PDA

View Full Version : Ran ComboFix as Instructed, Please Check Log



sixllamas
2009-02-17, 00:22
Hi,

I ran ComboFix as instructed by the user Shelf Life on Feb 4th to remove Virtumonde and other assorted malware. The log is below. Would someone be able to look over the log and help me continue fixing my laptop?

I really appreciate it. Thanks


---------------------------------------------

ComboFix 09-02-15.01 - me 2009-02-16 16:38:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.226 [GMT -5:00]
Running from: c:\documents and settings\me\My Documents\Downloads\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\me\Application Data\antivirus.exe
c:\documents and settings\me\Application Data\ultra
c:\documents and settings\me\Application Data\ultra\uninstall.bat
c:\documents and settings\me\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GetModule
c:\program files\GetPack
c:\program files\GetPack\GetPack30.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mozilla Firefox\components\0dd8225f-7d07-8ea8-02d9-f0a0470a16b5.dll
c:\program files\VnrPack
c:\program files\VnrPack\dicts.gz
c:\program files\VnrPack\trgts.gz
c:\program files\VnrPack\VnrPack22.exe
c:\windows\system32\apaupyct.dll
c:\windows\system32\aruqppej.dll
c:\windows\system32\avrronvv.dll
c:\windows\system32\BaceKkkj.ini
c:\windows\system32\BaceKkkj.ini2
c:\windows\system32\bahrpmje.dll
c:\windows\system32\bbswko.dll
c:\windows\system32\bdcpjqif.dll
c:\windows\system32\biemeutl.dll
c:\windows\system32\bucura.dll
c:\windows\system32\bvuddyku.dll
c:\windows\system32\caokglcu.dll
c:\windows\system32\ccdsbycx.dll
c:\windows\system32\cpwgtx.dll
c:\windows\system32\ddwqye.dll
c:\windows\system32\dmvgjjah.dll_old
c:\windows\system32\dnlcai.dll
c:\windows\system32\dnujld.dll
c:\windows\system32\dyjxop.dll
c:\windows\system32\eaxykknb.dll
c:\windows\system32\ebujqctt.dll
c:\windows\system32\eccfvfhn.dll
c:\windows\system32\ecdsxryb.dll
c:\windows\system32\edqijphl.dll
c:\windows\system32\eosrvgsq.dll
c:\windows\system32\erdqwk.dll
c:\windows\system32\esrocd.dll
c:\windows\system32\fapomx.dll
c:\windows\system32\ffinnvgg.dll
c:\windows\system32\fflweffi.dll
c:\windows\system32\fytbgm.dll
c:\windows\system32\hcpyaruy.dll
c:\windows\system32\hjhdifqt.dll
c:\windows\system32\hjvqdvos.dll
c:\windows\system32\hpnhfgia.dll
c:\windows\system32\hwaeqggv.dll
c:\windows\system32\ihwrpclb.dll
c:\windows\system32\iqtory.dll
c:\windows\system32\jkkKecaB.dll
c:\windows\system32\jorqywmk.dll
c:\windows\system32\jtohfy.dll
c:\windows\system32\kcxohryx.dll
c:\windows\system32\kvtimnwx.dll
c:\windows\system32\lwpjoxfg.dll
c:\windows\system32\lxeptdja.dll
c:\windows\system32\lyhtwecg.dll
c:\windows\system32\mmfqleem.dll
c:\windows\system32\mouijnvg.dll
c:\windows\system32\mttcegkpuejac.dll
c:\windows\system32\mulvcs.dll
c:\windows\system32\mwojbtjf.dll
c:\windows\system32\nexbgx.dll
c:\windows\system32\nnjxithw.dll
c:\windows\system32\nsdogjjk.dll
c:\windows\system32\nthpna.dll
c:\windows\system32\nyinld.dll
c:\windows\system32\octssykw.dll
c:\windows\system32\ovfvqceo.dll
c:\windows\system32\oysfnjmr.dll
c:\windows\system32\pflypofm.dll
c:\windows\system32\pktibs.dll
c:\windows\system32\pponxb.dll
c:\windows\system32\pqnkehqj.dll
c:\windows\system32\puihsx.dll
c:\windows\system32\qbtyam.dll
c:\windows\system32\qdrhcx.dll
c:\windows\system32\qngcljkq.dll
c:\windows\system32\qorlaz.dll
c:\windows\system32\rgevdg.dll
c:\windows\system32\scqhhb.dll
c:\windows\system32\sjlhahcb.dll
c:\windows\system32\smukhulv.dll
c:\windows\system32\ssanbg.dll
c:\windows\system32\tedhoyyt.dll
c:\windows\system32\tlqugp.dll
c:\windows\system32\tohpeyvo.dll
c:\windows\system32\ttfrdqwr.dll
c:\windows\system32\txrensqr.dll
c:\windows\system32\uapdcv.dll
c:\windows\system32\ubhyrotp.dll
c:\windows\system32\ucddmlwd.dll
c:\windows\system32\ufxsta.dll
c:\windows\system32\unbmpt.dll
c:\windows\system32\usxoqq.dll
c:\windows\system32\vepuxyyg.dll
c:\windows\system32\vfwozm.dll
c:\windows\system32\vjrjiqsd.dll
c:\windows\system32\wiqaqlja.dll
c:\windows\system32\wsxxwyvc.dll
c:\windows\system32\xvxeibfd.dll
c:\windows\system32\ygludplt.dll
c:\windows\system32\ygszva.dll
c:\windows\system32\yhytmurg.dll
c:\windows\system32\ypdunoqs.dll
c:\windows\system32\zbchtb.dll
c:\windows\system32\zgdvsd.dll
c:\windows\system32\zpazrg.dll
c:\windows\system32\zujsnx.dll
c:\windows\system32\zzvbue.dll
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.

2009-02-16 16:32 . 2009-02-16 16:32 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-02-16 16:12 . 2009-02-16 16:12 120 --ahs---- c:\windows\system32\mfopylfp.ini
2009-02-15 15:04 . 2009-02-15 15:04 120 --ahs---- c:\windows\system32\aigfhnph.ini
2009-02-15 13:39 . 2009-02-15 13:39 120 --ahs---- c:\windows\system32\xsyrvudi.ini
2009-02-14 13:35 . 2009-02-14 13:35 120 --ahs---- c:\windows\system32\fjtbjowm.ini
2009-02-11 22:08 . 2009-02-11 22:08 120 --ahs---- c:\windows\system32\gyyxupev.ini
2009-02-09 22:04 . 2009-02-09 22:04 120 --ahs---- c:\windows\system32\xwnmitvk.ini
2009-02-08 21:30 . 2009-02-08 21:30 120 --ahs---- c:\windows\system32\qwlntxjc.ini
2009-02-08 08:02 . 2009-02-08 08:02 120 --ahs---- c:\windows\system32\tcypuapa.ini
2009-02-07 10:36 . 2009-02-07 10:36 85,637 --a------ c:\windows\system32\0f995a83-38bc-c050-811c-6ed7c39fa585.exe
2009-02-07 10:36 . 2009-02-07 10:36 48,266 --a------ c:\windows\system32\mdffpnuhgsr.exe
2009-02-06 19:19 . 2009-02-06 19:19 120 --ahs---- c:\windows\system32\gvnjiuom.ini
2009-02-06 09:33 . 2009-02-06 09:33 120 --ahs---- c:\windows\system32\nhhfvwms.ini
2009-02-05 15:52 . 2009-02-05 15:52 672,768 --a------ c:\windows\system32\nsgB.dll
2009-02-03 23:05 . 2009-02-03 23:05 120 --ahs---- c:\windows\system32\pobdqxbs.ini
2009-02-03 22:45 . 2009-02-03 22:45 120 --ahs---- c:\windows\system32\jqheknqp.ini
2009-02-02 22:42 . 2009-02-02 22:42 120 --ahs---- c:\windows\system32\hshapait.ini
2009-02-01 15:11 . 2009-02-01 15:11 120 --ahs---- c:\windows\system32\rgfonwad.ini
2009-01-31 15:00 . 2009-01-31 15:33 <DIR> d-------- c:\program files\RegCure
2009-01-31 14:17 . 2009-01-31 14:17 120 --ahs---- c:\windows\system32\dwlmddcu.ini
2009-01-31 11:06 . 2009-01-31 11:06 120 --ahs---- c:\windows\system32\tyyohdet.ini
2009-01-30 09:15 . 2009-01-30 09:15 120 --ahs---- c:\windows\system32\bchahljs.ini
2009-01-28 22:51 . 2009-01-28 22:51 120 --ahs---- c:\windows\system32\hajjgvmd.ini
2009-01-28 21:42 . 2009-02-03 13:11 543 --a------ c:\windows\wininit.ini
2009-01-28 21:08 . 2009-01-28 21:08 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-28 21:08 . 2009-01-28 21:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-25 14:39 . 2009-01-25 14:39 <DIR> d-------- c:\program files\Windows Defender
2009-01-20 20:57 . 2009-01-28 21:12 <DIR> d-------- c:\documents and settings\me\Application Data\Twain
2009-01-20 20:52 . 2009-01-20 20:52 <DIR> d-------- c:\program files\WebShow

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 17:56 39,664 ----a-w c:\documents and settings\me\Application Data\GDIPFONTCACHEV1.DAT
2007-03-12 21:08 3,018,824 ----a-w c:\documents and settings\me\Application Data\prg.exe
2009-02-01 21:41 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-02-01 21:41 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-01 21:41 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-02-01 21:41 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-13 04:05 73,728 ----a-w c:\program files\mozilla firefox\components\srff.dll
2009-02-01 21:41 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08b8c0b0-bc5c-96e4-5dd8-ab1b268cef09}]
2009-02-05 15:52 672768 --a------ c:\windows\system32\nsgB.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2003-06-23 1409024]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"TPP Auto Loader"="c:\windows\tppaldr.exe" [2001-10-05 118784]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 81920]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-01 712704]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2003-08-14 90112]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-31 335872]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-09-19 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-03 108544]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
PowerPanel.lnk - c:\program files\PowerPanel\Program\PcfMgr.exe [2003-11-10 872448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cpwgtx.dll erdqwk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"vidc.ffds"= c:\progra~1\ffdshow\ffdshow.ax

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2003-11-07 71961]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};\??\c:\windows\TEMP\13.tmp --> c:\windows\TEMP\13.tmp [?]
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [2003-11-07 24618]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\TPP200.SYS [2005-07-08 35541]
.
Contents of the 'Scheduled Tasks' folder

2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1000410168-989732751-160940925-1005.job
- c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:35]

2009-02-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-01-31 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]

2009-01-31 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]

2009-01-26 c:\windows\Tasks\User_Feed_Synchronization-{618D4097-5CCE-4CA0-9B15-79EFB19E2B20}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]

2009-01-25 c:\windows\Tasks\zqqgeobs.job
- c:\windows\system32\awtsTLFy.dll [2009-01-05 00:45]
.
- - - - ORPHANS REMOVED - - - -

BHO-{155DDBE3-4BCA-4D03-A337-A5CADF31D1AA} - (no file)
BHO-{2FDFDB58-D7BE-44AF-9C8D-92247D172F0B} - (no file)
BHO-{5332CF2D-B814-58F2-55BC-4E872765CC76} - c:\windows\system32\mttcegkpuejac.dll
BHO-{77c96e76-97d7-4ab3-9ff1-1f592b002bd9} - c:\windows\system32\erdqwk.dll
BHO-{85B09DAA-13A1-4E5F-9B61-E7DBAD115373} - c:\windows\system32\jkkKecaB.dll
BHO-{a93362db-35dc-4629-b61b-be0b320a6791} - (no file)
BHO-{DBF8D289-D7FD-46AE-92FB-88362B3F16E6} - (no file)
HKCU-Run-VnrPack22 - c:\program files\VnrPack\VnrPack22.exe
HKCU-Run-GetPack30 - c:\program files\GetPack\GetPack30.exe
Notify-fccyvSJA - fccyvSJA.dll
Notify-WgaLogon - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/webhp
uInternet Settings,ProxyServer = servidor:80
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Trusted Zone: bwaypartners.com\mail
FF - ProfilePath - c:\documents and settings\me\Application Data\Mozilla\Firefox\Profiles\ipvjcdkg.default\
FF - component: c:\program files\Mozilla Firefox\components\srff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 16:48:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\c:\windows\TEMP\13.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
c:\program files\Maxtor\OneTouch\Utils\SyncServices.exe
c:\program files\Sony\HotKey Utility\HKWnd.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-02-16 16:55:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-16 21:55:17

Pre-Run: 2,068,529,152 bytes free
Post-Run: 2,089,091,072 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

317 --- E O F --- 2009-02-16 21:54:19

[B]Edit
09-01-31 http://forums.spybot.info/showthread.php?t=45113

Blade81
2009-02-19, 17:53
Hi,

Please post a fresh hjt log too :)

Blade81
2009-02-24, 19:25
Due to inactivity, this thread will now be closed.

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.