KG4ONJ
Newbie


Posts: 9
|
 |
Re: Virtumonde Eldorado Trojan - Help with removal
« Reply #10 on: Sep 9th, 2008, 8:57pm » |
Quote Modify
|
OK, I have to apologize - I have been a bit irresponsible. An opportunity came up and I had to leave for about 6 weeks. I was not able to complete your last set of instructions and while I was gone my computer was used by my family. It appears to be back to the same condition, perhaps not as bad. I did all of the same things again up through running ComboFix and a new HJT scan. Things are significantly better but I can't help but think that things are not quite 100% yet. Here is the ComboFix log: ComboFix 08-09-05.12 - Michael Barr 2008-09-09 21:15:44.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2151 [GMT -4:00] Running from: C:\Documents and Settings\Michael Barr\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Michael Barr\Cookies\michael_barr@trafficmp[1].txt C:\Documents and Settings\Michael Barr\Cookies\michael_barr@trafficmp[3].txt C:\Documents and Settings\NetworkService\Cookies\system@precisionclick[1].txt C:\Documents and Settings\NetworkService\Cookies\system@trafficmp[1].txt C:\Documents and Settings\NetworkService\Cookies\system@zedo[1].txt C:\WINDOWS\BMff500078.xml . ((((((((((((((((((((((((( Files Created from 2008-08-10 to 2008-09-10 ))))))))))))))))))))))))))))))) . 2008-09-06 17:43 . 2008-09-07 11:5154,156--ah-----C:\WINDOWS\QTFont.qfn 2008-09-06 17:43 . 2008-09-06 17:431,409--a------C:\WINDOWS\QTFont.for 2008-09-06 02:18 . 2008-09-06 02:180--a------C:\WINDOWS\system32\82aMLVBg.exe.a_a 2008-09-06 00:18 . 2008-09-07 12:2838,914--a------C:\WINDOWS\system32\82aMLVBg.exe 2008-09-06 00:06 . 2008-09-06 00:0529,824--a------C:\WINDOWS\system32\02Pg4EiT.exe 2008-09-06 00:06 . 2008-09-06 00:060--a------C:\WINDOWS\system32\02Pg4EiT.exe.a_a 2008-08-24 09:47 . 2008-05-01 10:33331,776-----c---C:\WINDOWS\system32\dllcache\msadce.dll 2008-08-24 09:45 . 2008-04-11 15:04691,712-----c---C:\WINDOWS\system32\dllcache\inetcomm.dll 2008-08-24 09:23 . 2008-08-24 09:23<DIR>d--------C:\WINDOWS\system32\scripting 2008-08-24 09:23 . 2008-08-24 09:23<DIR>d--------C:\WINDOWS\system32\en 2008-08-24 09:23 . 2008-08-24 09:23<DIR>d--------C:\WINDOWS\l2schemas 2008-08-18 20:57 . 2008-04-13 20:11650,752---------C:\WINDOWS\system32\dot3ui.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-09-10 01:11---------d-----wC:\Documents and Settings\All Users\Application Data\FRISK Software 2008-09-09 22:49---------d-----wC:\Documents and Settings\All Users\Application Data\Google Updater 2008-09-07 18:48---------d-----wC:\Program Files\Finale 2003 2008-08-07 10:50---------d-----wC:\Program Files\Java 2008-07-31 23:5439,248----a-wC:\Documents and Settings\Michael Barr\Application Data\GDIPFONTCACHEV1.DAT 2008-07-26 23:37---------d-----wC:\Documents and Settings\Michael Barr\Application Data\CoreFTP 2008-07-26 13:48162,914----a-wC:\WINDOWS\system32\KG4ONJ.zip 2008-07-26 13:39162,848----a-wC:\WINDOWS\system32\wsfmxdmp.zip 2008-07-26 10:49---------d-----wC:\Documents and Settings\Michael Barr\Application Data\TrojanHunter 2008-07-25 22:22---------d-----wC:\Program Files\TrojanHunter 5.0 2008-07-25 21:56---------d-----wC:\Program Files\Trend Micro 2008-07-25 02:34---------d-----wC:\Documents and Settings\Michael Barr\Application Data\FRISK Software 2008-07-24 05:38---------d-----wC:\Program Files\Google 2008-07-24 02:39---------d-----wC:\Documents and Settings\All Users\Application Data\Lavasoft 2008-07-24 02:37---------d-----wC:\Program Files\Lavasoft 2008-07-24 02:37---------d-----wC:\Program Files\Common Files\Wise Installation Wizard 2008-07-23 18:51---------d-----wC:\Documents and Settings\Michael Barr\Application Data\BitTorrent 2008-07-20 12:04---------d-----wC:\Documents and Settings\Michael Barr\Application Data\Sibelius Software 2008-07-20 12:03604---ha-wC:\Program Files\STLL Notifier 2008-07-20 12:03---------d-----wC:\Documents and Settings\All Users\Application Data\Sibelius Software 2008-07-20 11:58---------d-----wC:\Program Files\Sibelius Software 2008-07-19 02:1094,920----a-wC:\WINDOWS\system32\cdm.dll 2008-07-19 02:1053,448----a-wC:\WINDOWS\system32\wuauclt.exe 2008-07-19 02:1045,768----a-wC:\WINDOWS\system32\wups2.dll 2008-07-19 02:1036,552----a-wC:\WINDOWS\system32\wups.dll 2008-07-19 02:09563,912----a-wC:\WINDOWS\system32\wuapi.dll 2008-07-19 02:09325,832----a-wC:\WINDOWS\system32\wucltui.dll 2008-07-19 02:09205,000----a-wC:\WINDOWS\system32\wuweb.dll 2008-07-19 02:091,811,656----a-wC:\WINDOWS\system32\wuaueng.dll 2008-07-11 03:08---------d-----wC:\Documents and Settings\Michael Barr\Application Data\U3 2008-07-07 20:26253,952----a-wC:\WINDOWS\system32\es.dll 2008-06-24 16:4374,240----a-wC:\WINDOWS\system32\mscms.dll 2008-06-23 16:57826,368----a-wC:\WINDOWS\system32\wininet.dll 2008-06-20 17:46245,248----a-wC:\WINDOWS\system32\mswsock.dll 2008-04-25 18:325,817,064----a-wC:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000] "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600] "SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 C:\WINDOWS\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112] "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112] "EKIJ5000StatusMonitor"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ 5000MUI.exe" [2007-04-03 753664] "MoneyStartUp10.0"="C:\Program Files\Microsoft Money\System\Activation.exe" [2001-07-25 241714] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 385024] "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-17 49152] "HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648] "MediaFace Integration"="C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe" [2003-08-18 53248] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-07-09 1056928] "CTHelper"="CTHELPER.EXE" [2005-05-24 C:\WINDOWS\CTHELPER.EXE] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\WINDOWS\KHALMNPR.Exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\WINDOWS\KHALMNPR.Exe] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2008-02-02 49254] Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-27 124400] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-02-01 692224] Microsoft Office.lnk - C:\Program Files\Microsoft Office XP\Office10\OSA.EXE [2001-02-13 83360] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"= "C:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"= "C:\\CAVEDOG\\TOTALA\\TotalA.exe"= "C:\\Program Files\\DXport\\DXPort.exe"= "C:\\WINDOWS\\system32\\dplaysvr.exe"= "C:\\Program Files\\TADemo\\SERVER.EXE"= "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "C:\\Program Files\\Motorola\\Software Update\\msu.exe"= "C:\\kav\\kav7\\setup.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R2 KodakSvc;Kodak AiO Device Service;C:\Program Files\Kodak\printer\center\KodakSvc.exe [2007-03-22 9728] S2 ousbehci;OrangeWare USB Enhanced Host Controller Service;C:\WINDOWS\system32\Drivers\ousbehci.sys [2005-06-14 45440] S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 95232] S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\getnd5b.sys [2004-01-29 44544] S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-10-10 42112] S3 ousb2hub;OrangeWare USB 2.0 Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2005-06-14 56960] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e49a8b38-eebc-11dc-956b-00112fdd6d54}] \Shell\AutoRun\command - E:\LaunchU3.exe -a [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D48g43BC-4266-43f0-B6ED-9D38C4202C7E}] C:\Program Files\Common Files\mscd.exe . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Documents and Settings\Michael Barr\Application Data\Mozilla\Firefox\Profiles\l7ndjano.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.woot.com FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1202.1501\npCIDetect11.dll . ************************************************************************ ** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-09 21:41:40 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . Completion time: 2008-09-09 21:43:03 ComboFix-quarantined-files.txt 2008-09-10 01:42:28 Pre-Run: 41,666,646,016 bytes free Post-Run: 43,553,865,728 bytes free 152--- E O F ---2008-08-25 07:01:05
|
|
IP Logged |
|
|
|