Results 1 to 7 of 7

Thread: Virtumonde on Friends PC

  1. #1
    Junior Member
    Join Date
    May 2008
    Location
    San Diego, CA
    Posts
    3

    Question Virtumonde on Friends PC

    I am assisting someone in cleaning up their PC and found Virtumonde on it. After unsuccessfully not able to remove it I found your website and need assistance in removing it. I took it offline and am working from my home pc to fix it.
    I was able to load HJTInstall, but not Kaspersky since it is not online.
    Here is the hjt message from that pc:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:33:00 PM, on 5/22/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
    C:\Program Files\Common Files\AOL\1153376147\ee\AOLSoftware.exe
    C:\Program Files\ArcadeRockstar\arcaderockstar32.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCMTR.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\AGRSMMSG.exe
    c:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
    R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1153376147\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [arcaderockstar] C:\Program Files\ArcadeRockstar\arcaderockstar32.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.275.0\OEAddOn.exe
    O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.275.0\SeekmoSA.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [003a1eb5] rundll32.exe "C:\WINDOWS\system32\kxxughex.dll",b
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [BM03092d29] Rundll32.exe "C:\WINDOWS\system32\iacqdcva.dll",s
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKCU\..\Run: [A00F16FA708A.exe] C:\DOCUME~1\ILOVEJ~1.001\LOCALS~1\Temp\_A00F16FA708A.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-21-4047644330-203043146-785693424-1019\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\i love joe.DEBNKIDZ.001\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/down.../OTOYAX29b.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...70/mcfscan.cab
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 11655 bytes

  2. #2
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Hello

    Please download ATF Cleaner by Atribune.
    This program is for XP and Windows 2000 only
    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.




    Please visit this web page for instructions for downloading and running ComboFix

    http://www.bleepingcomputer.com/comb...o-use-combofix

    This includes installing the Windows XP Recovery Console in case you have not installed it yet.

    For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

    Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

    Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.





    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner and click Accept

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
      • Extended (if available otherwise Standard)
      • Scan Options:
      • Scan Archives
        Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
      • Select My Computer
    • This will program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  3. #3
    Junior Member
    Join Date
    May 2008
    Location
    San Diego, CA
    Posts
    3

    Cool Ran both programs ATF Cleaner & ComboFix

    What to do next??

    ComboFix log file:

    ComboFix 08-05-25.5 - i love joe 2008-05-26 10:18:55.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.134 [GMT -7:00]
    Running from: C:\Documents and Settings\i love joe.DEBNKIDZ.001\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\All Users\Application Data\SeekmoSA
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\Config.xml
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\db\Aliases.dbs
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\db\Sites.dbs
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\report\aggr_storage.xml
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\report\send_storage.xml
    C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
    C:\Program Files\AntiSpywareMaster
    C:\Program Files\License_Manager
    C:\Program Files\popcorn Terms.html
    C:\Program Files\ShoppingReport
    C:\Program Files\ShoppingReport\Uninst.exe
    C:\WINDOWS\BM03092d29.xml
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\__c00273E2.dat
    C:\WINDOWS\system32\__c00EBFCC.dat
    C:\WINDOWS\system32\AdggiRqr.ini
    C:\WINDOWS\system32\AdggiRqr.ini2
    C:\WINDOWS\system32\chbyfmki.exe
    C:\WINDOWS\system32\covvfftw.exe
    C:\WINDOWS\system32\dldfcjbi.ini
    C:\WINDOWS\system32\GfLVCccf.ini
    C:\WINDOWS\system32\GfLVCccf.ini2
    C:\WINDOWS\system32\gkqtwxvp.ini
    C:\WINDOWS\system32\gypchwij.ini
    C:\WINDOWS\system32\ilUFPXyb.ini
    C:\WINDOWS\system32\ilUFPXyb.ini2
    C:\WINDOWS\system32\jyycdhub.ini
    C:\WINDOWS\system32\kgwxywuw.ini
    C:\WINDOWS\system32\kxxughex.dll
    C:\WINDOWS\system32\lqlktyjf.dll
    C:\WINDOWS\system32\lvcycxnx.dll
    C:\WINDOWS\system32\lvqnpjfr.dll
    C:\WINDOWS\system32\lwbremti.ini
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mlJCRhFy.dll
    C:\WINDOWS\system32\mloXEfhk.ini
    C:\WINDOWS\system32\mloXEfhk.ini2
    C:\WINDOWS\system32\myqhtsvp.exe
    C:\WINDOWS\system32\nbrmbpcw.ini
    C:\WINDOWS\system32\ncwvwnkf.exe
    C:\WINDOWS\system32\nitgxwyk.dll
    C:\WINDOWS\system32\nmntpkal.dll
    C:\WINDOWS\system32\nrxgbbeb.exe
    C:\WINDOWS\system32\opnlLCVo.dll
    C:\WINDOWS\system32\otkecqwd.ini
    C:\WINDOWS\system32\oVCLlnpo.ini
    C:\WINDOWS\system32\oVCLlnpo.ini2
    C:\WINDOWS\system32\oxjiroql.ini
    C:\WINDOWS\system32\pmnlkLDu.dll
    C:\WINDOWS\system32\pvxwtqkg.dll
    C:\WINDOWS\system32\qmfnsjjy.exe
    C:\WINDOWS\system32\rayitbig.dll
    C:\WINDOWS\system32\rqRiggdA.dll
    C:\WINDOWS\system32\rravstfq.dll
    C:\WINDOWS\system32\rvcofpci.ini
    C:\WINDOWS\system32\suCbdccf.ini
    C:\WINDOWS\system32\suCbdccf.ini2
    C:\WINDOWS\system32\thuwflwn.ini
    C:\WINDOWS\system32\uDLklnmp.ini
    C:\WINDOWS\system32\uDLklnmp.ini2
    C:\WINDOWS\system32\UFghPXbc.ini
    C:\WINDOWS\system32\UFghPXbc.ini2
    C:\WINDOWS\system32\ugdmhiwo.dll
    C:\WINDOWS\system32\ukhkwuvk.dll
    C:\WINDOWS\system32\unjrukxj.ini
    C:\WINDOWS\system32\uupesxmt.dll
    C:\WINDOWS\system32\wpkpqlaq.dll
    C:\WINDOWS\system32\xehguxxk.ini
    C:\WINDOWS\system32\xfdouadh.ini
    C:\WINDOWS\system32\xgjpkbmi.dll
    C:\WINDOWS\system32\xhpaahvs.dll
    C:\WINDOWS\system32\xtamdiid.dll
    C:\WINDOWS\system32\Xybddfii.ini
    C:\WINDOWS\system32\Xybddfii.ini2
    C:\WINDOWS\system32\yayaYomL.dll
    C:\WINDOWS\system32\ybtnghnn.dll
    C:\WINDOWS\system32\ydxmrwrp.dll
    C:\WINDOWS\system32\ymdwnyrf.dll
    C:\xcrashdump.dat
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
    .

    2008-05-21 20:36 . 2008-05-21 20:36 <DIR> d-------- C:\Program Files\Alwil Software
    2008-05-21 20:10 . 2008-05-21 20:11 <DIR> d-------- C:\Temp\Officescan
    2008-05-21 20:05 . 2008-05-21 20:14 <DIR> d-------- C:\Temp\ClnExtor
    2008-05-21 17:54 . 2008-05-21 20:20 2,490 --a------ C:\WINDOWS\status.MIF
    2008-05-21 17:52 . 2008-05-21 20:11 <DIR> d-------- C:\Temp
    2008-05-21 17:52 . 2008-05-22 20:32 <DIR> d-------- C:\Program Files\Trend Micro
    2008-05-20 18:42 . 2008-05-20 18:42 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-05-20 18:42 . 2008-05-21 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-05-20 18:40 . 2008-05-22 18:39 443 --a------ C:\WINDOWS\wininit.ini
    2008-05-18 21:44 . 2008-05-20 15:21 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\LimeWire
    2008-05-18 21:40 . 2008-05-18 21:40 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\HP
    2008-05-18 21:39 . 2008-05-18 21:41 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\Yahoo!
    2008-05-18 21:37 . 2008-05-18 21:37 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\AOL
    2008-05-18 21:36 . 2005-05-26 10:20 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\WINDOWS
    2008-05-18 21:36 . 2005-05-26 10:20 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\Symantec
    2008-05-18 21:36 . 2005-05-26 10:20 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\SampleView
    2008-05-18 21:36 . 2005-05-26 10:20 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\InterMute
    2008-05-18 21:36 . 2005-05-26 10:20 <DIR> d-------- C:\Documents and Settings\N!!CKKZ\Application Data\Apple Computer
    2008-05-18 21:36 . 2008-05-20 19:17 <DIR> d-------- C:\Documents and Settings\N!!CKKZ
    2008-05-16 22:40 . 2008-05-17 01:01 1,666 --ahs---- C:\WINDOWS\system32\llwqtxha.ini
    2008-05-15 17:10 . 2008-05-16 22:29 1,486 --ahs---- C:\WINDOWS\system32\wovhfdky.ini
    2008-05-15 16:51 . 2008-05-15 17:00 1,074 --ahs---- C:\WINDOWS\system32\qjgyijam.ini
    2008-04-30 04:14 . 2008-04-30 04:14 <DIR> d-------- C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\Printer Info Cache
    2008-04-30 04:14 . 2008-04-30 04:14 <DIR> d-------- C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\Image Zone Express

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-22 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
    2008-05-22 01:03 --------- d-----w C:\Program Files\Google
    2008-05-22 00:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
    2008-05-19 23:15 --------- d-----w C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\LimeWire
    2008-05-19 04:44 --------- d-----w C:\Program Files\LimeWire
    2008-05-15 03:23 --------- d-----w C:\Program Files\Virtual Laguna Beach
    2008-05-15 03:20 --------- d-----w C:\Program Files\VirtualDJ
    2008-05-15 03:20 --------- d-----w C:\Program Files\SpacialAudio
    2008-05-15 03:19 --------- d-----w C:\Program Files\Yahoo! Games
    2008-05-02 22:30 --------- d-----w C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\IMVU
    2008-04-26 05:10 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-04-25 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
    2008-04-18 04:35 60,928 ----a-w C:\Documents and Settings\i love joe\i2.exe
    2007-05-08 04:27 158 ----a-w C:\Documents and Settings\i love joe.DEBNKIDZ.001\Application Data\wklnhst.dat
    2007-02-14 04:42 32 ----a-r C:\Documents and Settings\All Users\hash.dat
    2006-12-18 00:55 338 ----a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F282739-9F9B-4A10-8263-B6A97E5190F8}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{386a2525-0c76-440e-a393-64ff133424a1}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL" [2007-10-09 20:41 267592]

    [HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:00 15360]
    "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-23 03:31 126976]
    "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 15:34 245760]
    "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 06:54 253952]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-05-26 09:29 180269]
    "EPSON Stylus CX6600 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.exe" [ ]
    "AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2005-04-18 11:38 71256]
    "AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2005-04-11 10:36 83544]
    "HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 04:42 659456]
    "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
    "ISUSScheduler"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-07-27 16:50 81920]
    "Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-03 21:00 143360]
    "HostManager"="C:\Program Files\Common Files\AOL\1153376147\ee\AOLSoftware.exe" [2006-03-08 11:38 48280]
    "IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-03-27 08:57 126104]
    "arcaderockstar"="C:\Program Files\ArcadeRockstar\arcaderockstar32.exe" [2007-04-03 07:54 51200]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
    "AutoTBar"="c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE" [ ]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-15 00:43 286720]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 14:11 267048]
    "BM03092d29"="C:\WINDOWS\system32\iacqdcva.dll" [ ]

    C:\Documents and Settings\N!!CKKZ\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-04-18 12:21:09 147456]

    C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-04-18 12:21:09 147456]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
    America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-08-20 08:50:41 156784]
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
    Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 04:33:46 282624]
    Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-05-26 09:42:48 45056]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ied500]
    ied500.dll 2006-12-06 21:41 0 C:\WINDOWS\system32\ied500.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0048D50]
    C:\WINDOWS\system32\__c0048D50.dat

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "C:\\Program Files\\America Online 9.0\\waol.exe"=
    "C:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "C:\\Program Files\\Common Files\\AOL\\1153376147\\ee\\aolsoftware.exe"=
    "C:\\StubInstaller.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
    "C:\\Program Files\\AIM\\aim.exe"=
    "C:\\Program Files\\FrostWire\\FrostWire.exe"=
    "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "C:\\Documents and Settings\\i love joe.DEBNKIDZ.001\\Application Data\\PowerChallenge\\PowerFootball\\PowerFootball.exe"=
    "C:\\Documents and Settings\\i love joe.DEBNKIDZ.001\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 16:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 16:16]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-05-26 16:54:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-05-08 02:41:00 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
    - C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.4.20.2.sxt _RegistrationOffer@16
    "2008-05-23 01:48:42 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
    - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-26 10:38:36
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\ArcadeRockstar\wshlib.dll
    -> C:\Program Files\ArcadeRockstar\shcfglib.dll
    -> C:\Program Files\ArcadeRockstar\hlplib.dll
    -> C:\Program Files\ArcadeRockstar\poplib.dll
    -> C:\Program Files\ArcadeRockstar\clutil.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    .
    **************************************************************************
    .
    Completion time: 2008-05-26 10:44:32 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-05-26 17:44:22

    Pre-Run: 122,392,051,712 bytes free
    Post-Run: 122,716,569,600 bytes free

    274 --- E O F --- 2008-04-09 10:04:32

  4. #4
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Post the Kaspersky log
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  5. #5
    Junior Member
    Join Date
    May 2008
    Location
    San Diego, CA
    Posts
    3

    Default Kaspersky not available on PC

    I have the users pc at my home that hasn't a regular phone modem connection so I can't do the online Kaspersky scan. If necessary I will take the pc to the users house and hook it up to the internet.

    Can you advise what to do on this matter?

  6. #6
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Lets leave Kaspersky then

    1. Close any open browsers.

    2. Open notepad and copy/paste the text in the quotebox below into it:

    File::
    C:\WINDOWS\system32\llwqtxha.ini
    C:\WINDOWS\system32\wovhfdky.ini
    C:\WINDOWS\system32\qjgyijam.ini
    C:\Documents and Settings\i love joe\i2.exe

    Folder::

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ied500]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0048D50]

    Driver::
    Save this as CFScript.txt, in the same location as ComboFix.exe




    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at "C:\ComboFix.txt"

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall




    Also post a new HijackThis log
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  7. #7
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Due to inactivity, this thread will now be closed.

    Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

    If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •