PDA

View Full Version : virtumonde infection



noladave
2010-07-10, 08:07
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 10/14/2005 7:18:25 PM
System Uptime: 7/10/2010 12:14:21 AM (0 hours ago)

Motherboard: Dell Inc. | | 0X8582
Processor: Intel(R) Pentium(R) D CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 146 GiB total, 19.778 GiB free.
D: is FIXED (NTFS) - 1397 GiB total, 872.249 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (FAT32) - 931 GiB total, 274.064 GiB free.
K: is Removable
L: is FIXED (FAT32) - 466 GiB total, 28.536 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1737: 4/10/2010 8:12:18 AM - System Checkpoint
RP1738: 4/11/2010 11:56:34 AM - System Checkpoint
RP1739: 4/12/2010 12:13:05 PM - System Checkpoint
RP1740: 4/13/2010 2:19:41 AM - Software Distribution Service 3.0
RP1741: 4/14/2010 7:01:33 AM - System Checkpoint
RP1742: 4/15/2010 7:24:31 AM - System Checkpoint
RP1743: 4/16/2010 2:19:15 AM - Software Distribution Service 3.0
RP1744: 4/17/2010 7:39:18 AM - System Checkpoint
RP1745: 4/18/2010 9:43:21 AM - System Checkpoint
RP1746: 4/19/2010 4:47:04 PM - System Checkpoint
RP1747: 4/20/2010 2:19:49 AM - Software Distribution Service 3.0
RP1748: 4/20/2010 5:14:27 PM - Software Distribution Service 3.0
RP1749: 4/21/2010 7:43:24 PM - System Checkpoint
RP1750: 4/22/2010 10:31:25 PM - System Checkpoint
RP1751: 4/23/2010 2:14:14 AM - Software Distribution Service 3.0
RP1752: 4/24/2010 11:09:41 AM - System Checkpoint
RP1753: 4/25/2010 5:27:17 PM - System Checkpoint
RP1754: 4/26/2010 4:24:12 PM - Software Distribution Service 3.0
RP1755: 4/27/2010 6:57:05 PM - System Checkpoint
RP1756: 4/28/2010 7:30:48 PM - System Checkpoint
RP1757: 4/29/2010 10:56:50 PM - System Checkpoint
RP1758: 4/30/2010 2:14:15 AM - Software Distribution Service 3.0
RP1759: 5/1/2010 9:35:56 AM - System Checkpoint
RP1760: 5/2/2010 10:52:48 AM - System Checkpoint
RP1761: 5/3/2010 5:50:04 PM - System Checkpoint
RP1762: 5/3/2010 9:03:35 PM - Software Distribution Service 3.0
RP1763: 5/4/2010 11:36:29 PM - System Checkpoint
RP1764: 5/6/2010 6:38:39 AM - System Checkpoint
RP1765: 5/7/2010 2:14:10 AM - Software Distribution Service 3.0
RP1766: 5/8/2010 8:12:33 AM - System Checkpoint
RP1767: 5/9/2010 11:27:32 AM - System Checkpoint
RP1768: 5/10/2010 9:36:22 PM - System Checkpoint
RP1769: 5/11/2010 2:14:15 AM - Software Distribution Service 3.0
RP1770: 5/12/2010 7:51:12 AM - System Checkpoint
RP1771: 5/12/2010 5:16:16 PM - Installed DirectX
RP1772: 5/12/2010 5:19:38 PM - Installed DirectX
RP1773: 5/12/2010 8:01:13 PM - Software Distribution Service 3.0
RP1774: 5/13/2010 4:35:55 PM - Software Distribution Service 3.0
RP1775: 5/14/2010 5:54:36 PM - System Checkpoint
RP1776: 5/15/2010 6:14:54 PM - System Checkpoint
RP1777: 5/16/2010 9:26:29 PM - System Checkpoint
RP1778: 5/17/2010 4:48:48 PM - Software Distribution Service 3.0
RP1779: 5/18/2010 5:35:17 PM - System Checkpoint
RP1780: 5/19/2010 6:54:17 PM - System Checkpoint
RP1781: 5/21/2010 2:14:15 AM - Software Distribution Service 3.0
RP1782: 5/22/2010 3:58:10 AM - System Checkpoint
RP1783: 5/23/2010 8:58:28 AM - System Checkpoint
RP1784: 5/24/2010 11:44:45 AM - System Checkpoint
RP1785: 5/25/2010 2:14:15 AM - Software Distribution Service 3.0
RP1786: 5/26/2010 7:50:22 AM - System Checkpoint
RP1787: 5/27/2010 8:13:42 AM - System Checkpoint
RP1788: 5/28/2010 2:14:08 AM - Software Distribution Service 3.0
RP1789: 5/28/2010 10:56:09 PM - Software Distribution Service 3.0
RP1790: 5/30/2010 12:15:52 AM - System Checkpoint
RP1791: 5/31/2010 9:18:35 AM - System Checkpoint
RP1792: 5/31/2010 2:37:52 PM - Software Distribution Service 3.0
RP1793: 6/1/2010 5:18:02 PM - System Checkpoint
RP1794: 6/2/2010 7:16:02 PM - System Checkpoint
RP1795: 6/3/2010 7:36:54 PM - System Checkpoint
RP1796: 6/4/2010 2:14:15 AM - Software Distribution Service 3.0
RP1797: 6/5/2010 9:11:09 AM - System Checkpoint
RP1798: 6/6/2010 11:38:57 AM - System Checkpoint
RP1799: 6/7/2010 2:56:36 PM - System Checkpoint
RP1800: 6/7/2010 11:10:57 PM - Software Distribution Service 3.0
RP1801: 6/9/2010 7:54:30 AM - System Checkpoint
RP1802: 6/10/2010 9:50:27 AM - System Checkpoint
RP1803: 6/10/2010 8:26:42 PM - Software Distribution Service 3.0
RP1804: 6/11/2010 2:14:30 AM - Software Distribution Service 3.0
RP1805: 6/12/2010 11:22:26 AM - System Checkpoint
RP1806: 6/12/2010 2:26:35 PM - Installed DirectX
RP1807: 6/13/2010 6:45:53 PM - System Checkpoint
RP1808: 6/14/2010 7:47:15 PM - System Checkpoint
RP1809: 6/15/2010 2:12:39 AM - Software Distribution Service 3.0
RP1810: 6/16/2010 8:49:48 AM - System Checkpoint
RP1811: 6/17/2010 8:56:06 AM - System Checkpoint
RP1812: 6/17/2010 6:00:54 PM - Software Distribution Service 3.0
RP1813: 6/18/2010 8:57:53 PM - System Checkpoint
RP1814: 6/19/2010 8:58:27 PM - System Checkpoint
RP1815: 6/21/2010 9:42:37 AM - System Checkpoint
RP1816: 6/22/2010 1:59:15 AM - Software Distribution Service 3.0
RP1817: 6/22/2010 11:17:37 PM - Software Distribution Service 3.0
RP1818: 6/27/2010 9:33:40 PM - Software Distribution Service 3.0
RP1819: 6/28/2010 9:35:39 PM - Software Distribution Service 3.0
RP1820: 6/30/2010 10:15:33 AM - System Checkpoint
RP1821: 7/1/2010 5:23:13 PM - System Checkpoint
RP1822: 7/2/2010 2:25:14 AM - Software Distribution Service 3.0
RP1823: 7/3/2010 7:37:34 AM - System Checkpoint
RP1824: 7/7/2010 11:22:39 PM - System Checkpoint

==== Installed Programs ======================

7-Zip 4.65
Ad-Aware
Ad-Aware Email Scanner for Outlook
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 2.1
Adobe Photoshop Elements 5.0
Adobe Photoshop Elements 7.0
Adobe Photoshop.com Inspiration Browser
Adobe Reader 7.0.9
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
AutoUpdate
Bibble Lite
Bibble 5
Bonjour
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities Digital Photo Professional 3.2
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities Original Data Security Tools
Canon Utilities PhotoStitch
Canon Utilities Picture Style Editor
Canon Utilities RemoteCapture DC
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities WFT-E1/E2/E3 Utility
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Check Point SSL Network Extender
Citrix Presentation Server Client
Color LaserJet 2600n
Creative Audio Console
Data Lifeguard Tools
Dell Driver Reset Tool
Dell Support 3.2.1
Dell Support Center (Support Software)
Dell System Restore
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
ERUNT 1.1j
Facebook Plug-In
Family Tree Creator Deluxe
FastStone Image Viewer 3.5
FPT Web Template
Free Mp3 Wma Converter V 1.81
Free Video to iPod Converter version 3.1
Free Video to Mp3 Converter version 3.1
Free YouTube to Mp3 Converter version 3.1
Google Earth
Google Update Helper
Google Updater
GoToMeeting 4.0.0.320
H&R Block Deluxe + Efile + State 2009
H&R Block Louisiana 2009
HDView for Internet Explorer
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel Matrix Storage Manager
Intel(R) PRO Network Connections Software v9.2.4.11
Intel(R) PROSafe for Wired Connections
Internet Explorer Default Page
iPhone Configuration Utility
iPhone Configuration Web Utility
iTunes
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_03
Java 2 Runtime Environment, SE v1.4.2_11
Java(TM) 6 Update 3
Learn2 Player (Uninstall Only)
Linksys EasyLink Advisor
Macromedia Flash Player
Malwarebytes' Anti-Malware
McAfee AntiVirus Plus
Memorex exPressit Label Design Studio
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Suite 2006
Microsoft Digital Image Suite 2006 Editor
Microsoft Digital Image Suite 2006 Library
Microsoft FrontPage 2002
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MobileMe Control Panel
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.5.9)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
MyWay Search Assistant
Neat Image v5.85 Pro
NetWorker Management Console
NetWorker Management Console on lsuhsc-oak.master.lsuhsc.edu
NetWorker Procedure Generator
Noise Ninja 2 (Standalone Version)
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
Photo Mechanic
PhotoshopdotcomInspirationBrowser
PowerDVD 5.5
Pro Studio Manager ver.3.5
Professional Notepad
Pure Networks Platform
Qualxserve Service Agreement
QuickBooks Simple Start Special Edition
QuickTime
RealPlayer
SAMSUNG Mobile Modem Driver Set
Seagate*DiscWizard
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sound Blaster Audigy
Sprint SmartView
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
TaxCut Deluxe 2005
TaxCut Louisiana 2007
TaxCut Louisiana 2008
TaxCut Premium + State + Efile 2008
TaxCut Premium + State 2007
TaxCut Premium 2006
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WD Diagnostics
WebCyberCoach 3.2 Dell
WebEx
WebEx Support Manager for Internet Explorer
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB894476
Windows Mobile® Device Handbook
Windows Vista Upgrade Advisor
Windows XP Service Pack 3
WordPerfect Office 12
XviD MPEG-4 Video Codec

==== Event Viewer Messages From Past Week ========

7/6/2010 7:49:28 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
7/6/2010 5:38:27 PM, error: Service Control Manager [7022] - The Pure Networks Platform Service service hung on starting.
7/4/2010 10:54:07 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
7/3/2010 7:09:00 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
7/3/2010 7:09:00 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL. Reference error message: The operation completed successfully. .
7/3/2010 7:09:00 AM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.
7/3/2010 7:05:37 AM, error: Service Control Manager [7023] - The Seagate Scheduler2 Service service terminated with the following error: The endpoint is a duplicate.
7/10/2010 12:45:40 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
7/10/2010 12:17:29 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
7/10/2010 12:16:22 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm
7/10/2010 12:16:04 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

==== End Of File ===========================

Edit:

If someone posts such advice to others in their own topic as in, "this worked for me", it will be removed, possibly without notice. Just so you know.
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Please do NOT run 'FIXES' (ComboFix etc) without being asked (http://forums.spybot.info/showthread.php?t=16806)

noladave
2010-07-11, 16:03
no problem. I just wanted to post that the problem was fixed, so that someone didn't wast their time, and start working on it.