamin^Start Menu^Programs^Startup^infos.exe] path=C:\Documents and Settings\Benjamin\Start Menu\Programs\Startup\infos.exe backup=C:\WINDOWS\pss\infos.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Benjamin^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=C:\Documents and Settings\Benjamin\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Scott^Start Menu^Programs^Startup^findfast.exe] path=C:\Documents and Settings\Scott\Start Menu\Programs\Startup\findfast.exe backup=C:\WINDOWS\pss\findfast.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Scott^Start Menu^Programs^Startup^infos.exe] path=C:\Documents and Settings\Scott\Start Menu\Programs\Startup\infos.exe backup=C:\WINDOWS\pss\infos.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Yvette^Start Menu^Programs^Startup^findfast.exe] path=C:\Documents and Settings\Yvette\Start Menu\Programs\Startup\findfast.exe backup=C:\WINDOWS\pss\findfast.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Yvette^Start Menu^Programs^Startup^infos.exe] path=C:\Documents and Settings\Yvette\Start Menu\Programs\Startup\infos.exe backup=C:\WINDOWS\pss\infos.exeStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\clkhost] C:\WINDOWS\xlaherx.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla] C:\WINDOWS\system32\dla\tfswctrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dumprep] C:\WINDOWS\system32\spoolv.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e0406f04] rundll32.exe "C:\WINDOWS\system32\unxvijbf.dll",b [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gwiz] C:\WINDOWS\system32\ntsystem.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers] C:\WINDOWS\system32\igfxpers.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray] C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KGTunes] C:\Program Files\KG Tunes\KG Tunes\KG Tunes 5.exe /hide [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\noskrnl] C:\WINDOWS\noskrnl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestTrap] C:\Program Files\PestTrap\PestTrap.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pgdkdgrg] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pgdkdgrg.dll" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printer] C:\WINDOWS\system32\printer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spoolsv] C:\WINDOWS\system32\spoolvs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Undefined] C:\WINDOWS\system32\winter.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAble] C:\Program Files\WinAble\winable.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows installer] C:\winstall.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "AOL ACS"=2 (0x2) S2 mrtRate;mrtRate;C:\WINDOWS\system32\drivers\mrtRate.sys S3 DELL_A02;Dell TrueMobile 1300 USB2.0 WLAN Card Driver;C:\WINDOWS\system32\DRIVERS\PRISMA02.sys S3 noskrnl.sys;noskrnl.sys;\??\C:\WINDOWS\system32\noskrnl.sys S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\system32\Drivers\SilvrLnk.sys S4 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE . ************************************************************************ ** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-15 15:08:07 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . Completion time: 2007-11-15 15:09:41 - machine was rebooted . --- E O F ---
|