PDA

View Full Version : Virtumonde - not sure whether removed



moonliter06
2008-06-28, 14:28
Hello!

Nice place to get advice.

On being attacked many times by Virtumonde trojans, have come back and used advices given here. However, on being attacked most recently, used advice of using Combofix, felt all healed and removed. However AVG detected again - which were then vaulted and deleted.

Thereafter re-downloaded Combofix, and ran again. Then rebooted with AVG disabled. The system is faster than before, but am not sure if the Trojan is gone. PLease Help

Here's the last Combofix log:

ComboFix 08-06-20.4 - Shantu-Boney 2008-06-28 16:02:21.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.459 [GMT 4:00]
Running from: C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-28 )))))))))))))))))))))))))))))))
.

2008-06-28 13:47 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-28 12:35 . 2008-06-28 13:31 982 ---hs---- C:\WINDOWS\system32\agsknbsx.ini
2008-06-27 16:12 . 2008-06-27 16:12 81,408 --a--c--- C:\WINDOWS\system32\xsbnksga.dll
2008-06-23 22:22 . 2008-06-23 22:22 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\AdobeUM
2008-06-21 22:13 . 2008-06-21 22:14 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\Ahead
2008-06-21 21:57 . 2008-06-21 21:57 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\Apple Computer
2008-06-21 21:56 . 2008-06-21 21:56 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
2008-06-21 21:56 . 2008-06-21 21:56 1,409 --a--c--- C:\WINDOWS\QTFont.for
2008-06-21 21:52 . 2008-06-21 21:52 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-21 21:41 . 2008-06-21 21:41 <DIR> d-------- C:\Program Files\CCleaner
2008-06-21 19:21 . 2008-06-21 19:21 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\AccurateRip
2008-06-21 19:20 . 2008-06-21 19:19 5,052,280 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-06-21 19:20 . 2008-06-21 19:20 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-06-21 19:20 . 2008-06-21 19:20 13,772 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-06-21 18:49 . 2008-06-21 18:49 <DIR> d-------- C:\Program Files\MP3 Recorder
2008-06-21 18:24 . 2003-05-21 15:31 1,063,040 --a------ C:\WINDOWS\system32\drivers\HSF_DP.sys
2008-06-21 18:24 . 2003-04-15 06:00 231,867 --a------ C:\WINDOWS\system32\drivers\hpm0850.cty
2008-06-21 18:24 . 2003-05-21 15:35 65,536 --a------ C:\WINDOWS\system32\carpdll.dll
2008-06-21 18:24 . 2003-05-21 15:35 30,592 --a------ C:\WINDOWS\system32\drivers\strmdisp.sys
2008-06-21 18:24 . 2003-04-15 06:00 12,074 --a------ C:\WINDOWS\system32\hsfinst.dll
2008-06-21 18:24 . 2003-05-21 15:35 4,608 --a------ C:\WINDOWS\system32\carpserv.exe
2008-06-21 18:22 . 2008-06-21 18:22 <DIR> d----c--- C:\Documents and Settings\SHANTU~1~SHA\LOCALS~1
2008-06-21 18:22 . 2008-06-21 18:22 <DIR> d----c--- C:\Documents and Settings\SHANTU~1~SHA
2008-06-21 18:10 . 2004-11-04 18:42 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll
2008-06-21 01:08 . 2008-06-21 01:08 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\CyberLink
2008-06-20 15:07 . 2008-06-20 15:07 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\ESTsoft
2008-06-20 14:57 . 2008-06-20 14:57 <DIR> d-------- C:\Program Files\CoreAAC
2008-06-20 14:49 . 2008-06-20 14:49 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\GRETECH
2008-06-20 14:48 . 2008-06-20 14:48 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\GRETECH
2008-06-16 22:33 . 2008-06-17 19:47 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-16 21:29 . 2008-06-20 12:34 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\DivX
2008-06-16 20:48 . 2008-06-28 14:42 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY\Application Data\BitTorrent
2008-06-16 20:43 . 2008-06-28 15:33 <DIR> d----c--- C:\Documents and Settings\Shantu-Boney.SHANTUBONEY
2008-06-16 20:43 . 2008-06-16 20:43 <DIR> d--hsc--- C:\Documents and Settings\NetworkService.NT AUTHORITY.000
2008-06-16 20:43 . 2008-06-16 20:43 <DIR> d--hsc--- C:\Documents and Settings\LocalService.NT AUTHORITY.000
2008-06-15 22:32 . 2008-06-20 09:30 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-14 22:43 . 2008-06-14 22:43 0 --a--c--- C:\WINDOWS\nsreg.dat
2008-06-14 11:42 . 2008-06-14 11:43 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-06-11 14:46 . 2008-05-08 18:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-11 13:55 . 2008-06-13 15:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 15:31 . 2003-04-16 09:00 50,520 --a------ C:\WINDOWS\system32\SP30739.SYS
2008-06-06 20:03 . 2008-06-06 20:03 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-06-03 06:27 . 2008-06-28 15:58 <DIR> d--h-c--- C:\$AVG8.VAULT$
2008-06-02 21:59 . 2008-06-28 15:00 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-02 21:59 . 2008-06-20 09:29 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-02 21:59 . 2008-06-20 09:30 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-02 21:59 . 2008-06-20 09:29 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-02 21:58 . 2008-06-02 21:58 <DIR> d-------- C:\Program Files\AVG
2008-05-30 12:25 . 2008-06-21 18:07 <DIR> d----c--- C:\swsetup
2008-05-30 12:12 . 2008-05-30 12:12 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-05-30 10:57 . 2008-06-21 10:23 410 --a--c--- C:\WINDOWS\Wininit.ini
2008-05-28 06:55 . 2008-06-20 09:53 <DIR> d--h-c--- C:\WINDOWS\$hf_mig$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 11:56 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-28 11:54 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-06-28 09:47 --------- d-----w C:\Program Files\Java
2008-06-27 14:29 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-06-23 18:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-21 14:48 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg8
2008-06-21 14:29 --------- d-----w C:\Program Files\HPQ
2008-06-21 14:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-21 14:21 --------- d-----w C:\Program Files\CONEXANT
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 10:23 --------- d-----w C:\Program Files\Google
2008-06-06 05:20 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-06-02 17:52 --------- d-----w C:\Program Files\Symantec
2008-06-02 17:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-02 17:51 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2008-06-02 17:51 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-26 18:37 --------- d-----w C:\Program Files\Picasa2
2008-05-26 17:15 --------- d-----w C:\Program Files\WIDCOMM
2008-05-23 20:09 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 15:43 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-05-22 15:38 --------- d-----w C:\Program Files\Cyberlink
2008-05-22 15:32 505,392 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-21 14:34 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-21 12:17 --------- d-----w C:\Program Files\uTorrent
2008-05-20 16:51 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-05-18 17:10 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-05-18 17:10 --------- d-----w C:\Program Files\Common Files\Nero
2008-05-17 15:30 --------- d-----w C:\Program Files\NeroInstall.bak
2008-05-16 16:11 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\ESTsoft
2008-05-16 14:37 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-05-16 14:16 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-16 14:16 --------- d-----w C:\Program Files\Common Files\Real
2008-05-16 13:27 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-05-16 13:21 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-05-16 13:21 --------- d-----w C:\Program Files\Apple Software Update
2008-05-16 11:28 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2008-05-16 11:01 --------- d-----w C:\Program Files\HP
2008-05-16 10:41 --------- d-----w C:\Program Files\InterVideo
2008-05-14 17:17 --------- d-----w C:\Program Files\BitTorrent
2008-05-13 17:43 15,890 ----a-w C:\WINDOWS\system32\drivers\mdc8021x.sys
2008-05-13 01:53 9,464 ----a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-13 01:53 9,336 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-13 01:53 43,528 ----a-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-05-13 01:53 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-05-13 01:53 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-13 01:53 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 15:56 524,288 -c--a-w C:\WINDOWS\opuc.dll
2008-04-14 01:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 01:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 01:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:35 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ----a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 48,128 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2004-10-01 11:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2003-06-19 23:05 49,776 ----a-w C:\WINDOWS\inf\usbhub20.sys
2003-06-19 23:05 24,752 ----a-w C:\WINDOWS\inf\hidclass.sys
2003-06-19 23:05 20,688 ----a-w C:\WINDOWS\inf\usbd.sys
2003-06-19 23:05 19,728 ----a-w C:\WINDOWS\inf\usbehci.sys
2003-06-19 23:05 138,288 ----a-w C:\WINDOWS\inf\usbport.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-28_12.32.05.22 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-28 08:25:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-28 11:56:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-13 18:22:03 24,670 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-03-24 21:28:39 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-05-13 18:22:03 28,768 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-03-24 21:28:43 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-03-24 22:37:01 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0DBE1655-0871-4FC5-9969-8ABED669DA22}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ECE8F45-C1CB-4E17-A491-14D740896A43}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{948A8B07-54DF-4411-A963-2B92B8853C64}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3552739-8823-4377-8E94-C4E678382E4B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D554A583-D4CF-4A6F-B07A-CB25F60FA743}]
C:\WINDOWS\system32\efcASmKa.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EDB3F5D9-E4DD-489F-B85E-485B422D0CA2}]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{D554A583-D4CF-4A6F-B07A-CB25F60FA743}"= C:\WINDOWS\system32\efcASmKa.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcASmKa]
efcASmKa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnlKBrS]
opnlKBrS.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyabayA]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NBKeyScan"="D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Administrative Tools\\Recycle Bin\\kdja.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-20 09:30]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-20 09:29]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};D:\Program Files\CyberLink\PowerDVD\000.fcl [2008-01-17 22:35]
R2 avg8emc;AVG8 E-mail Scanner;d:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-20 09:30]
R2 avg8wd;AVG8 WatchDog;d:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-20 09:29]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-20 09:30]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 20:04]
R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 20:04]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS [2003-07-17 06:01]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-24 01:25]
S3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;C:\WINDOWS\system32\DRIVERS\WG11TND5.sys [2004-10-15 10:41]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 18:24]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 12:10]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 16:12]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F8B9E5C0-4DCC-CFCF-ABA5-00401D608516}]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-24 03:43:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-28 08:42:31 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
"2008-06-28 12:05:31 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A9D37181-8692-4FC8-9CB8-FB9A7AB34CE5}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-06-28 12:05:31 C:\WINDOWS\Tasks\User_Feed_Synchronization-{BAF90B0F-8FA8-4C2D-91EA-0A461573ABAC}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-28 16:04:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\D:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-06-28 16:06:24
ComboFix-quarantined-files.txt 2008-06-28 12:05:58
ComboFix2.txt 2008-06-28 11:52:29
ComboFix3.txt 2008-05-20 02:25:27

Pre-Run: 2,859,282,432 bytes free
Post-Run: 2,838,601,728 bytes free

267 --- E O F --- 2008-06-25 13:04:25

tashi
2008-06-29, 06:38
Hello,

Please see our stickies:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Do NOT run 'fixes' before helpers have analyzed the HJT log (http://forums.spybot.info/showthread.php?t=16806)

Start a new topic providing the HJT log with a link back to this thread, which will then be closed as helpers look for topics without a response.

Regards. :)