along_came_spider
New member
hi ive run the combo fix and this is the log..i need help with the code to run to remove the virus completely ..any help wud be appreciated...
ComboFix 08-02-28 - arun s 2008-03-03 23:32:54.1 - FAT32x86
Running from: E:\Documents and Settings\arun s\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
E:\WINDOWS\system32\sockspy.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\Fonts\a.zip
E:\WINDOWS\system32\cbxvsrs.dll
E:\WINDOWS\system32\orqss.ini
E:\WINDOWS\system32\orqss.ini2
E:\WINDOWS\system32\pac.txt
E:\WINDOWS\system32\windows
.
((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.
2008-03-03 22:15 . 2008-03-03 22:15 <DIR> d-------- E:\VundoFix Backups
2008-03-03 21:49 . 2008-03-03 23:36 54,156 --ah----- E:\WINDOWS\QTFont.qfn
2008-03-03 21:49 . 2008-03-03 23:34 1,409 --a------ E:\WINDOWS\QTFont.for
2008-03-03 19:01 . 2008-03-03 19:03 98,158 --a------ E:\WINDOWS\BM93cdef99.xml
2008-03-03 19:01 . 2008-03-03 21:50 22 --a------ E:\WINDOWS\pskt.ini
2008-03-02 17:44 . 2008-03-02 17:44 <DIR> d--hs---- E:\FOUND.020
2008-03-02 17:34 . 2008-03-02 17:34 147,456 --a------ E:\WINDOWS\system32\vbzip10.dll
2008-03-02 17:31 . 2008-03-02 17:31 <DIR> d-------- E:\WINDOWS\system32\iDlo18
2008-03-01 15:47 . 2007-09-24 23:31 69,632 --a------ E:\WINDOWS\system32\javacpl.cpl
2008-02-29 11:36 . 2008-02-29 11:36 <DIR> d-------- E:\Program Files\Total Assistant
2008-02-27 11:56 . 2008-02-27 11:56 <DIR> d--hs---- E:\FOUND.009
2008-02-24 16:59 . 2008-02-24 16:59 <DIR> d--hs---- E:\FOUND.008
2008-02-17 11:13 . 2008-02-17 11:13 <DIR> d--hs---- E:\FOUND.007
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d--hs---- E:\FOUND.006
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-03 18:05 81,984 ----a-w E:\WINDOWS\system32\bdod.bin
2008-01-24 06:55 12,632 ----a-w E:\WINDOWS\system32\lsdelete.exe
2008-01-24 05:21 --------- d-----w E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 15:12 311,840 ----a-w E:\WINDOWS\eFaxView.exe
2006-08-26 18:14 461 ----a-w E:\Program Files\INSTALL.LOG
2007-07-02 14:18 149 --sha-r E:\WINDOWS\Regbak.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C75F5BC9-BEC9-42EA-87F7-FDD1E6621694}]
E:\WINDOWS\system32\ssqro.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd4d6dfe-f7c6-4450-9394-220039298c32}]
E:\WINDOWS\system32\woiqtluw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="E:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDMCon"="E:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2006-08-26 23:38 372736]
"BDNewsAgent"="E:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe" [2005-06-09 10:28 9728]
"BDSwitchAgent"="E:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe" [2005-04-06 13:09 33280]
"QuickTime Task"="E:\Program Files\QuickTime\qttask.exe" [2006-11-10 13:38 77824]
"LVCOMS"="E:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 09:39 98304]
"Sony Ericsson PC Suite"="E:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"!AVG Anti-Spyware"="E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:55 6731312]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"bc70990b"="E:\WINDOWS\system32\qshutojh.dll" [ ]
"BM93cdef99"="E:\WINDOWS\system32\uaillsmj.dll" [ ]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - E:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2006-11-10 13:54:09 1421328]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=E:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=E:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
--a------ 2006-08-26 23:38 372736 E:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDNewsAgent]
--a------ 2005-06-09 10:28 9728 E:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent]
--a------ 2005-04-06 13:09 33280 E:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-05-30 15:22 542208 E:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGNER]
--a------ 2007-04-04 12:54 561172 E:\WINDOWS\system32\aphvcso.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 21:54 1694208 E:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-11-10 13:38 77824 E:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-02-13 23:59 35328 E:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"ose"=3 (0x3)
"InCDsrv"=2 (0x2)
"SLService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"E:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"E:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"E:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3cc8de-3371-11dc-a3e7-0008a183c26d}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 18:06:50 E:\WINDOWS\Tasks\Symantec NetDetect.job"
- E:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 23:37:03
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: E:\WINDOWS\system32\winlogon.exe
-> E:\WINDOWS\system32\sockspy.dll
PROCESS: E:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> E:\WINDOWS\system32\sockspy.dll
.
------------------------ Other Running Processes ------------------------
.
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
E:\Program Files\Common Files\Teleca Shared\Generic.exe
E:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
E:\PROGRA~1\ESCRIP~1\EDITSC~1\EditScriptProcMon.exe
E:\WINDOWS\system32\wdfmgr.exe
E:\Program Files\RealVNC\VNC4\WinVNC4.exe
E:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
E:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
E:\Program Files\Softwin\BitDefender9\vsserv.exe
E:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-03 23:40:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 18:10:00
.
2008-01-10 02:35:17 --- E O F ---
thanx again
ComboFix 08-02-28 - arun s 2008-03-03 23:32:54.1 - FAT32x86
Running from: E:\Documents and Settings\arun s\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
E:\WINDOWS\system32\sockspy.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\Fonts\a.zip
E:\WINDOWS\system32\cbxvsrs.dll
E:\WINDOWS\system32\orqss.ini
E:\WINDOWS\system32\orqss.ini2
E:\WINDOWS\system32\pac.txt
E:\WINDOWS\system32\windows
.
((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.
2008-03-03 22:15 . 2008-03-03 22:15 <DIR> d-------- E:\VundoFix Backups
2008-03-03 21:49 . 2008-03-03 23:36 54,156 --ah----- E:\WINDOWS\QTFont.qfn
2008-03-03 21:49 . 2008-03-03 23:34 1,409 --a------ E:\WINDOWS\QTFont.for
2008-03-03 19:01 . 2008-03-03 19:03 98,158 --a------ E:\WINDOWS\BM93cdef99.xml
2008-03-03 19:01 . 2008-03-03 21:50 22 --a------ E:\WINDOWS\pskt.ini
2008-03-02 17:44 . 2008-03-02 17:44 <DIR> d--hs---- E:\FOUND.020
2008-03-02 17:34 . 2008-03-02 17:34 147,456 --a------ E:\WINDOWS\system32\vbzip10.dll
2008-03-02 17:31 . 2008-03-02 17:31 <DIR> d-------- E:\WINDOWS\system32\iDlo18
2008-03-01 15:47 . 2007-09-24 23:31 69,632 --a------ E:\WINDOWS\system32\javacpl.cpl
2008-02-29 11:36 . 2008-02-29 11:36 <DIR> d-------- E:\Program Files\Total Assistant
2008-02-27 11:56 . 2008-02-27 11:56 <DIR> d--hs---- E:\FOUND.009
2008-02-24 16:59 . 2008-02-24 16:59 <DIR> d--hs---- E:\FOUND.008
2008-02-17 11:13 . 2008-02-17 11:13 <DIR> d--hs---- E:\FOUND.007
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d--hs---- E:\FOUND.006
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-03 18:05 81,984 ----a-w E:\WINDOWS\system32\bdod.bin
2008-01-24 06:55 12,632 ----a-w E:\WINDOWS\system32\lsdelete.exe
2008-01-24 05:21 --------- d-----w E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 15:12 311,840 ----a-w E:\WINDOWS\eFaxView.exe
2006-08-26 18:14 461 ----a-w E:\Program Files\INSTALL.LOG
2007-07-02 14:18 149 --sha-r E:\WINDOWS\Regbak.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C75F5BC9-BEC9-42EA-87F7-FDD1E6621694}]
E:\WINDOWS\system32\ssqro.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd4d6dfe-f7c6-4450-9394-220039298c32}]
E:\WINDOWS\system32\woiqtluw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="E:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDMCon"="E:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2006-08-26 23:38 372736]
"BDNewsAgent"="E:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe" [2005-06-09 10:28 9728]
"BDSwitchAgent"="E:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe" [2005-04-06 13:09 33280]
"QuickTime Task"="E:\Program Files\QuickTime\qttask.exe" [2006-11-10 13:38 77824]
"LVCOMS"="E:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 09:39 98304]
"Sony Ericsson PC Suite"="E:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"!AVG Anti-Spyware"="E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:55 6731312]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"bc70990b"="E:\WINDOWS\system32\qshutojh.dll" [ ]
"BM93cdef99"="E:\WINDOWS\system32\uaillsmj.dll" [ ]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - E:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2006-11-10 13:54:09 1421328]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=E:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=E:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
--a------ 2006-08-26 23:38 372736 E:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDNewsAgent]
--a------ 2005-06-09 10:28 9728 E:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent]
--a------ 2005-04-06 13:09 33280 E:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-05-30 15:22 542208 E:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGNER]
--a------ 2007-04-04 12:54 561172 E:\WINDOWS\system32\aphvcso.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 21:54 1694208 E:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-11-10 13:38 77824 E:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-02-13 23:59 35328 E:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"ose"=3 (0x3)
"InCDsrv"=2 (0x2)
"SLService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"E:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"E:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"E:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3cc8de-3371-11dc-a3e7-0008a183c26d}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - E:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 18:06:50 E:\WINDOWS\Tasks\Symantec NetDetect.job"
- E:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 23:37:03
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: E:\WINDOWS\system32\winlogon.exe
-> E:\WINDOWS\system32\sockspy.dll
PROCESS: E:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> E:\WINDOWS\system32\sockspy.dll
.
------------------------ Other Running Processes ------------------------
.
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
E:\Program Files\Common Files\Teleca Shared\Generic.exe
E:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
E:\PROGRA~1\ESCRIP~1\EDITSC~1\EditScriptProcMon.exe
E:\WINDOWS\system32\wdfmgr.exe
E:\Program Files\RealVNC\VNC4\WinVNC4.exe
E:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
E:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
E:\Program Files\Softwin\BitDefender9\vsserv.exe
E:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-03 23:40:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 18:10:00
.
2008-01-10 02:35:17 --- E O F ---
thanx again