PDA

View Full Version : Virtumonde and fake "security center balloon"



Blaine0002
2007-09-08, 17:50
So spybot snd says i have virtumonde, and when i remove it it comes right back, ive used all those little remover apps, they say they remove it but it never works. I am also loosing focus in my programs every once and awhile, and i get random popups in IE, I also get popups from avast! saying trojans are trying to be installed on my computer, so i delete them. Oh then theres the random security certificates that pop up that i deny. and theres a fake "security center balloon" that when i click on it, wants me to install ultimate remover or something :P



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:43:47 AM, on 9/8/2003
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\SlySoft\Game Jackal\GameJackal.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\SecCenter\scprot4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Documents and Settings\-Karl-\Desktop\HiJackThis_v2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cmd.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {632AB9DB-EE1E-43B0-AA06-4DD209EE33BF} - C:\WINDOWS\system32\gebxvur.dll
O2 - BHO: (no name) - {64B94229-7967-860A-A0C2-034C02BA876B} - C:\Program Files\Zyrabkxc\vcjjtmea.dll
O2 - BHO: (no name) - {90EFB485-10E6-429B-A321-5E0E89D3CD93} - C:\WINDOWS\system32\ssqpp.dll
O2 - BHO: (no name) - {984544AB-5FA6-46AF-BE1D-E21804DAD281} - C:\WINDOWS\system32\ssqrqqq.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Maplom] C:\Program Files\SlySoft\Game Jackal\GameJackal.exe /silent
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [rgjqletu] rundll32.exe "C:\Program Files\rgjqletu\zunwdsdg.dll",Init
O4 - HKLM\..\Run: [zafitcvu] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\zafitcvu.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Sero] "C:\DOCUME~1\-Karl-\MYDOCU~1\MBOLS~1\cmd.exe" -vt yazb
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167893939828
O20 - Winlogon Notify: gebxvur - C:\WINDOWS\SYSTEM32\gebxvur.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe (file missing)

--
End of file - 8812 bytes



Thx for any help,

And im currently running combofixer to see if that helps.

Blaine0002
2007-09-08, 18:00
here is combofixer log


ComboFix 07-09-08.7 - "-Karl-" 2003-09-08 9:44:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1576 [GMT -5:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\-Karl-\MYDOCU~1\MBOLS~1
C:\DOCUME~1\-Karl-\MYDOCU~1\MBOLS~1\??mbols\
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\ngfynoho.dll
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\zafitcvu.dll
C:\Program Files\rgjqletu
C:\Program Files\rgjqletu\zunwdsdg.dll
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Uhkwqzob
C:\Program Files\Uhkwqzob\uimlnxla.dll
C:\Program Files\Zyrabkxc
C:\Program Files\Zyrabkxc\vcjjtmea.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\eekgialm.exe
C:\WINDOWS\system32\ssqqqrs.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-08 to 2007-09-08 )))))))))))))))))))))))))))))))
.

2007-09-07 18:01 <DIR> d-------- C:\Program Files\PacCafe
2007-09-07 15:16 <DIR> d-------- C:\Program Files\PacSteamT
2007-09-07 15:16 <DIR> d-------- C:\Program Files\Common Files\Thraex Software
2007-09-07 15:04 6,448 ---hs---- C:\WINDOWS\system32\ppqss.bak1
2007-09-07 15:03 244,832 --a------ C:\WINDOWS\system32\ssqpp.dll
2007-09-07 14:57 23,040 --------- C:\WINDOWS\system32\winexy32.dll
2007-09-06 15:40 <DIR> d-------- C:\Program Files\uTorrent
2007-09-04 17:12 <DIR> d-------- C:\DOCUME~1\-Karl-\APPLIC~1\InfraRecorder
2007-09-04 17:08 <DIR> d-------- C:\Program Files\InfraRecorder
2007-09-03 23:29 <DIR> d-------- C:\Office10
2007-09-03 22:53 <DIR> d-------- C:\Program Files\Logs
2007-09-03 22:20 <DIR> d-------- C:\Program Files\Microsoft Visual Studio .NET 2003
2007-09-03 22:20 <DIR> d-------- C:\Program Files\Microsoft Platform SDK for Windows Server 2003 R2
2007-09-03 20:05 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-09-03 20:05 <DIR> d-------- C:\Program Files\Common Files\Merge Modules
2007-09-03 19:54 <DIR> d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Dev-Cpp
2007-09-03 19:48 <DIR> d-------- C:\Program Files\Relsoft
2007-09-03 19:45 <DIR> d-------- C:\LC LUABot v6 Public
2007-09-02 16:38 75,683 --a------ C:\WINDOWS\War3Unin.dat
2007-09-02 16:38 2,829 --a------ C:\WINDOWS\War3Unin.pif
2007-09-02 16:38 139,264 --a------ C:\WINDOWS\War3Unin.exe
2007-09-02 16:20 31,744 --a------ C:\WINDOWS\system32\drivers\maplom.sys
2007-09-01 18:57 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-09-01 18:57 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-09-01 18:56 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-08-31 18:58 <DIR> d-------- C:\Program Files\America's Army Server Manager
2007-08-31 18:54 <DIR> d-------- C:\Program Files\America's Army
2007-08-31 11:58 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2007-08-31 11:58 <DIR> d-------- C:\Program Files\DAP
2007-08-27 18:54 <DIR> d-------- C:\Program Files\DivXCodec
2007-08-26 04:11 <DIR> d-------- C:\Program Files\Blockland
2007-08-23 18:32 <DIR> d-------- C:\FMA3
2007-08-23 17:41 <DIR> d-------- C:\FMA2
2007-08-23 17:35 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2007-08-23 17:35 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-08-23 17:22 <DIR> d-------- C:\FMA1
2007-08-23 16:13 <DIR> d-------- C:\Program Files\DVDtoOgm
2007-08-23 14:46 43,602 --a------ C:\WINDOWS\system32\xvid-uninstall.exe
2007-08-23 14:46 <DIR> d-------- C:\Program Files\AutoGK
2007-08-23 14:09 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2007-08-23 14:09 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2007-08-23 13:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA Corporation
2007-08-23 13:08 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2007-08-23 13:08 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2007-08-23 13:03 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-08-23 13:03 <DIR> d-------- C:\Program Files\Xvid
2007-08-23 12:48 36,734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2007-08-23 12:48 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-08-20 17:17 <DIR> d-------- C:\Program Files\QuickTime
2007-08-20 17:17 <DIR> d-------- C:\Program Files\iTunes
2007-08-20 17:17 <DIR> d-------- C:\Program Files\iPod
2007-08-17 22:47 <DIR> d-------- C:\WINDOWS\system32\Photosynth
2007-08-17 21:04 <DIR> d-------- C:\Program Files\FireTrust
2007-08-17 20:38 <DIR> d-------- C:\DOCUME~1\-Karl-\APPLIC~1\MailWasherPro
2007-08-15 03:02 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-13 14:27 <DIR> d-------- C:\DOCUME~1\-Karl-\APPLIC~1\vlc
2007-08-13 14:05 <DIR> d-------- C:\Program Files\VideoLAN
2007-08-13 11:42 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-08-13 11:34 <DIR> d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Media Player Classic
2007-08-13 11:28 <DIR> d-------- C:\Program Files\Gabest
2007-08-10 18:59 <DIR> d-------- C:\asdfadf
2007-08-08 19:05 <DIR> d-------- C:\Program Files\seRapid

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-08 09:44 2045164 ---hs---- C:\WINDOWS\system32\ppqss.bak2
2007-09-07 18:46 --------- d-------- C:\Program Files\Trillian
2007-09-06 05:09 801144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-09-06 05:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 05:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 05:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 05:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 05:00 95608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-09-06 05:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-04 17:12 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\InfraRecorder
2007-09-03 23:31 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-09-03 20:06 --------- d-------- C:\Program Files\Microsoft Visual Studio 8
2007-09-03 10:22 --------- d-------- C:\Program Files\UT2004
2007-09-02 16:19 --------- d-------- C:\Program Files\SlySoft
2007-09-02 16:15 --------- d-------- C:\Program Files\Elaborate Bytes
2007-09-02 12:11 --------- d-------- C:\Program Files\WE Unlimited
2007-09-02 12:05 --------- d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-09-02 12:03 --------- d-------- C:\Program Files\VentSrv
2007-09-02 12:01 --------- d-------- C:\Program Files\MAIET
2007-08-27 22:47 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-26 01:21 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Hamachi
2007-08-23 14:09 --------- d-------- C:\Program Files\NVIDIA Corporation
2007-08-23 13:08 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-23 10:48 --------- d-------- C:\Program Files\Winamp
2007-08-21 14:27 --------- d-------- C:\Program Files\Starcraft
2007-08-20 17:16 --------- d-------- C:\Program Files\Apple Software Update
2007-08-18 16:54 --------- d-------- C:\Program Files\Magic Workstation
2007-08-17 21:04 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\MailWasherPro
2007-08-14 17:02 82248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-14 17:02 57672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-14 17:02 40264 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-14 17:02 29000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-13 14:27 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\vlc
2007-08-13 14:03 52338 --a------ C:\WINDOWS\system32\RadLightOggUninstall.exe
2007-08-13 11:44 --------- d-------- C:\Program Files\ffdshow
2007-08-13 11:34 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Media Player Classic
2007-08-13 11:33 --------- d-------- C:\Program Files\DivX
2007-08-13 11:30 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-13 11:21 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Apple Computer
2007-08-09 14:43 --------- d-------- C:\Program Files\World of Warcraft
2007-08-07 23:20 --------- d-------- C:\Program Files\WinPcap
2007-08-07 23:19 --------- d-------- C:\Program Files\Hi-Net Software
2007-08-07 19:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-07 19:25 --------- d-------- C:\Program Files\Fraps
2007-08-07 13:58 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-05 13:30 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\vexorian
2007-08-03 12:47 --------- d-------- C:\Program Files\Mozilla Thunderbird
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 15:47 359808 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2007-07-30 15:47 359808 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-07-30 15:28 --------- d-------- C:\Program Files\Shareaza
2007-07-30 15:28 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Shareaza
2007-07-30 11:55 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\WinRAR
2007-07-25 22:06 144704 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-25 21:53 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-25 21:53 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-25 21:50 81920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-25 21:50 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-25 21:50 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-25 21:50 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-25 21:50 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-25 21:50 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-25 21:50 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-25 21:50 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-25 21:49 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-25 18:40 --------- d-------- C:\Program Files\Common Files\Real
2007-07-25 18:07 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\DivX
2007-07-18 23:03 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-07-17 18:01 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Atari
2007-07-17 18:00 --------- d-------- C:\Program Files\Common Files\PocketSoft
2007-07-17 17:56 --------- d-------- C:\Program Files\Atari
2007-07-17 08:56 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-17 08:56 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-14 01:53 --------- d-------- C:\Program Files\Real
2007-07-11 14:37 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-07-10 22:08 --------- d-------- C:\DOCUME~1\-Karl-\APPLIC~1\Ventrilo
2007-07-09 15:55 --------- d-------- C:\Program Files\WC3Banlist
2007-06-29 01:54 356352 --a--c--- C:\WINDOWS\system32\nvudisp.exe
2007-06-29 00:43 8466432 --a------ C:\WINDOWS\system32\nvcpl.dll
2007-06-29 00:43 81920 --a------ C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43 81920 --a------ C:\WINDOWS\system32\nvmctray.dll
2007-06-29 00:43 753664 --a------ C:\WINDOWS\system32\nvcplui.exe
2007-06-29 00:43 6729728 --a------ C:\WINDOWS\system32\nvoglnt.dll
2007-06-29 00:43 6234112 --a------ C:\WINDOWS\system32\nvdisps.dll
2007-06-29 00:43 5690624 --a------ C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43 5455872 --a------ C:\WINDOWS\system32\nvdispsr.dll
2007-06-29 00:43 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43 458752 --a------ C:\WINDOWS\system32\nvmccssr.dll
2007-06-29 00:43 45056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2007-06-29 00:43 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{632AB9DB-EE1E-43B0-AA06-4DD209EE33BF}]
2003-09-08 00:57 44054 --a------ C:\WINDOWS\system32\gebxvur.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{984544AB-5FA6-46AF-BE1D-E21804DAD281}]
C:\WINDOWS\system32\ssqrqqq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1531DB3-3DAD-4A59-9EBB-C4EE69AA92A6}]
2007-09-07 15:03 244832 --a------ C:\WINDOWS\system32\ssqpp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"WatchDog"="C:\Program Files\mobile PhoneTools\WatchDog.exe" []
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe" [2007-03-14 17:23]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 07:12]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 21:34]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 08:21]
"Maplom"="C:\Program Files\SlySoft\Game Jackal\GameJackal.exe" [2007-08-14 18:34]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 05:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 07:00]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
"Sero"="C:\DOCUME~1\-Karl-\MYDOCU~1\MBOLS~1\cmd.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-06 17:26:55]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{984544AB-5FA6-46AF-BE1D-E21804DAD281}"= C:\WINDOWS\system32\ssqrqqq.dll [ ]
"{632AB9DB-EE1E-43B0-AA06-4DD209EE33BF}"= C:\WINDOWS\system32\gebxvur.dll [2003-09-08 00:57 44054]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxvur]
gebxvur.dll 2003-09-08 00:57 44054 C:\WINDOWS\system32\gebxvur.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\system32\\ssqpp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R0 SI3132;SiI-3132 SATALink Controller;C:\WINDOWS\system32\DRIVERS\SI3132.sys
R1 nvport;NVIDIA PORT IO Control Driver;\??\C:\WINDOWS\system32\Drivers\nvport.sys
R3 ADIDTSFiltService;ADI DTS Filter Service;C:\WINDOWS\system32\drivers\adidts.sys
R3 Maplom;Maplom;C:\WINDOWS\system32\drivers\Maplom.sys
S3 mamotou;mamotou;C:\WINDOWS\system32\DRIVERS\mamotou.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21;C:\WINDOWS\system32\DRIVERS\xusb21.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\NCDSTART.EXE

.
Contents of the 'Scheduled Tasks' folder
"2007-08-23 12:57:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2003-09-08 06:20:44 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-08 09:53:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\WINDOWS\system32\ifyxsdyn.dll

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2007-09-08 9:56:06 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-08 09:55
.
--- E O F ---





I am still getting popups and whatnot.

Blaine0002
2007-09-08, 18:03
crap

combofixer killed my avast trial when it changed date settings...

now im unprotected...

tashi
2007-09-08, 18:12
crap

combofixer killed my avast trial when it changed date settings...

now im unprotected...

You seem to have missed the stickied topics for this forum: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Start with ONLY the Two Logs We Ask For in Our Sticky Topic, NOT CF etc (http://forums.spybot.info/showthread.php?t=16806)

Best regards.

tashi
2007-09-17, 00:15
Hello.

We do have this sticky topic:
The Waiting Room: Post here if waiting for help longer than four days (http://forums.spybot.info/forumdisplay.php?f=37)

However if members waiting for assistance do not post there, their topic will be archived after several days.