webbe
2007-08-01, 22:24
Hello there....I seem to have a problem. Spybot found the virtumonde on my pc & I found my way to the forum. So far I ran Vundofix & combofix - I'll post my combofix log below....I would appreciate any help.:eek:
_________________________________________________
ComboFix 07-07-30.2 - "bwebbe" 08/01/2007 13:40:15.1 [GMT -5:00] - NTFS
Microsoft Windows 2000 Professional 5.0.2195.3.1252.1.1033.18.True
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\jkkjj.dll
C:\WINNT\system32\irhdqdws.dll
C:\WINNT\system32\swaixabg.dll
C:\WINNT\system32\yobjlvyk.dll
C:\WINNT\system32\yobjlvyk.dll
C:\WINNT\SYSTEM32\jjkkj.bak1
C:\WINNT\SYSTEM32\jjkkj.ini
C:\WINNT\system32\opnkkjh.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\fnts~1
C:\Program Files\fnts~1\dexplore.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINNT\system32\hlfnj.dll
C:\WINNT\system32\wcpisvit.exe
((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 )))))))))))))))))))))))))))))))
2007-08-01 13:39 51,200 --a------ C:\WINNT\nircmd.exe
2007-08-01 08:19 <DIR> d-------- C:\VundoFix Backups
2007-08-01 05:45 125,504 --a------ C:\WINNT\SYSTEM32\uluqytql.dll
2007-07-31 12:02 83,208 --a------ C:\WINNT\SYSTEM32\S32EVNT1.DLL
2007-07-31 12:02 73,496 --a------ C:\WINNT\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-07-31 12:01 <DIR> d-------- C:\Program Files\Symantec_Client_Security
2007-07-28 05:41 126,016 --a------ C:\WINNT\SYSTEM32\dahhqege.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
07-08-01 13:37 --------- d-------- C:\Program Files\PestPatrol
07-07-31 12:02 --------- d-------- C:\Program Files\Symantec
07-07-31 12:01 --------- d-------- C:\Program Files\Common Files\Symantec Shared
04-03-26 09:50 69198 --a------ C:\DOCUME~1\BWEBBE~1.GAD\APPLIC~1\Winsock2.reg
03-07-22 12:32 12118 --a------ C:\Program Files\complete.wav
03-07-17 14:29 12888 --a------ C:\DOCUME~1\BWEBBE~1.GAD\APPLIC~1\GDIPFONTCACHEV1.DAT
03-01-22 17:08 271 --ah----- C:\Program Files\DESKTOP.INI
03-01-22 17:08 21952 --ah----- C:\Program Files\FOLDER.HTT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F59B5A2-7B52-449F-B033-3243C20CF2E2}]
C:\WINNT\system32\mllmm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{547AD8C8-FEFF-4D41-A791-FE1522C5ABF9}]
C:\WINNT\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69C4B269-5C27-4142-9BBC-B50A058A7957}]
C:\WINNT\system32\dmcompops.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BB0C23AD-F210-4AB9-BF39-3B4E97B8993C}"= C:\Program Files\SuperBar\SuperBar.Dll [ ]
[-HKEY_CLASSES_ROOT\CLSID\{BB0C23AD-F210-4AB9-BF39-3B4E97B8993C}]
[HKEY_CLASSES_ROOT\SuperBar.Component]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [02-07-24 13:00 C:\WINNT\SYSTEM32\MOBSYNC.EXE]
"CreateCD50"="C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" [02-12-17 20:14 ]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [02-12-17 19:28 ]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [02-07-01 09:50 ]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [02-05-20 19:36 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04-01-20 18:00 ]
"PestPatrol Control Center"="C:\PROGRA~1\PESTPA~1\PPControl.exe" [04-11-15 11:49 ]
"PPMemCheck"="C:\PROGRA~1\PESTPA~1\PPMemCheck.exe" [03-04-19 07:53 ]
"CookiePatrol"="C:\PROGRA~1\PESTPA~1\CookiePatrol.exe" [05-01-10 09:35 ]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [05-10-31 12:05 ]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [05-10-31 12:18 ]
"GoToMyPC"="C:\Program Files\Citrix\GoToMyPC\g2svc.exe" [07-01-12 18:45 ]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [03-05-21 01:21 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Internat.exe"="internat.exe" [02-07-24 13:00 C:\WINNT\SYSTEM32\INTERNAT.EXE]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [06-06-20 22:36 ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07-06-15 19:05 ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-06-04 21:53:14]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-07-23 11:59:45]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
WcesWlgn.dll 06-06-20 22:34 14120 C:\WINNT\SYSTEM32\WcesWlgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
R0 fasttrak;fasttrak;C:\WINNT\system32\DRIVERS\fasttrak.sys
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys
R0 mraid2k;mraid2k;C:\WINNT\system32\DRIVERS\mraid2k.sys
R1 Cdr4_2K;Cdr4_2K;C:\WINNT\system32\drivers\Cdr4_2K.sys
R1 Cdralw2k;Cdralw2k;C:\WINNT\system32\drivers\Cdralw2k.sys
R1 cdudf;cdudf;C:\WINNT\system32\drivers\cdudf.sys
R1 pwd_2k;pwd_2k;C:\WINNT\system32\drivers\pwd_2k.sys
R1 UdfReadr;UdfReadr;C:\WINNT\system32\drivers\UdfReadr.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINNT\System32\drivers\AsfAlrt.sys
R2 NAVAPEL;NAVAPEL;\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS
R3 E1000;Intel(R) PRO/1000 Adapter Driver;C:\WINNT\system32\DRIVERS\e1000nt5.sys
R3 lkbdflt2;Logitech Keyboard Class Filter Driver;C:\WINNT\system32\DRIVERS\lkbdflt2.sys
R3 mmc_2K;mmc_2K;C:\WINNT\system32\drivers\mmc_2K.sys
R3 MxlW2k;MxlW2k;C:\WINNT\system32\drivers\MxlW2k.sys
R3 NAVAP;NAVAP;\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 dvd_2K;dvd_2K;C:\WINNT\system32\drivers\dvd_2K.sys
S3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys
S3 MPE;BDA MPE Filter;C:\WINNT\system32\DRIVERS\MPE.sys
S3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys
*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
Contents of the 'Scheduled Tasks' folder
2007-07-28 01:01:02 C:\WINNT\Tasks\BackupMD.job - C:\Tools\BackupMD.cmd
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-01 13:48:28
Windows 5.0.2195 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
C:\WINNT\system32\Perflib_Perfdata_6f8.dat
scan completed successfully
hidden files: 1
**************************************************************************
Completion time: 2007-08-01 13:50:27 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-08-01 13:49
--- E O F ---
_________________________________________________
ComboFix 07-07-30.2 - "bwebbe" 08/01/2007 13:40:15.1 [GMT -5:00] - NTFS
Microsoft Windows 2000 Professional 5.0.2195.3.1252.1.1033.18.True
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\jkkjj.dll
C:\WINNT\system32\irhdqdws.dll
C:\WINNT\system32\swaixabg.dll
C:\WINNT\system32\yobjlvyk.dll
C:\WINNT\system32\yobjlvyk.dll
C:\WINNT\SYSTEM32\jjkkj.bak1
C:\WINNT\SYSTEM32\jjkkj.ini
C:\WINNT\system32\opnkkjh.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\fnts~1
C:\Program Files\fnts~1\dexplore.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINNT\system32\hlfnj.dll
C:\WINNT\system32\wcpisvit.exe
((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 )))))))))))))))))))))))))))))))
2007-08-01 13:39 51,200 --a------ C:\WINNT\nircmd.exe
2007-08-01 08:19 <DIR> d-------- C:\VundoFix Backups
2007-08-01 05:45 125,504 --a------ C:\WINNT\SYSTEM32\uluqytql.dll
2007-07-31 12:02 83,208 --a------ C:\WINNT\SYSTEM32\S32EVNT1.DLL
2007-07-31 12:02 73,496 --a------ C:\WINNT\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-07-31 12:01 <DIR> d-------- C:\Program Files\Symantec_Client_Security
2007-07-28 05:41 126,016 --a------ C:\WINNT\SYSTEM32\dahhqege.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
07-08-01 13:37 --------- d-------- C:\Program Files\PestPatrol
07-07-31 12:02 --------- d-------- C:\Program Files\Symantec
07-07-31 12:01 --------- d-------- C:\Program Files\Common Files\Symantec Shared
04-03-26 09:50 69198 --a------ C:\DOCUME~1\BWEBBE~1.GAD\APPLIC~1\Winsock2.reg
03-07-22 12:32 12118 --a------ C:\Program Files\complete.wav
03-07-17 14:29 12888 --a------ C:\DOCUME~1\BWEBBE~1.GAD\APPLIC~1\GDIPFONTCACHEV1.DAT
03-01-22 17:08 271 --ah----- C:\Program Files\DESKTOP.INI
03-01-22 17:08 21952 --ah----- C:\Program Files\FOLDER.HTT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F59B5A2-7B52-449F-B033-3243C20CF2E2}]
C:\WINNT\system32\mllmm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{547AD8C8-FEFF-4D41-A791-FE1522C5ABF9}]
C:\WINNT\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69C4B269-5C27-4142-9BBC-B50A058A7957}]
C:\WINNT\system32\dmcompops.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BB0C23AD-F210-4AB9-BF39-3B4E97B8993C}"= C:\Program Files\SuperBar\SuperBar.Dll [ ]
[-HKEY_CLASSES_ROOT\CLSID\{BB0C23AD-F210-4AB9-BF39-3B4E97B8993C}]
[HKEY_CLASSES_ROOT\SuperBar.Component]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [02-07-24 13:00 C:\WINNT\SYSTEM32\MOBSYNC.EXE]
"CreateCD50"="C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" [02-12-17 20:14 ]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [02-12-17 19:28 ]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [02-07-01 09:50 ]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [02-05-20 19:36 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04-01-20 18:00 ]
"PestPatrol Control Center"="C:\PROGRA~1\PESTPA~1\PPControl.exe" [04-11-15 11:49 ]
"PPMemCheck"="C:\PROGRA~1\PESTPA~1\PPMemCheck.exe" [03-04-19 07:53 ]
"CookiePatrol"="C:\PROGRA~1\PESTPA~1\CookiePatrol.exe" [05-01-10 09:35 ]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [05-10-31 12:05 ]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [05-10-31 12:18 ]
"GoToMyPC"="C:\Program Files\Citrix\GoToMyPC\g2svc.exe" [07-01-12 18:45 ]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [03-05-21 01:21 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Internat.exe"="internat.exe" [02-07-24 13:00 C:\WINNT\SYSTEM32\INTERNAT.EXE]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [06-06-20 22:36 ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07-06-15 19:05 ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-06-04 21:53:14]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-07-23 11:59:45]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
WcesWlgn.dll 06-06-20 22:34 14120 C:\WINNT\SYSTEM32\WcesWlgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
R0 fasttrak;fasttrak;C:\WINNT\system32\DRIVERS\fasttrak.sys
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys
R0 mraid2k;mraid2k;C:\WINNT\system32\DRIVERS\mraid2k.sys
R1 Cdr4_2K;Cdr4_2K;C:\WINNT\system32\drivers\Cdr4_2K.sys
R1 Cdralw2k;Cdralw2k;C:\WINNT\system32\drivers\Cdralw2k.sys
R1 cdudf;cdudf;C:\WINNT\system32\drivers\cdudf.sys
R1 pwd_2k;pwd_2k;C:\WINNT\system32\drivers\pwd_2k.sys
R1 UdfReadr;UdfReadr;C:\WINNT\system32\drivers\UdfReadr.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINNT\System32\drivers\AsfAlrt.sys
R2 NAVAPEL;NAVAPEL;\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS
R3 E1000;Intel(R) PRO/1000 Adapter Driver;C:\WINNT\system32\DRIVERS\e1000nt5.sys
R3 lkbdflt2;Logitech Keyboard Class Filter Driver;C:\WINNT\system32\DRIVERS\lkbdflt2.sys
R3 mmc_2K;mmc_2K;C:\WINNT\system32\drivers\mmc_2K.sys
R3 MxlW2k;MxlW2k;C:\WINNT\system32\drivers\MxlW2k.sys
R3 NAVAP;NAVAP;\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 dvd_2K;dvd_2K;C:\WINNT\system32\drivers\dvd_2K.sys
S3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys
S3 MPE;BDA MPE Filter;C:\WINNT\system32\DRIVERS\MPE.sys
S3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys
*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
Contents of the 'Scheduled Tasks' folder
2007-07-28 01:01:02 C:\WINNT\Tasks\BackupMD.job - C:\Tools\BackupMD.cmd
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-01 13:48:28
Windows 5.0.2195 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
C:\WINNT\system32\Perflib_Perfdata_6f8.dat
scan completed successfully
hidden files: 1
**************************************************************************
Completion time: 2007-08-01 13:50:27 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-08-01 13:49
--- E O F ---