OPLADMIN
Newbie


Posts: 4
|
 |
Re: Vundo.B infection!
« Reply #2 on: Apr 20th, 2008, 2:27pm » |
Quote Modify
|
ComboFix log: ComboFix 08-04-18.3 - Clarke 2008-04-20 12:15:20.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.165 [GMT -6:00]Running from: C:\Documents and Settings\Clarke\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\pskt.ini C:\WINDOWS\system32\buhcjcnh.dll C:\WINDOWS\system32\geBrsSIy.dll C:\WINDOWS\system32\myfhkedp.dll C:\WINDOWS\system32\pdekhfym.ini C:\WINDOWS\system32\rdqckats.dll C:\WINDOWS\system32\rqRLbyyV.dll C:\WINDOWS\system32\VyybLRqr.ini C:\WINDOWS\system32\VyybLRqr.ini2 . ((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 ))))))))))))))))))))))))))))))) . 2008-04-20 11:30 . 2008-04-20 11:30<DIR>d--------C:\Program Files\Three Rings Design 2008-04-20 11:30 . 2008-02-22 02:3369,632--a------C:\WINDOWS\system32\javacpl.cpl 2008-04-19 16:08 . 2008-04-20 11:43<DIR>d--------C:\VundoFix Backups 2008-04-19 13:22 . 2008-04-19 13:22<DIR>d--------C:\Program Files\Trend Micro 2008-04-18 21:50 . 2008-04-19 03:57294---hs----C:\WINDOWS\system32\mdmnmtdk.ini 2008-04-18 21:44 . 2008-04-20 09:40109,705--a------C:\WINDOWS\BM5f34e7e7.xml 2008-04-18 08:29 . 2008-04-18 08:29<DIR>d--------C:\Documents and Settings\Clarke\Application Data\TrojanHunter 2008-04-18 00:20 . 2008-04-18 00:22<DIR>d--------C:\Program Files\TrojanHunter 5.0 2008-04-17 21:53 . 2008-04-17 23:40294---hs----C:\WINDOWS\system32\olulbwcm.ini 2008-04-17 21:28 . 2008-04-17 21:32172--a------C:\WINDOWS\wininit.ini 2008-04-17 18:52 . 2008-04-17 18:522,541--a------C:\WINDOWS\unins000.dat 2008-04-17 18:37 . 2004-08-04 00:5632,866--a--c---C:\WINDOWS\system32\dllcache\slrundll.exe 2008-04-17 18:37 . 2004-08-04 00:5632,866--a------C:\WINDOWS\slrundll.exe 2008-04-17 11:32 . 2008-04-17 19:061,529,499---hs----C:\WINDOWS\system32\rvvegihe.ini 2008-04-07 09:00 . 2008-04-20 11:4854,156--ah-----C:\WINDOWS\QTFont.qfn 2008-04-07 09:00 . 2008-04-07 09:001,409--a------C:\WINDOWS\QTFont.for 2008-04-07 08:59 . 2008-04-07 08:59<DIR>d--------C:\Program Files\iPod 2008-04-07 08:58 . 2008-04-07 08:59<DIR>d--------C:\Program Files\iTunes 2008-04-07 08:55 . 2008-04-07 08:56<DIR>d--------C:\Program Files\QuickTime 2008-04-02 20:54 . 2008-04-02 20:54<DIR>d--------C:\Documents and Settings\Clarke\Application Data\LEGO Company 2008-04-02 20:53 . 2008-04-02 20:53<DIR>d--------C:\Program Files\LEGO Company 2008-03-30 23:16 . 2008-03-30 23:16<DIR>d--------C:\Documents and Settings\Clarke\Application Data\NeroDCTemplates 2008-03-28 23:37 . 2008-03-28 23:3790,112--a------C:\WINDOWS\system32\QuickTimeVR.qtx 2008-03-28 23:37 . 2008-03-28 23:3757,344--a------C:\WINDOWS\system32\QuickTime.qts 2008-03-25 09:08 . 2008-03-25 09:08<DIR>d--------C:\Program Files\Safari . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-20 17:30---------d-----wC:\Program Files\Java 2008-04-20 13:56---------d-----wC:\Program Files\LogMeIn 2008-04-19 04:42---------d-----wC:\Documents and Settings\Clarke\Application Data\Apple Computer 2008-04-19 01:39---------d-----wC:\Program Files\Common Files\Symantec Shared 2008-04-18 03:54---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-04-18 01:18---------d-----wC:\Program Files\Spybot - Search & Destroy 2008-04-16 19:0139,424--sh--rC:\WINDOWS\livemessenger.com 2008-04-10 05:01---------d-----wC:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-03-26 03:44---------d-----wC:\Program Files\Microsoft Digital Image 2006 2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys 2008-03-14 17:40---------d-----wC:\Documents and Settings\Clarke\Application Data\Intuit 2008-03-14 17:36---------d--h--wC:\Program Files\InstallShield Installation Information 2008-03-14 17:36---------d-----wC:\Program Files\Common Files\AnswerWorks 4.0 2008-03-14 17:31---------d-----wC:\Program Files\TurboTax 2008-03-08 05:35---------d-----wC:\Program Files\Punch! Super Home 2008-03-02 22:41---------d-----wC:\Documents and Settings\Clarke\Application Data\LimeWire 2008-03-01 13:06826,368----a-wC:\WINDOWS\system32\wininet.dll 2008-02-28 16:21---------d-----wC:\Documents and Settings\Clarke\Application Data\Move Networks 2008-02-20 06:51282,624----a-wC:\WINDOWS\system32\gdi32.dll 2008-02-20 05:3245,568----a-wC:\WINDOWS\system32\dnsrslvr.dll 2008-01-29 18:02107,368----a-wC:\WINDOWS\system32\GEARAspi.dll 2007-03-12 15:41722,176----a-wC:\Documents and Settings\Clarke\gotomypc_428.exe 2006-10-30 01:20563,712----a-wC:\Documents and Settings\Clarke\gotomypc_370.exe 2006-02-08 02:40563,712----a-wC:\Documents and Settings\Clarke\370_gotomypc.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AFD2FC0-B2A8-497B-ADFA-885BA1498838}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{56AA862C-7629-4944-8673-72B2BE6602B6}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCBABDA2-801E-4F51-B6E8-0122032FB16B}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-10 10:44 94208] "ares"="C:\Program Files\Ares\Ares.exe" [ ] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 19:01 68856] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2005-10-20 15:45 871936] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-10 11:34 180269] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016] "AdobeVersionCue"="C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2004-03-25 11:35 1732608] "DVDtoiPodConverter_upgrade"="C:\Program Files\E-Zsoft\DVDtoiPodConverter\DVDtoiPodConverter.exe" [2007-12-06 05:25 822272] "LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 16:09 63048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-03-25 19:08 1047712] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01 437160] C:\Documents and Settings\Clarke\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193] Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [2005-09-03 07:45:28 176128] Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423] QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-09-19 11:36:08 960032] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] LMIinit.dll 2007-11-15 19:46 87352 C:\WINDOWS\system32\LMIinit.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\FS9.EXE"= "C:\\WINDOWS\\system32\\dpnsvr.exe"= "C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"= "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"= "C:\\Program Files\\Kodak\\Kodak EasyShare Software\\bin\\EasyShare.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\NetMeeting\\conf.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"= "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "C:\\Program Files\\Internet Explorer\\iexplore.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 12:31] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 12:35] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-08-03 16:09] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 16:09] S3 P1001VID;Creative WebCam (WDM);C:\WINDOWS\system32\DRIVERS\P1001Vid.sys [2002-06-03 21:38] . Contents of the 'Scheduled Tasks' folder "2008-04-17 01:44:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-04-20 18:41:13 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************ ** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-20 12:39:15 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\LogMeIn\x86\ramaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\searchindexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe . ************************************************************************ ** . Completion time: 2008-04-20 12:54:35 - machine was rebooted [Clarke] ComboFix-quarantined-files.txt 2008-04-20 18:54:23 Pre-Run: 20,224,360,448 bytes free Post-Run: 24,702,513,152 bytes free 194--- E O F ---2008-04-16 14:07:05
|
|
IP Logged |
|
|
|