ruledbychrist
Newbie



Posts: 10
|
 |
vundo problem
« on: Apr 30th, 2008, 8:39pm » |
Quote Modify
|
my log files are too long to post in one message, so i am posting them in parts. i already ran combofix and hijackthis. i don't know what to do next. please help. ComboFix 08-04-29.5 - Geisendorffs 2008-04-30 13:58:34.2 - NTFSx86 Running from: C:\Documents and Settings\Geisendorffs\Desktop\ComboFix.exe * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\smp.bat C:\WINDOWS\a.bat C:\WINDOWS\bdn.com C:\WINDOWS\cookies.ini C:\WINDOWS\Downloaded Program Files\setup.inf C:\WINDOWS\iTunesMusic.exe C:\WINDOWS\mslagent C:\WINDOWS\mssecu.exe C:\WINDOWS\SYSTEM32\ahhayjgk.ini C:\WINDOWS\system32\andbvsnj.ini C:\WINDOWS\system32\awtQgdby.dll C:\WINDOWS\system32\briyenvu.dll C:\WINDOWS\system32\cfowwdux.dll C:\WINDOWS\system32\emytyfmv.ini C:\WINDOWS\system32\kgjyahha.dll C:\WINDOWS\system32\MabryObj.dll C:\WINDOWS\system32\smp C:\WINDOWS\system32\smp\msrc.exe C:\WINDOWS\SYSTEM32\uvneyirb.ini C:\WINDOWS\system32\vwfvsreg.ini C:\WINDOWS\system32\wvUllIYP.dll C:\WINDOWS\system32\xudwwofc.ini C:\WINDOWS\SYSTEM32\ybdgQtwa.ini C:\WINDOWS\SYSTEM32\ybdgQtwa.ini2 C:\WINDOWS\Web\def.htm . ((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))) . 2008-04-30 13:04 . 2008-04-30 13:04<DIR>d--------C:\Program Files\Trend Micro 2008-04-25 09:28 . 2008-04-30 14:2754,156--ah-----C:\WINDOWS\QTFont.qfn 2008-04-25 09:28 . 2008-04-25 09:281,409--a------C:\WINDOWS\QTFont.for 2008-04-25 00:08 . 2008-04-25 09:46<DIR>d--------C:\Program Files\Windows Live Safety Center 2008-04-24 20:35 . 2008-04-24 21:59<DIR>d--------C:\Program Files\RegCure 2008-04-24 11:10 . 2008-04-24 11:100--a------C:\WINDOWS\exchng.ini 2008-04-23 23:34 . 2007-06-04 10:5667,968--a------C:\WINDOWS\SYSTEM32\DRIVERS\BSafFltr.sys 2008-04-23 23:34 . 2007-06-04 10:5629,024--a------C:\WINDOWS\SYSTEM32\DRIVERS\bsofrwl.sys 2008-04-23 02:48 . 2008-04-23 02:481,075--a------C:\WINDOWS\SYSTEM32\hgGwUkKc.dll 2008-04-23 02:37 . 2008-04-23 02:371,075--a------C:\WINDOWS\SYSTEM32\geBrsRHX.dll 2008-04-23 01:36 . 2008-04-23 01:361,087--a------C:\WINDOWS\SYSTEM32\qoMfghhf.dll 2008-04-22 20:43 . 2008-04-22 20:431,087--a------C:\WINDOWS\SYSTEM32\hgGwUkHw.dll 2008-04-22 19:43 . 2008-04-22 19:431,087--a------C:\WINDOWS\SYSTEM32\pmnlmmLB.dll 2008-04-22 18:43 . 2008-04-22 18:431,087--a------C:\WINDOWS\SYSTEM32\ljJATjjh.dll 2008-04-22 17:43 . 2008-04-22 17:431,087--a------C:\WINDOWS\SYSTEM32\iifdbcyY.dll 2008-04-22 15:43 . 2008-04-22 15:431,087--a------C:\WINDOWS\SYSTEM32\efccyxWo.dll 2008-04-22 14:43 . 2008-04-22 14:431,087--a------C:\WINDOWS\SYSTEM32\khfEVOFv.dll 2008-04-21 23:56 . 2008-04-21 23:561,087--a------C:\WINDOWS\SYSTEM32\tuvTJyWp.dll 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\WINWGPX.EXE 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\winsystem.exe 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\sysreq.exe 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\newsd32.exe 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\mssecu.exe 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\bdn.com 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\awtoolb.dll 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\anticipator.dll 2008-04-21 22:31 . 2008-04-21 22:314,096--a------C:\WINDOWS\SYSTEM32\akttzn.exe 2008-04-21 21:47 . 2008-04-21 21:471,087--a------C:\WINDOWS\SYSTEM32\byXNgdaw.dll 2008-04-21 20:47 . 2008-04-21 20:471,087--a------C:\WINDOWS\SYSTEM32\fccaYrOI.dll 2008-04-21 19:47 . 2008-04-21 19:471,087--a------C:\WINDOWS\SYSTEM32\ssqpMCSk.dll 2008-04-21 18:47 . 2008-04-21 18:471,087--a------C:\WINDOWS\SYSTEM32\ssqNGyxu.dll 2008-04-21 16:47 . 2008-04-21 16:471,087--a------C:\WINDOWS\SYSTEM32\mlJCRlLE.dll 2008-04-21 15:47 . 2008-04-21 15:471,087--a------C:\WINDOWS\SYSTEM32\byXRjhfF.dll 2008-04-21 14:46 . 2008-04-21 14:461,087--a------C:\WINDOWS\SYSTEM32\hgGvuUmj.dll 2008-04-21 13:46 . 2008-04-21 13:461,087--a------C:\WINDOWS\SYSTEM32\qoMghgEW.dll 2008-04-21 12:46 . 2008-04-21 12:461,087--a------C:\WINDOWS\SYSTEM32\ssqRKdBq.dll 2008-04-21 11:46 . 2008-04-21 11:461,087--a------C:\WINDOWS\SYSTEM32\vtUopQJb.dll 2008-04-21 10:46 . 2008-04-21 10:461,087--a------C:\WINDOWS\SYSTEM32\ddcAstsR.dll 2008-04-21 09:46 . 2008-04-21 09:461,087--a------C:\WINDOWS\SYSTEM32\jkkJbcDS.dll 2008-04-21 08:46 . 2008-04-21 08:461,087--a------C:\WINDOWS\SYSTEM32\yayvTkIx.dll 2008-04-21 07:46 . 2008-04-21 07:461,087--a------C:\WINDOWS\SYSTEM32\ljJBrRjK.dll 2008-04-21 06:46 . 2008-04-21 06:461,087--a------C:\WINDOWS\SYSTEM32\geBrqqNg.dll 2008-04-21 05:46 . 2008-04-21 05:461,087--a------C:\WINDOWS\SYSTEM32\urqRJBRI.dll 2008-04-21 04:46 . 2008-04-21 04:461,087--a------C:\WINDOWS\SYSTEM32\rqRJDuRk.dll 2008-04-21 03:46 . 2008-04-21 03:461,087--a------C:\WINDOWS\SYSTEM32\xxywXOhE.dll 2008-04-21 02:46 . 2008-04-21 02:461,087--a------C:\WINDOWS\SYSTEM32\rqRHwUNF.dll 2008-04-21 01:46 . 2008-04-21 01:461,087--a------C:\WINDOWS\SYSTEM32\awttuvsr.dll 2008-04-21 00:46 . 2008-04-21 00:461,087--a------C:\WINDOWS\SYSTEM32\pmnmnOHx.dll 2008-04-20 23:46 . 2008-04-20 23:461,087--a------C:\WINDOWS\SYSTEM32\urqRHyvV.dll 2008-04-20 22:46 . 2008-04-20 22:461,087--a------C:\WINDOWS\SYSTEM32\awtqoPiH.dll 2008-04-20 21:46 . 2008-04-20 21:461,087--a------C:\WINDOWS\SYSTEM32\wvUoPheF.dll 2008-04-20 20:46 . 2008-04-20 20:461,087--a------C:\WINDOWS\SYSTEM32\wvUliiiI.dll 2008-04-20 09:53 . 2008-04-20 09:531,087--a------C:\WINDOWS\SYSTEM32\cbXOHBQj.dll 2008-04-20 08:53 . 2008-04-20 08:531,087--a------C:\WINDOWS\SYSTEM32\iifcYpMe.dll 2008-04-20 07:53 . 2008-04-20 07:531,087--a------C:\WINDOWS\SYSTEM32\nnnKbaaY.dll 2008-04-20 06:53 . 2008-04-20 06:531,087--a------C:\WINDOWS\SYSTEM32\ssqRKeca.dll 2008-04-20 05:53 . 2008-04-20 05:531,087--a------C:\WINDOWS\SYSTEM32\cbXOgffE.dll 2008-04-20 04:53 . 2008-04-20 04:531,087--a------C:\WINDOWS\SYSTEM32\opnkiFya.dll 2008-04-20 03:53 . 2008-04-20 03:531,087--a------C:\WINDOWS\SYSTEM32\ssqrqOHX.dll 2008-04-20 02:53 . 2008-04-20 02:531,087--a------C:\WINDOWS\SYSTEM32\urqPgFWo.dll 2008-04-20 01:53 . 2008-04-20 01:531,087--a------C:\WINDOWS\SYSTEM32\hgGXRjjK.dll 2008-04-20 00:53 . 2008-04-20 00:531,087--a------C:\WINDOWS\SYSTEM32\awtqoLca.dll 2008-04-19 23:53 . 2008-04-19 23:531,087--a------C:\WINDOWS\SYSTEM32\nnnMGwvT.dll 2008-04-19 22:53 . 2008-04-19 22:531,087--a------C:\WINDOWS\SYSTEM32\fccCUKcD.dll 2008-04-19 20:53 . 2008-04-19 20:531,087--a------C:\WINDOWS\SYSTEM32\urqQKayX.dll 2008-04-19 19:53 . 2008-04-19 19:531,087--a------C:\WINDOWS\SYSTEM32\ljJDWQKd.dll 2008-04-19 18:53 . 2008-04-19 18:531,087--a------C:\WINDOWS\SYSTEM32\iifeccdE.dll 2008-04-19 17:53 . 2008-04-19 17:531,087--a------C:\WINDOWS\SYSTEM32\tuvWPfda.dll 2008-04-19 14:47 . 2008-04-19 14:471,087--a------C:\WINDOWS\SYSTEM32\nnnkJCRJ.dll 2008-04-19 13:47 . 2008-04-19 13:471,087--a------C:\WINDOWS\SYSTEM32\tuvtTnNG.dll 2008-04-19 12:47 . 2008-04-19 12:471,087--a------C:\WINDOWS\SYSTEM32\mlJawUNH.dll 2008-04-19 11:47 . 2008-04-19 11:471,087--a------C:\WINDOWS\SYSTEM32\hgGyvSLE.dll 2008-04-19 10:47 . 2008-04-19 10:471,087--a------C:\WINDOWS\SYSTEM32\ljJDUnlL.dll 2008-04-19 09:32 . 2008-04-19 09:321,075--a------C:\WINDOWS\SYSTEM32\wvUopQJB.dll 2008-04-19 07:32 . 2008-04-19 07:321,075--a------C:\WINDOWS\SYSTEM32\mlJDwWQi.dll 2008-04-19 06:32 . 2008-04-19 06:321,075--a------C:\WINDOWS\SYSTEM32\wvUnOGWQ.dll 2008-04-19 05:32 . 2008-04-19 05:321,075--a------C:\WINDOWS\SYSTEM32\xxywwXPg.dll 2008-04-19 03:32 . 2008-04-19 03:321,087--a------C:\WINDOWS\SYSTEM32\vtUkljGa.dll 2008-04-19 02:32 . 2008-04-19 02:321,087--a------C:\WINDOWS\SYSTEM32\pmnLETmL.dll 2008-04-19 01:26 . 2008-04-23 02:28<DIR>d--------C:\Documents and Settings\All Users\Application Data\bypcfgzo 2008-04-17 20:45 . 2008-04-17 20:45<DIR>d--------C:\Program Files\MSECache 2008-04-10 21:54 . 2008-04-10 21:55<DIR>d--------C:\BUSYTOWN 2008-04-10 17:31 . 2008-04-10 17:32<DIR>d--------C:\WINDOWS\CWONDERS 2008-04-10 17:31 . 2008-04-10 17:31<DIR>d--------C:\CWONDERS 2008-04-08 18:37 . 2008-01-29 10:39184,320--a------C:\WINDOWS\SYSTEM32\InetCntrl0011.dll 2008-04-04 16:10 . 2008-04-04 16:10<DIR>d--------C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-03-13 10:29 . 2008-03-13 10:29<DIR>d--------C:\Documents and Settings\All Users\Application Data\TGHomeSoft 2008-03-13 10:21 . 2008-03-13 10:21<DIR>d--------C:\Program Files\TGHome . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-30 19:28---------d-----wC:\Program Files\lx_cats 2008-04-24 18:28---------d--h--wC:\Program Files\InstallShield Installation Information 2008-04-24 18:22---------d-----wC:\Program Files\NCP6 2008-04-23 21:06---------d-----wC:\Program Files\Common Files\Symantec Shared 2008-04-23 21:06---------d-----wC:\Documents and Settings\All Users\Application Data\Symantec 2008-04-23 20:54---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP 2008-04-23 20:28---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-04-23 19:53---------d-----wC:\Program Files\Lavasoft 2008-04-23 19:53---------d-----wC:\Documents and Settings\Geisendorffs\Application Data\Lavasoft 2008-04-23 15:06---------d-----wC:\Documents and Settings\Geisendorffs\Application Data\Symantec 2008-04-23 07:21---------d-----wC:\Program Files\QuickTime 2008-04-18 14:58---------d-----wC:\Documents and Settings\Geisendorffs\Application Data\AdobeUM 2008-04-08 03:46---------d-----wC:\Program Files\DeductionPro 2007 2008-04-04 21:10---------d-----wC:\Documents and Settings\Geisendorffs\Application Data\Yahoo! 2008-03-11 03:59---------d--h--wC:\Documents and Settings\Geisendorffs\Application Data\Move Networks 2006-04-09 01:2011,892,223----a-wC:\Program Files\DeductionPro_2005-6_Installer.exe 2005-06-02 19:1364,600-c--a-wC:\Documents and Settings\Geisendorffs\Application Data\GDIPFONTCACHEV1.DAT 2004-12-30 04:43216,096----a-wC:\Program Files\aide-0.9.tar.tar 2004-07-29 15:0210,135,688----a-wC:\Program Files\MPSetupXP.exe 2004-07-20 14:346,185,072----a-wC:\Program Files\InstallPuzzleInlay.exe 2004-04-28 18:191,092,902----a-wC:\Program Files\wash33.exe 2004-04-01 21:031,760,378----a-wC:\Program Files\aaw6.exe 2004-04-01 05:105,008,016----a-wC:\Program Files\zonealarm.exe 2003-06-02 02:541,075,399----a-wC:\Program Files\photovulink2_10.exe 2003-05-19 03:278,839,120----a-wC:\Program Files\AcroReader51_ENU.exe 2003-05-05 22:123,750,576----a-wC:\Program Files\zaSetup_37_143.exe 2003-05-03 11:1619,208,239----a-wC:\Program Files\ecdc_v5.3.5.10_plt_enu.exe 2003-04-29 16:00207,759----a-wC:\Program Files\INSTALL.LOG 1996-10-29 20:5312,848----a-wC:\Program Files\readpre.txt .
|