ravelink69
New member
I was using the following thread in the archives :http://forums.spybot.info/archive/index.php/t-23765.html but i got different results when running the scans. ComboFix.exe did not delete the file. here is my combofix log and hijack this log.
ComboFix 08-07-17.4 - robh 2008-07-18 11:27:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.438 [GMT -5:00]
Running from: C:\Documents and Settings\robh\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\robh\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-18 11:31 . 2008-07-18 11:31 <DIR> d-------- C:\Temp\tn3
2008-07-18 09:19 . 2008-07-18 09:19 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-07-17 14:56 . 2008-07-18 11:32 932 --------- C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
2008-07-07 10:11 . 2008-04-14 05:42 1,306,624 --------- C:\WINDOWS\SYSTEM32\msxml6.dll
2008-07-07 10:11 . 2008-04-14 05:42 1,306,624 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msxml6.dll
2008-07-07 10:11 . 2008-04-14 05:41 233,472 --------- C:\WINDOWS\SYSTEM32\azroles.dll
2008-07-07 10:11 . 2008-04-14 05:41 136,192 --------- C:\WINDOWS\SYSTEM32\aaclient.dll
2008-07-07 10:11 . 2008-04-13 22:57 79,872 --------- C:\WINDOWS\SYSTEM32\msxml6r.dll
2008-07-07 10:11 . 2008-04-13 22:57 79,872 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msxml6r.dll
2008-07-07 10:11 . 2008-04-14 05:42 10,752 --------- C:\WINDOWS\SYSTEM32\smtpapi.dll
2008-07-07 10:11 . 2008-04-14 05:42 9,728 --------- C:\WINDOWS\SYSTEM32\rwnh.dll
2008-07-07 09:59 . 2008-04-13 22:06 144,384 --------- C:\WINDOWS\SYSTEM32\DRIVERS\hdaudbus.sys
2008-07-07 09:59 . 2008-04-14 00:10 10,240 --------- C:\WINDOWS\SYSTEM32\DRIVERS\sffp_mmc.sys
2008-07-07 09:56 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\003552_.tmp
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\bits
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\l2schemas
2008-07-02 17:34 . 2008-04-14 05:42 539,136 --a------ C:\WINDOWS\SYSTEM32\SET10E6.tmp
2008-07-02 17:34 . 2008-04-14 05:42 354,304 --a------ C:\WINDOWS\SYSTEM32\SET10B5.tmp
2008-07-02 17:34 . 2008-04-14 05:40 177,152 --a------ C:\WINDOWS\SYSTEM32\SET10E8.tmp
2008-07-02 17:34 . 2008-04-14 05:42 80,896 --a------ C:\WINDOWS\SYSTEM32\SET10B0.tmp
2008-07-02 17:34 . 2008-04-14 05:42 6,656 --a------ C:\WINDOWS\SYSTEM32\SET10AD.tmp
2008-07-02 17:27 . 2008-04-14 05:42 471,552 --a------ C:\WINDOWS\SYSTEM32\SET69B.tmp
2008-07-02 17:27 . 2008-04-14 05:41 95,744 --a------ C:\WINDOWS\SYSTEM32\SET6A1.tmp
2008-07-02 17:25 . 2008-04-14 05:41 1,267,200 --a------ C:\WINDOWS\SYSTEM32\SET4C1.tmp
2008-07-02 17:24 . 2008-04-14 05:41 1,082,368 --a------ C:\WINDOWS\SYSTEM32\SET451.tmp
2008-07-02 17:23 . 2008-04-14 05:42 3,066,880 --a------ C:\WINDOWS\SYSTEM32\SET399.tmp
2008-07-02 17:22 . 2008-04-14 05:42 1,703,936 --a------ C:\WINDOWS\SYSTEM32\SET352.tmp
2008-07-02 17:21 . 2008-04-14 05:42 8,461,312 --a------ C:\WINDOWS\SYSTEM32\SET2B7.tmp
2008-07-02 17:20 . 2008-04-14 05:42 727,040 --a------ C:\WINDOWS\SYSTEM32\SET259.tmp
2008-07-02 17:19 . 2008-04-14 05:42 666,112 --a------ C:\WINDOWS\SYSTEM32\SET23C.tmp
2008-07-02 17:10 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\005753_.tmp
2008-07-02 17:05 . 2008-04-14 05:42 409,088 --a------ C:\WINDOWS\SYSTEM32\qmgr.dll
2008-07-02 17:03 . 2008-04-14 00:57 2,188,928 --a------ C:\WINDOWS\SYSTEM32\ntoskrnl.exe
2008-06-25 14:08 . 2008-07-15 22:39 <DIR> d-------- C:\SmitfraudFix
2008-06-25 00:19 . 2008-06-25 00:20 1,445,888 --a------ C:\WinsockxpFix.exe
2008-06-25 00:11 . 2008-06-25 14:42 <DIR> d-------- C:\backups
2008-06-24 18:04 . 2008-06-24 18:04 251,392 --a------ C:\hijackthis_sfx.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 19:07 --------- d-----w C:\Documents and Settings\robh\Application Data\U3
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-13 15:00 691,545 ----a-w C:\WINDOWS\unins000.exe
2007-12-27 20:53 285,396 ----a-w C:\Program Files\50calrev.gif
2006-05-01 15:42 563,712 ----a-w C:\Documents and Settings\Administrator\370_gotomypc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinVNC"="C:\Program Files\UltraVNC\WinVNC.exe" [2005-08-06 19:45 974848]
C:\Documents and Settings\fasclampitt 2\Start Menu\Programs\Startup\
DESKTOP(2).INI [2002-09-03 14:36:04 84]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Firewall Client Management.lnk - C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe [2006-12-09 20:04:10 117568]
UPS WorldShip Messaging Utility.lnk - C:\UPS\WSTD\WSTDMessaging.exe [2007-12-13 16:55:54 65536]
UPS WorldShip PLD Reminder Utility.lnk - C:\UPS\WSTD\wstdPldReminder.exe [2007-12-12 22:05:04 31744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DESKTOP(2).INI]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP(2).INI
backup=C:\WINDOWS\pss\DESKTOP(2).INICommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-05-16 14:57 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iGateway"=2 (0x2)
"IDriverT"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="C:\Program Files\Microsoft Games\DAEMON Tools Lite\daemon.exe"
"Sonic RecordNow!"=
"WebSUpdater"="C:\Program Files\winvi\wupda.exe" /background
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" -lang 1033
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"BCMSMMSG"=BCMSMMSG.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"Realtime Monitor"="C:\Program Files\CA\eTrustITM\realmon.exe" -s
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe"
"runner1"=C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\UltraVNC\\winvnc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\CA\\eTrustITM\\InoRpc.exe"=
"C:\\Program Files\\CA\\eTrustITM\\Realmon.exe"=
"C:\\Program Files\\CA\\eTrustITM\\Shellscn.exe"=
"C:\\Program Files\\CA\\SharedComponents\\iTechnology\\igateway.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP
xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 netbtt;netbtt;C:\WINDOWS\system32\drivers\netbtt.sys [2008-05-08 14:50]
R2 Alert Notification Server;Alert Notification Server;C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE [2004-04-19 11:05]
R2 FwcAgent;Firewall Client Agent;C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe [2006-12-09 20:04]
S4 Win32Sr;Win32Sr;C:\WINDOWS\win32ssr.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b448d2a8-3956-11dd-ad26-000d56599d48}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-18 16:35:52 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 11:33:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\CA\eTrustITM\InoRpc.exe
C:\Program Files\CA\eTrustITM\InoRT.exe
C:\Program Files\CA\eTrustITM\InoTask.exe
C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\CA\eTrustITM\Ppcl.exe
C:\Program Files\CA\eTrustITM\Ppcl.exe
.
**************************************************************************
.
Completion time: 2008-07-18 11:41:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 16:41:46
ComboFix2.txt 2008-07-18 16:10:12
Pre-Run: 60,074,033,152 bytes free
Post-Run: 60,055,728,128 bytes free
163
----------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:46, on 2008-07-18
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
C:\Program Files\CA\eTrustITM\InoRpc.exe
C:\Program Files\CA\eTrustITM\InoRT.exe
C:\Program Files\CA\eTrustITM\InoTask.exe
C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\CA\eTrustITM\ppcl.exe
C:\Program Files\CA\eTrustITM\ppcl.exe
C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe
C:\UPS\WSTD\WSTDMessaging.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://cpcvpn:8080/array.dll?Get.Routing.Script
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cpcvpn:8080
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - Global Startup: Microsoft Firewall Client Management.lnk = C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1215604273551
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1215604189783
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Alert Notification Server - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
O23 - Service: eTrust ITM RPC Service (InoRPC) - CA - C:\Program Files\CA\eTrustITM\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Service (InoRT) - CA - C:\Program Files\CA\eTrustITM\InoRT.exe
O23 - Service: eTrust ITM Job Service (InoTask) - CA - C:\Program Files\CA\eTrustITM\InoTask.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
is this problem the same as Virtumonde?
---------------------------------------------------
Edit:
ComboFix 08-07-17.4 - robh 2008-07-18 11:27:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.438 [GMT -5:00]
Running from: C:\Documents and Settings\robh\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\robh\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-18 11:31 . 2008-07-18 11:31 <DIR> d-------- C:\Temp\tn3
2008-07-18 09:19 . 2008-07-18 09:19 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-07-17 14:56 . 2008-07-18 11:32 932 --------- C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
2008-07-07 10:11 . 2008-04-14 05:42 1,306,624 --------- C:\WINDOWS\SYSTEM32\msxml6.dll
2008-07-07 10:11 . 2008-04-14 05:42 1,306,624 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msxml6.dll
2008-07-07 10:11 . 2008-04-14 05:41 233,472 --------- C:\WINDOWS\SYSTEM32\azroles.dll
2008-07-07 10:11 . 2008-04-14 05:41 136,192 --------- C:\WINDOWS\SYSTEM32\aaclient.dll
2008-07-07 10:11 . 2008-04-13 22:57 79,872 --------- C:\WINDOWS\SYSTEM32\msxml6r.dll
2008-07-07 10:11 . 2008-04-13 22:57 79,872 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msxml6r.dll
2008-07-07 10:11 . 2008-04-14 05:42 10,752 --------- C:\WINDOWS\SYSTEM32\smtpapi.dll
2008-07-07 10:11 . 2008-04-14 05:42 9,728 --------- C:\WINDOWS\SYSTEM32\rwnh.dll
2008-07-07 09:59 . 2008-04-13 22:06 144,384 --------- C:\WINDOWS\SYSTEM32\DRIVERS\hdaudbus.sys
2008-07-07 09:59 . 2008-04-14 00:10 10,240 --------- C:\WINDOWS\SYSTEM32\DRIVERS\sffp_mmc.sys
2008-07-07 09:56 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\003552_.tmp
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\SYSTEM32\bits
2008-07-02 17:34 . 2008-07-07 10:10 <DIR> d-------- C:\WINDOWS\l2schemas
2008-07-02 17:34 . 2008-04-14 05:42 539,136 --a------ C:\WINDOWS\SYSTEM32\SET10E6.tmp
2008-07-02 17:34 . 2008-04-14 05:42 354,304 --a------ C:\WINDOWS\SYSTEM32\SET10B5.tmp
2008-07-02 17:34 . 2008-04-14 05:40 177,152 --a------ C:\WINDOWS\SYSTEM32\SET10E8.tmp
2008-07-02 17:34 . 2008-04-14 05:42 80,896 --a------ C:\WINDOWS\SYSTEM32\SET10B0.tmp
2008-07-02 17:34 . 2008-04-14 05:42 6,656 --a------ C:\WINDOWS\SYSTEM32\SET10AD.tmp
2008-07-02 17:27 . 2008-04-14 05:42 471,552 --a------ C:\WINDOWS\SYSTEM32\SET69B.tmp
2008-07-02 17:27 . 2008-04-14 05:41 95,744 --a------ C:\WINDOWS\SYSTEM32\SET6A1.tmp
2008-07-02 17:25 . 2008-04-14 05:41 1,267,200 --a------ C:\WINDOWS\SYSTEM32\SET4C1.tmp
2008-07-02 17:24 . 2008-04-14 05:41 1,082,368 --a------ C:\WINDOWS\SYSTEM32\SET451.tmp
2008-07-02 17:23 . 2008-04-14 05:42 3,066,880 --a------ C:\WINDOWS\SYSTEM32\SET399.tmp
2008-07-02 17:22 . 2008-04-14 05:42 1,703,936 --a------ C:\WINDOWS\SYSTEM32\SET352.tmp
2008-07-02 17:21 . 2008-04-14 05:42 8,461,312 --a------ C:\WINDOWS\SYSTEM32\SET2B7.tmp
2008-07-02 17:20 . 2008-04-14 05:42 727,040 --a------ C:\WINDOWS\SYSTEM32\SET259.tmp
2008-07-02 17:19 . 2008-04-14 05:42 666,112 --a------ C:\WINDOWS\SYSTEM32\SET23C.tmp
2008-07-02 17:10 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\005753_.tmp
2008-07-02 17:05 . 2008-04-14 05:42 409,088 --a------ C:\WINDOWS\SYSTEM32\qmgr.dll
2008-07-02 17:03 . 2008-04-14 00:57 2,188,928 --a------ C:\WINDOWS\SYSTEM32\ntoskrnl.exe
2008-06-25 14:08 . 2008-07-15 22:39 <DIR> d-------- C:\SmitfraudFix
2008-06-25 00:19 . 2008-06-25 00:20 1,445,888 --a------ C:\WinsockxpFix.exe
2008-06-25 00:11 . 2008-06-25 14:42 <DIR> d-------- C:\backups
2008-06-24 18:04 . 2008-06-24 18:04 251,392 --a------ C:\hijackthis_sfx.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 19:07 --------- d-----w C:\Documents and Settings\robh\Application Data\U3
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-13 15:00 691,545 ----a-w C:\WINDOWS\unins000.exe
2007-12-27 20:53 285,396 ----a-w C:\Program Files\50calrev.gif
2006-05-01 15:42 563,712 ----a-w C:\Documents and Settings\Administrator\370_gotomypc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinVNC"="C:\Program Files\UltraVNC\WinVNC.exe" [2005-08-06 19:45 974848]
C:\Documents and Settings\fasclampitt 2\Start Menu\Programs\Startup\
DESKTOP(2).INI [2002-09-03 14:36:04 84]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Firewall Client Management.lnk - C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe [2006-12-09 20:04:10 117568]
UPS WorldShip Messaging Utility.lnk - C:\UPS\WSTD\WSTDMessaging.exe [2007-12-13 16:55:54 65536]
UPS WorldShip PLD Reminder Utility.lnk - C:\UPS\WSTD\wstdPldReminder.exe [2007-12-12 22:05:04 31744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DESKTOP(2).INI]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP(2).INI
backup=C:\WINDOWS\pss\DESKTOP(2).INICommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-05-16 14:57 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iGateway"=2 (0x2)
"IDriverT"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="C:\Program Files\Microsoft Games\DAEMON Tools Lite\daemon.exe"
"Sonic RecordNow!"=
"WebSUpdater"="C:\Program Files\winvi\wupda.exe" /background
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" -lang 1033
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"BCMSMMSG"=BCMSMMSG.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"Realtime Monitor"="C:\Program Files\CA\eTrustITM\realmon.exe" -s
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe"
"runner1"=C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\UltraVNC\\winvnc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\CA\\eTrustITM\\InoRpc.exe"=
"C:\\Program Files\\CA\\eTrustITM\\Realmon.exe"=
"C:\\Program Files\\CA\\eTrustITM\\Shellscn.exe"=
"C:\\Program Files\\CA\\SharedComponents\\iTechnology\\igateway.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 netbtt;netbtt;C:\WINDOWS\system32\drivers\netbtt.sys [2008-05-08 14:50]
R2 Alert Notification Server;Alert Notification Server;C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE [2004-04-19 11:05]
R2 FwcAgent;Firewall Client Agent;C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe [2006-12-09 20:04]
S4 Win32Sr;Win32Sr;C:\WINDOWS\win32ssr.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b448d2a8-3956-11dd-ad26-000d56599d48}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-18 16:35:52 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 11:33:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\CA\eTrustITM\InoRpc.exe
C:\Program Files\CA\eTrustITM\InoRT.exe
C:\Program Files\CA\eTrustITM\InoTask.exe
C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\CA\eTrustITM\Ppcl.exe
C:\Program Files\CA\eTrustITM\Ppcl.exe
.
**************************************************************************
.
Completion time: 2008-07-18 11:41:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 16:41:46
ComboFix2.txt 2008-07-18 16:10:12
Pre-Run: 60,074,033,152 bytes free
Post-Run: 60,055,728,128 bytes free
163
----------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:46, on 2008-07-18
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
C:\Program Files\CA\eTrustITM\InoRpc.exe
C:\Program Files\CA\eTrustITM\InoRT.exe
C:\Program Files\CA\eTrustITM\InoTask.exe
C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\CA\eTrustITM\ppcl.exe
C:\Program Files\CA\eTrustITM\ppcl.exe
C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe
C:\UPS\WSTD\WSTDMessaging.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://cpcvpn:8080/array.dll?Get.Routing.Script
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cpcvpn:8080
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - Global Startup: Microsoft Firewall Client Management.lnk = C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\microsoft firewall client 2004\fwcwsp.dll
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1215604273551
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1215604189783
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Alert Notification Server - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
O23 - Service: eTrust ITM RPC Service (InoRPC) - CA - C:\Program Files\CA\eTrustITM\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Service (InoRT) - CA - C:\Program Files\CA\eTrustITM\InoRT.exe
O23 - Service: eTrust ITM Job Service (InoTask) - CA - C:\Program Files\CA\eTrustITM\InoTask.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRealtime\bin\ITMRTSVC.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
is this problem the same as Virtumonde?
---------------------------------------------------
Edit:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)but i got different results when running the scans.
Do NOT run 'fixes' before helpers have analyzed the HJT logPlease note that all instructions given are customized for that member's computer only, the tools used may cause damage if run on a computer with different infections. Your symptoms may only appear to be similar.
Last edited by a moderator: