partial logs
i knew that couldn't be right when i opened those (actually 2 log results) and that's all there was to them. i have found a few files, same time and date that i think are from the scan. i'll list them below but i haven't got a clue about this. one of the files only contains the row of parenthesis shown in other logs. i hope this helps.
ComboDel.txt
Files to Move:
C:\WINDOWS\system32\icqmlib.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\icqmlib.exe.vir
C:\WINDOWS\system32\iepref32.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\iepref32.dll.vir
C:\WINDOWS\system32\ierplc.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ierplc.dll.vir
C:\WINDOWS\system32\ips.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ips.dll.vir
C:\WINDOWS\system32\lanmandrv.sys|C:\QooBox\Quarantine\C\WINDOWS\system32\lanmandrv.sys.vir
C:\WINDOWS\system32\lanmanwrk.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\lanmanwrk.exe.vir
C:\WINDOWS\system32\laprxy.dllexe|C:\QooBox\Quarantine\C\WINDOWS\system32\laprxy.dllexe.vir
C:\WINDOWS\system32\ocxapi.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ocxapi.dll.vir
C:\WINDOWS\system32\ocxloader.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\ocxloader.exe.vir
C:\WINDOWS\system32\qmopt.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\qmopt.dll.vir
ComboFix.txt
ComboFix 08-02.05.3 - Owner 2008-02-09 11:52:20.6 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 36 bytes in 1 streams.
ADS - explorer.exe: deleted 68 bytes in 1 streams.
drevB.dat
"C:\WINDOWS\system32\ddcya.exe"
"C:\WINDOWS\system32\geebb.exe"
"C:\WINDOWS\system32\cqdtoipk.dll"
"C:\WINDOWS\system32\ddcya.dll"
"C:\WINDOWS\system32\geeda.dll"
"C:\WINDOWS\system32\mllml.dll"
"C:\WINDOWS\system32\oiiuirep.dll"
"C:\WINDOWS\system32\tdxyceek.dll"
"C:\WINDOWS\system32\wvusspn.dll"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\aycdd.ini2"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\periuiio.ini"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\aycdd.ini2"
"C:\WINDOWS\system32\periuiio.ini"
SvcTarget.dat
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
d-del4AV.dat
""C:\WINDOWS\system32\icqmlib.exe""
""C:\WINDOWS\system32\iepref32.dll""
""C:\WINDOWS\system32\ierplc.dll""
""C:\WINDOWS\system32\ips.dll""
""C:\WINDOWS\system32\lanmandrv.sys""
""C:\WINDOWS\system32\lanmanwrk.exe""
""C:\WINDOWS\system32\laprxy.dllexe""
""C:\WINDOWS\system32\ocxapi.dll""
""C:\WINDOWS\system32\ocxloader.exe""
""C:\WINDOWS\system32\qmopt.dll""
and here is the only vundo log i can find anywhere...
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 10:22:14 AM 2/5/2008
Listing files found while scanning....
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\kxyxepux.dll
C:\WINDOWS\system32\onstvhvy.dll
C:\WINDOWS\system32\qbtirtul.dll
C:\WINDOWS\system32\tpjymcvb.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\geebb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kxyxepux.dll
C:\WINDOWS\system32\kxyxepux.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\onstvhvy.dll
C:\WINDOWS\system32\onstvhvy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qbtirtul.dll
C:\WINDOWS\system32\qbtirtul.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tpjymcvb.dll
C:\WINDOWS\system32\tpjymcvb.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tpjymcvb.dll
C:\WINDOWS\system32\tpjymcvb.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 2:36:40 PM 2/5/2008
Listing files found while scanning....
No infected files were found.
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 3:29:51 PM 2/5/2008
Listing files found while scanning....
No infected files were found.
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 20:32:33 2008-02-05
Listing files found while scanning....
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 05:56:42 2008-02-08
Listing files found while scanning....
C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\bxxxbwlp.dll
C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\ddcya.exe
C:\WINDOWS\system32\geebb.exe
C:\windows\system32\geeda.dll
C:\WINDOWS\system32\mjosaxqs.dll
C:\windows\system32\mllml.dll
C:\WINDOWS\system32\pgrxdmry.dll
C:\WINDOWS\system32\wvusspn.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\aycdd.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\bxxxbwlp.dll
C:\WINDOWS\system32\bxxxbwlp.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\ddcya.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddcya.exe
C:\WINDOWS\system32\ddcya.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebb.exe
C:\WINDOWS\system32\geebb.exe Has been deleted!
Attempting to delete C:\windows\system32\geeda.dll
C:\windows\system32\geeda.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mjosaxqs.dll
C:\WINDOWS\system32\mjosaxqs.dll Has been deleted!
Attempting to delete C:\windows\system32\mllml.dll
C:\windows\system32\mllml.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pgrxdmry.dll
C:\WINDOWS\system32\pgrxdmry.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 06:24:46 2008-02-08
Listing files found while scanning....
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmkji.exe
C:\WINDOWS\system32\wvusspn.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\ijkmp.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmkji.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmkji.exe
C:\WINDOWS\system32\pmkji.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 8:32:47 PM 2/8/2008
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 01:39:30 2008-02-09
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 18:05:18 2008-02-09
Listing files found while scanning....
No infected files were found.
i hope you can make some sense of this. again i appreciate your patience in helping more than i can say. i know i'm of little help. i'd have made a good scarecrow in the wizard of oz. if i only had a brain. let me know what i need to do next.
i knew that couldn't be right when i opened those (actually 2 log results) and that's all there was to them. i have found a few files, same time and date that i think are from the scan. i'll list them below but i haven't got a clue about this. one of the files only contains the row of parenthesis shown in other logs. i hope this helps.
ComboDel.txt
Files to Move:
C:\WINDOWS\system32\icqmlib.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\icqmlib.exe.vir
C:\WINDOWS\system32\iepref32.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\iepref32.dll.vir
C:\WINDOWS\system32\ierplc.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ierplc.dll.vir
C:\WINDOWS\system32\ips.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ips.dll.vir
C:\WINDOWS\system32\lanmandrv.sys|C:\QooBox\Quarantine\C\WINDOWS\system32\lanmandrv.sys.vir
C:\WINDOWS\system32\lanmanwrk.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\lanmanwrk.exe.vir
C:\WINDOWS\system32\laprxy.dllexe|C:\QooBox\Quarantine\C\WINDOWS\system32\laprxy.dllexe.vir
C:\WINDOWS\system32\ocxapi.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\ocxapi.dll.vir
C:\WINDOWS\system32\ocxloader.exe|C:\QooBox\Quarantine\C\WINDOWS\system32\ocxloader.exe.vir
C:\WINDOWS\system32\qmopt.dll|C:\QooBox\Quarantine\C\WINDOWS\system32\qmopt.dll.vir
ComboFix.txt
ComboFix 08-02.05.3 - Owner 2008-02-09 11:52:20.6 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 36 bytes in 1 streams.
ADS - explorer.exe: deleted 68 bytes in 1 streams.
drevB.dat
"C:\WINDOWS\system32\ddcya.exe"
"C:\WINDOWS\system32\geebb.exe"
"C:\WINDOWS\system32\cqdtoipk.dll"
"C:\WINDOWS\system32\ddcya.dll"
"C:\WINDOWS\system32\geeda.dll"
"C:\WINDOWS\system32\mllml.dll"
"C:\WINDOWS\system32\oiiuirep.dll"
"C:\WINDOWS\system32\tdxyceek.dll"
"C:\WINDOWS\system32\wvusspn.dll"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\aycdd.ini2"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\periuiio.ini"
"C:\WINDOWS\system32\aycdd.ini"
"C:\WINDOWS\system32\aycdd.ini2"
"C:\WINDOWS\system32\periuiio.ini"
SvcTarget.dat
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
d-del4AV.dat
""C:\WINDOWS\system32\icqmlib.exe""
""C:\WINDOWS\system32\iepref32.dll""
""C:\WINDOWS\system32\ierplc.dll""
""C:\WINDOWS\system32\ips.dll""
""C:\WINDOWS\system32\lanmandrv.sys""
""C:\WINDOWS\system32\lanmanwrk.exe""
""C:\WINDOWS\system32\laprxy.dllexe""
""C:\WINDOWS\system32\ocxapi.dll""
""C:\WINDOWS\system32\ocxloader.exe""
""C:\WINDOWS\system32\qmopt.dll""
and here is the only vundo log i can find anywhere...
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 10:22:14 AM 2/5/2008
Listing files found while scanning....
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\kxyxepux.dll
C:\WINDOWS\system32\onstvhvy.dll
C:\WINDOWS\system32\qbtirtul.dll
C:\WINDOWS\system32\tpjymcvb.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\geebb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kxyxepux.dll
C:\WINDOWS\system32\kxyxepux.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\onstvhvy.dll
C:\WINDOWS\system32\onstvhvy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qbtirtul.dll
C:\WINDOWS\system32\qbtirtul.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tpjymcvb.dll
C:\WINDOWS\system32\tpjymcvb.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tpjymcvb.dll
C:\WINDOWS\system32\tpjymcvb.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 2:36:40 PM 2/5/2008
Listing files found while scanning....
No infected files were found.
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 3:29:51 PM 2/5/2008
Listing files found while scanning....
No infected files were found.
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 20:32:33 2008-02-05
Listing files found while scanning....
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 05:56:42 2008-02-08
Listing files found while scanning....
C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\bxxxbwlp.dll
C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\ddcya.exe
C:\WINDOWS\system32\geebb.exe
C:\windows\system32\geeda.dll
C:\WINDOWS\system32\mjosaxqs.dll
C:\windows\system32\mllml.dll
C:\WINDOWS\system32\pgrxdmry.dll
C:\WINDOWS\system32\wvusspn.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\aycdd.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\bxxxbwlp.dll
C:\WINDOWS\system32\bxxxbwlp.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\ddcya.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddcya.exe
C:\WINDOWS\system32\ddcya.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebb.exe
C:\WINDOWS\system32\geebb.exe Has been deleted!
Attempting to delete C:\windows\system32\geeda.dll
C:\windows\system32\geeda.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mjosaxqs.dll
C:\WINDOWS\system32\mjosaxqs.dll Has been deleted!
Attempting to delete C:\windows\system32\mllml.dll
C:\windows\system32\mllml.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pgrxdmry.dll
C:\WINDOWS\system32\pgrxdmry.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 06:24:46 2008-02-08
Listing files found while scanning....
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmkji.exe
C:\WINDOWS\system32\wvusspn.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\ijkmp.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmkji.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmkji.exe
C:\WINDOWS\system32\pmkji.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\wvusspn.dll
C:\WINDOWS\system32\wvusspn.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 8:32:47 PM 2/8/2008
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 01:39:30 2008-02-09
Listing files found while scanning....
No infected files were found.
Beginning removal...
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.
Scan started at 18:05:18 2008-02-09
Listing files found while scanning....
No infected files were found.
i hope you can make some sense of this. again i appreciate your patience in helping more than i can say. i know i'm of little help. i'd have made a good scarecrow in the wizard of oz. if i only had a brain. let me know what i need to do next.