Steffan72
2007-07-19, 10:25
I cannot remove this Malware/Trojan.......I have tried different programs (i.e. symantec virtumonde removal, nod32, vundofix) and deleted registry entries and still the PC registers that I have the Virtumonde in the system. I have run ComboFix, Hijackthis and here are its logs..any help will be greatly appreciated, thanks. :bigthumb:
ComboFix
C:\WINDOWS\system32\goicvljt.dll
C:\WINDOWS\system32\qvptsemx.dll
C:\WINDOWS\system32\hqwhrrto.exe
C:\WINDOWS\system32\vriumwol.exe
C:\WINDOWS\system32\weidoxxs.exe
C:\WINDOWS\system32\ahgccwhw.dll
C:\WINDOWS\system32\elsnkyod.dll
C:\WINDOWS\system32\gbdvudua.dll
C:\WINDOWS\system32\iievykle.dll
C:\WINDOWS\system32\jfledxyc.dll
C:\WINDOWS\system32\mejrkllm.dll
C:\WINDOWS\system32\nysvhdwx.dll
C:\WINDOWS\system32\olmcjtoq.dll
C:\WINDOWS\system32\oxtxgtgl.dll
C:\WINDOWS\system32\puqhwypq.dll
C:\WINDOWS\system32\qqtpgavp.dll
C:\WINDOWS\system32\rtmkgueo.dll
C:\WINDOWS\system32\sxuqlkhs.dll
C:\WINDOWS\system32\tpkorlas.dll
C:\WINDOWS\system32\ttsvgrjw.dll
C:\WINDOWS\system32\uqxeyrod.dll
C:\WINDOWS\system32\vgifysct.dll
C:\WINDOWS\system32\viyubsuj.dll
C:\WINDOWS\system32\vweakrap.dll
C:\WINDOWS\system32\wgevxack.dll
C:\WINDOWS\system32\wglnlyli.dll
C:\WINDOWS\system32\ygymvdqv.dll
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\xmestpvq.ini
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\mljkllm.dll
C:\WINDOWS\system32\mljkllm.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\mljkllm.dll
C:\WINDOWS\system32\mljkllm.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bnylqcwh.exe
C:\WINDOWS\system32\bsoplmjr.exe
C:\WINDOWS\system32\cfkfghia.exe
C:\WINDOWS\system32\clyjwdvg.exe
C:\WINDOWS\system32\crxdshha.exe
C:\WINDOWS\system32\dfeayfkx.exe
C:\WINDOWS\system32\eacwhsjs.exe
C:\WINDOWS\system32\efclpxfh.exe
C:\WINDOWS\system32\ehpoosbl.exe
C:\WINDOWS\system32\eqkhlalv.exe
C:\WINDOWS\system32\eswewlgv.exe
C:\WINDOWS\system32\euufnpvs.exe
C:\WINDOWS\system32\grebnkay.exe
C:\WINDOWS\system32\gsdogljg.exe
C:\WINDOWS\system32\hnfmcbxo.exe
C:\WINDOWS\system32\iauhuqie.exe
C:\WINDOWS\system32\jfojyygt.exe
C:\WINDOWS\system32\kpfgquxx.exe
C:\WINDOWS\system32\krvqrexm.exe
C:\WINDOWS\system32\logpchsh.exe
C:\WINDOWS\system32\mlgederm.exe
C:\WINDOWS\system32\mtaxcyji.exe
C:\WINDOWS\system32\nfwcemyt.exe
C:\WINDOWS\system32\opgjgypp.exe
C:\WINDOWS\system32\plhbleux.exe
C:\WINDOWS\system32\pmvophis.exe
C:\WINDOWS\system32\pqklvaqw.exe
C:\WINDOWS\system32\qaggoqkj.exe
C:\WINDOWS\system32\qmrdstug.exe
C:\WINDOWS\system32\qokdqjha.exe
C:\WINDOWS\system32\rnrstqft.exe
C:\WINDOWS\system32\ryrngicx.exe
C:\WINDOWS\system32\sgsckcuk.exe
C:\WINDOWS\system32\skdtpxny.exe
C:\WINDOWS\system32\tcvqulbq.exe
C:\WINDOWS\system32\txgmltuu.exe
C:\WINDOWS\system32\ugjqfokm.exe
C:\WINDOWS\system32\uormaiqn.exe
C:\WINDOWS\system32\verocqqh.exe
((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))
2007-07-18 14:22 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-16 14:14 <DIR> d--hs---- C:\WINDOWS\CSC
2007-07-16 13:32 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-07-16 13:32 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-07-16 13:32 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-10 13:26 175,616 --a------ C:\WINDOWS\system32\tet.exe
2007-07-10 13:26 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-10 13:23 <DIR> d-------- C:\VundoFix Backups
2007-07-10 12:56 266,336 --a------ C:\WINDOWS\system32\ssqrs.dll
2007-07-10 12:51 31,254 --a------ C:\WINDOWS\system32\mljkllm.dll
2007-07-10 12:51 175,616 --a------ C:\WINDOWS\tet.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-18 11:12:47 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\MailWasherPro
2007-07-18 06:15:06 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Avant Browser
2007-07-10 11:45:21 -------- d-----w C:\Program Files\MSN Messenger
2007-07-10 11:28:19 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-06-12 06:44:15 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
2007-06-11 10:28:32 -------- d-----w C:\Program Files\Common Files\Ahead
2007-06-11 10:21:21 -------- d-----w C:\Program Files\Nero
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-03-19 12:54:10 19,000 ----a-w C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{253AE266-52F7-4C9F-B096-AE76DD4AB706}]
2007-07-10 12:56 266336 --a------ C:\WINDOWS\system32\ssqrs.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-11-09 16:21 440056 --a------ C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}]
2007-07-10 12:51 31254 --a------ C:\WINDOWS\system32\mljkllm.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-28 00:21 C:\WINDOWS\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2006-06-02 02:22 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-03-19 10:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-14 10:02]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 23:48]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"QNPlus"="C:\Program Files\Conceptworld\QNPlus\QNPlus.exe" [2004-05-21 16:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"combofix"=C:\WINDOWS\system32\cmd.exe /c C:\ComboFix\Combobatch.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}"="C:\WINDOWS\system32\mljkllm.dll" [2007-07-10 12:51]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljkllm]
mljkllm.dll --a------ 2007-07-10 12:51 31254 C:\WINDOWS\system32\mljkllm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrs]
C:\WINDOWS\system32\ssqrs.dll --a------ 2007-07-10 12:56 266336 C:\WINDOWS\system32\ssqrs.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e71a95f4-3cdc-11db-98ee-0017313b1430}]
AutoRun\command- setupSNK.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 14:28:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-18 14:30:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-18 14:30
Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 15:09:09, on 18/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Conceptworld\QNPlus\QNPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MailWasher Pro\MailWasher.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {253AE266-52F7-4C9F-B096-AE76DD4AB706} - C:\WINDOWS\system32\ssqrs.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - C:\WINDOWS\system32\qmnweuom.dll
O2 - BHO: (no name) - {FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F} - C:\WINDOWS\system32\mljkllm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QNPlus] C:\Program Files\Conceptworld\QNPlus\QNPlus.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = C:\Program Files\MailWasher Pro\MailWasher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.westlaw.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{844CA461-F432-4DC3-BF79-D93C2454EA83}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: mljkllm - C:\WINDOWS\SYSTEM32\mljkllm.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
ComboFix
C:\WINDOWS\system32\goicvljt.dll
C:\WINDOWS\system32\qvptsemx.dll
C:\WINDOWS\system32\hqwhrrto.exe
C:\WINDOWS\system32\vriumwol.exe
C:\WINDOWS\system32\weidoxxs.exe
C:\WINDOWS\system32\ahgccwhw.dll
C:\WINDOWS\system32\elsnkyod.dll
C:\WINDOWS\system32\gbdvudua.dll
C:\WINDOWS\system32\iievykle.dll
C:\WINDOWS\system32\jfledxyc.dll
C:\WINDOWS\system32\mejrkllm.dll
C:\WINDOWS\system32\nysvhdwx.dll
C:\WINDOWS\system32\olmcjtoq.dll
C:\WINDOWS\system32\oxtxgtgl.dll
C:\WINDOWS\system32\puqhwypq.dll
C:\WINDOWS\system32\qqtpgavp.dll
C:\WINDOWS\system32\rtmkgueo.dll
C:\WINDOWS\system32\sxuqlkhs.dll
C:\WINDOWS\system32\tpkorlas.dll
C:\WINDOWS\system32\ttsvgrjw.dll
C:\WINDOWS\system32\uqxeyrod.dll
C:\WINDOWS\system32\vgifysct.dll
C:\WINDOWS\system32\viyubsuj.dll
C:\WINDOWS\system32\vweakrap.dll
C:\WINDOWS\system32\wgevxack.dll
C:\WINDOWS\system32\wglnlyli.dll
C:\WINDOWS\system32\ygymvdqv.dll
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\xmestpvq.ini
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\mljkllm.dll
C:\WINDOWS\system32\mljkllm.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\mljkllm.dll
C:\WINDOWS\system32\mljkllm.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bnylqcwh.exe
C:\WINDOWS\system32\bsoplmjr.exe
C:\WINDOWS\system32\cfkfghia.exe
C:\WINDOWS\system32\clyjwdvg.exe
C:\WINDOWS\system32\crxdshha.exe
C:\WINDOWS\system32\dfeayfkx.exe
C:\WINDOWS\system32\eacwhsjs.exe
C:\WINDOWS\system32\efclpxfh.exe
C:\WINDOWS\system32\ehpoosbl.exe
C:\WINDOWS\system32\eqkhlalv.exe
C:\WINDOWS\system32\eswewlgv.exe
C:\WINDOWS\system32\euufnpvs.exe
C:\WINDOWS\system32\grebnkay.exe
C:\WINDOWS\system32\gsdogljg.exe
C:\WINDOWS\system32\hnfmcbxo.exe
C:\WINDOWS\system32\iauhuqie.exe
C:\WINDOWS\system32\jfojyygt.exe
C:\WINDOWS\system32\kpfgquxx.exe
C:\WINDOWS\system32\krvqrexm.exe
C:\WINDOWS\system32\logpchsh.exe
C:\WINDOWS\system32\mlgederm.exe
C:\WINDOWS\system32\mtaxcyji.exe
C:\WINDOWS\system32\nfwcemyt.exe
C:\WINDOWS\system32\opgjgypp.exe
C:\WINDOWS\system32\plhbleux.exe
C:\WINDOWS\system32\pmvophis.exe
C:\WINDOWS\system32\pqklvaqw.exe
C:\WINDOWS\system32\qaggoqkj.exe
C:\WINDOWS\system32\qmrdstug.exe
C:\WINDOWS\system32\qokdqjha.exe
C:\WINDOWS\system32\rnrstqft.exe
C:\WINDOWS\system32\ryrngicx.exe
C:\WINDOWS\system32\sgsckcuk.exe
C:\WINDOWS\system32\skdtpxny.exe
C:\WINDOWS\system32\tcvqulbq.exe
C:\WINDOWS\system32\txgmltuu.exe
C:\WINDOWS\system32\ugjqfokm.exe
C:\WINDOWS\system32\uormaiqn.exe
C:\WINDOWS\system32\verocqqh.exe
((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))
2007-07-18 14:22 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-16 14:14 <DIR> d--hs---- C:\WINDOWS\CSC
2007-07-16 13:32 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-07-16 13:32 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-07-16 13:32 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-10 13:26 175,616 --a------ C:\WINDOWS\system32\tet.exe
2007-07-10 13:26 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-10 13:23 <DIR> d-------- C:\VundoFix Backups
2007-07-10 12:56 266,336 --a------ C:\WINDOWS\system32\ssqrs.dll
2007-07-10 12:51 31,254 --a------ C:\WINDOWS\system32\mljkllm.dll
2007-07-10 12:51 175,616 --a------ C:\WINDOWS\tet.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-18 11:12:47 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\MailWasherPro
2007-07-18 06:15:06 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Avant Browser
2007-07-10 11:45:21 -------- d-----w C:\Program Files\MSN Messenger
2007-07-10 11:28:19 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-06-12 06:44:15 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
2007-06-11 10:28:32 -------- d-----w C:\Program Files\Common Files\Ahead
2007-06-11 10:21:21 -------- d-----w C:\Program Files\Nero
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-03-19 12:54:10 19,000 ----a-w C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{253AE266-52F7-4C9F-B096-AE76DD4AB706}]
2007-07-10 12:56 266336 --a------ C:\WINDOWS\system32\ssqrs.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-11-09 16:21 440056 --a------ C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}]
2007-07-10 12:51 31254 --a------ C:\WINDOWS\system32\mljkllm.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-28 00:21 C:\WINDOWS\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2006-06-02 02:22 C:\WINDOWS\system32\nwiz.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-03-19 10:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-14 10:02]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 23:48]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"QNPlus"="C:\Program Files\Conceptworld\QNPlus\QNPlus.exe" [2004-05-21 16:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"combofix"=C:\WINDOWS\system32\cmd.exe /c C:\ComboFix\Combobatch.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}"="C:\WINDOWS\system32\mljkllm.dll" [2007-07-10 12:51]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljkllm]
mljkllm.dll --a------ 2007-07-10 12:51 31254 C:\WINDOWS\system32\mljkllm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrs]
C:\WINDOWS\system32\ssqrs.dll --a------ 2007-07-10 12:56 266336 C:\WINDOWS\system32\ssqrs.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e71a95f4-3cdc-11db-98ee-0017313b1430}]
AutoRun\command- setupSNK.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 14:28:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-18 14:30:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-18 14:30
Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 15:09:09, on 18/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Conceptworld\QNPlus\QNPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MailWasher Pro\MailWasher.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {253AE266-52F7-4C9F-B096-AE76DD4AB706} - C:\WINDOWS\system32\ssqrs.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - C:\WINDOWS\system32\qmnweuom.dll
O2 - BHO: (no name) - {FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F} - C:\WINDOWS\system32\mljkllm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QNPlus] C:\Program Files\Conceptworld\QNPlus\QNPlus.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MailWasherPro.lnk = C:\Program Files\MailWasher Pro\MailWasher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.westlaw.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{844CA461-F432-4DC3-BF79-D93C2454EA83}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: mljkllm - C:\WINDOWS\SYSTEM32\mljkllm.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe