payback1110
New member
I also have this bad virtumonde thing. i have some of the threads here and have ran the combfix and here is the log. Spybot found this for me but it keeps coming back. Thanks for the help.
Pat
ComboFix 08-04-29.5 - payback 2008-05-03 12:07:13.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.584 [GMT -6:00]
Running from: C:\Documents and Settings\payback\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))
.
2008-05-03 10:02 . 2008-05-03 10:02 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-28 21:36 . 2008-05-03 11:35 109,747 --a------ C:\WINDOWS\BMffa541c6.xml
2008-04-27 21:54 . 2008-04-28 06:40 406 --ahs---- C:\WINDOWS\system32\supavksr.ini
2008-04-27 20:46 . 2008-04-27 20:46 2,126 --a------ C:\WINDOWS\system32\wpa.dbl
2008-04-26 12:31 . 2008-04-26 12:31 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-26 12:31 . 2008-05-03 12:03 1,024 --ah----- C:\Documents and Settings\Administrator\NTUSER.dat.LOG
2008-04-26 11:53 . 2004-08-04 01:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-17 21:31 . 2008-04-17 21:31 <DIR> d-------- C:\Documents and Settings\payback\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-03 17:42 --------- d-----w C:\Program Files\Eraser
2008-05-02 23:56 --------- d-----w C:\Program Files\McAfee
2008-05-01 13:12 --------- d-----w C:\Documents and Settings\payback\Application Data\SiteAdvisor
2008-04-26 17:52 --------- d-----w C:\Program Files\Web Publish
2008-04-19 16:47 --------- d-----w C:\Program Files\DivX
2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-13 23:51 --------- d-----w C:\Program Files\Java
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-18 19:52 691,545 ----a-w C:\WINDOWS\unins000.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-03_10.10.55.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-03 16:07:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-03 17:43:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-02 19:26:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-03 17:02:01 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-02 19:26:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-03 17:02:01 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
Pat
ComboFix 08-04-29.5 - payback 2008-05-03 12:07:13.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.584 [GMT -6:00]
Running from: C:\Documents and Settings\payback\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))
.
2008-05-03 10:02 . 2008-05-03 10:02 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-28 21:36 . 2008-05-03 11:35 109,747 --a------ C:\WINDOWS\BMffa541c6.xml
2008-04-27 21:54 . 2008-04-28 06:40 406 --ahs---- C:\WINDOWS\system32\supavksr.ini
2008-04-27 20:46 . 2008-04-27 20:46 2,126 --a------ C:\WINDOWS\system32\wpa.dbl
2008-04-26 12:31 . 2008-04-26 12:31 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-26 12:31 . 2008-05-03 12:03 1,024 --ah----- C:\Documents and Settings\Administrator\NTUSER.dat.LOG
2008-04-26 11:53 . 2004-08-04 01:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-17 21:31 . 2008-04-17 21:31 <DIR> d-------- C:\Documents and Settings\payback\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-03 17:42 --------- d-----w C:\Program Files\Eraser
2008-05-02 23:56 --------- d-----w C:\Program Files\McAfee
2008-05-01 13:12 --------- d-----w C:\Documents and Settings\payback\Application Data\SiteAdvisor
2008-04-26 17:52 --------- d-----w C:\Program Files\Web Publish
2008-04-19 16:47 --------- d-----w C:\Program Files\DivX
2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-13 23:51 --------- d-----w C:\Program Files\Java
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-18 19:52 691,545 ----a-w C:\WINDOWS\unins000.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-03_10.10.55.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-03 16:07:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-03 17:43:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-02 19:26:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-03 17:02:01 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-02 19:26:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-03 17:02:01 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.