Cooley
Topic Starter
Continuation of previous topic:
http://forums.whatthetech.com/Hijack_Log_t100861.html
Combo Fix Log:
ComboFix 09-03-15.01 - Kodiak 2009-03-15 21:12:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1069 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Panda Antivirus Platinum 7 *On-access scanning disabled* (Outdated)
FW: Panda Antivirus Platinum 7 *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Kodiak\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Kodiak\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\poppers.exe
c:\windows\services.exe
c:\windows\system32\abiyanek.ini
c:\windows\system32\agifofih.ini
c:\windows\system32\ajuyodul.ini
c:\windows\system32\akufuvoh.ini
c:\windows\system32\amiriyan.ini
c:\windows\system32\anojireb.ini
c:\windows\system32\bahezido.dll
c:\windows\system32\berijona.dll
c:\windows\system32\cdpqey.dll
c:\windows\system32\cgehfq.dll
c:\windows\system32\dazimowe.dll
c:\windows\system32\dijuzihi.dll
c:\windows\system32\duvafiyi.dll
c:\windows\system32\duzileru.dll
c:\windows\system32\ejususig.ini
c:\windows\system32\elolofim.ini
c:\windows\system32\esunodey.ini
c:\windows\system32\etukezoy.ini
c:\windows\system32\exwzjo.dll
c:\windows\system32\fasapako.dll
c:\windows\system32\fesumuye.dll
c:\windows\system32\fiwobifi.dll
c:\windows\system32\fuzedanu.dll
c:\windows\system32\fwomqs.dll
c:\windows\system32\gisusuje.dll
c:\windows\system32\gomebomu.dll
c:\windows\system32\guteheso.dll
c:\windows\system32\hajiruno.dll
c:\windows\system32\hbpuwu.dll
c:\windows\system32\hgddxb.dll
c:\windows\system32\hifofiga.dll
c:\windows\system32\hnzjxi.dll
c:\windows\system32\hovufuka.dll
c:\windows\system32\hupezivu.dll
c:\windows\system32\ifibowif.ini
c:\windows\system32\imebetej.ini
c:\windows\system32\inikegoj.ini
c:\windows\system32\ipejiriw.ini
c:\windows\system32\jasoreje.dll
c:\windows\system32\jawegafa.dll
c:\windows\system32\jetebemi.dll
c:\windows\system32\jijejamu.dll
c:\windows\system32\jogekini.dll
c:\windows\system32\juguteto.dll
c:\windows\system32\juvoludi.dll
c:\windows\system32\kenayiba.dll
c:\windows\system32\kvrmtg.dll
c:\windows\system32\laviweta.dll
c:\windows\system32\leyoyoji.dll
c:\windows\system32\lipjvh.dll
c:\windows\system32\loyuvejo.dll
c:\windows\system32\ludoyuja.dll
c:\windows\system32\mifolole.dll
c:\windows\system32\mivalivo.dll
c:\windows\system32\muyipigu.dll
c:\windows\system32\nagomone.dll
c:\windows\system32\nahibozo.dll
c:\windows\system32\nayirima.dll
c:\windows\system32\niwezufa.dll
c:\windows\system32\novituto.dll
c:\windows\system32\nugedoka.dll
c:\windows\system32\onerabus.ini
c:\windows\system32\oteraget.ini
c:\windows\system32\pihuzura.dll
c:\windows\system32\popezaho.dll
c:\windows\system32\qmbcet.dll
c:\windows\system32\qvfplh.dll
c:\windows\system32\ravoruna.dll
c:\windows\system32\remebeyi.dll
c:\windows\system32\ridilave.dll
c:\windows\system32\ritibiji.dll
c:\windows\system32\sehcqh.dll
c:\windows\system32\sojohehu.dll
c:\windows\system32\sqpehm.dll
c:\windows\system32\subareno.dll
c:\windows\system32\tegareto.dll
c:\windows\system32\tepepife.dll
c:\windows\system32\uhehojos.ini
c:\windows\system32\uktuir.dll
c:\windows\system32\unadezuf.ini
c:\windows\system32\vabuzano.dll
c:\windows\system32\vbbgdf.dll
c:\windows\system32\vijogojo.dll
c:\windows\system32\vliixo.dll
c:\windows\system32\vuhugeya.dll
c:\windows\system32\wirijepi.dll
c:\windows\system32\wisahiri.dll
c:\windows\system32\wnbzup.dll
c:\windows\system32\wyjnux.dll
c:\windows\system32\yedonuse.dll
c:\windows\system32\yozekute.dll
c:\windows\system32\zesupoma.dll
c:\windows\system32\zotovebu.dll
—– BITS: Possible infected sites —–
hxxp://82.98.235.205
.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.
2009-03-10 05:23 . 2009-03-10 06:12 d——– c:\documents and settings\Kodiak\Application Data\HouseCall 6.6
2009-03-10 01:55 . 2009-03-10 01:55 20,709 –a—— c:\windows\system32\AAWService_2009_03_10_01_55_10.dmp
2009-03-10 01:16 . 2009-03-10 01:16 d——– c:\program files\Trend Micro
2009-02-23 09:59 . 2009-02-23 09:59 22,899 –a—— c:\windows\system32\AAWService_2009_02_23_08_59_04.dmp
2009-02-20 19:40 . 2009-02-20 19:38 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2009-02-20 19:38 . 2009-03-10 03:53 d——– c:\documents and settings\Kodiak\.housecall6.6
2009-02-20 19:32 . 2009-02-20 19:32 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_18_32_16.dmp
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-02-20 11:17 . 2009-02-20 11:17 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_10_17_53.dmp
2009-02-20 11:16 . 2009-03-10 01:10 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-20 10:30 . 2009-03-10 01:03 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-02-19 17:12 . 2009-03-12 08:52 69 –a—— c:\windows\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 05:02 ——— d—–w c:\program files\SpywareBlaster
2009-02-04 15:11 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2009-02-04 14:39 ——— d—–w c:\program files\CCleaner
2009-02-04 13:28 ——— d—–w c:\program files\VideoLAN
2009-02-03 13:50 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 13:43 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-02 16:16 ——— d—–w c:\program files\UltraMon
2009-02-02 16:16 ——— d—–w c:\program files\Common Files\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\Kodiak\Application Data\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\Realtime Soft
2009-02-02 14:13 ——— d—–w c:\documents and settings\Kodiak\Application Data\acccore
2009-02-02 14:13 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2009-02-02 04:46 ——— d—–w c:\program files\Avaya
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Macrovision
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-02-02 02:08 ——— d—–w c:\program files\UltraVNC
2009-02-02 01:25 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-02 01:23 ——— dc-h–w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-02 01:23 ——— d—–w c:\program files\Lavasoft
2009-02-02 01:23 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-02 00:56 ——— d—–w c:\documents and settings\Kodiak\Application Data\UltraVNC
2009-02-02 00:31 ——— d—–w c:\program files\PingPlotter Standard
2009-02-01 23:49 ——— d—–w c:\program files\Common Files\Adobe
2009-02-01 23:34 ——— d—–w c:\program files\Java
2009-02-01 23:25 ——— d—–w c:\program files\Citrix
2009-02-01 23:24 ——— d—–w c:\program files\Tftpd32
2009-02-01 23:19 ——— d—–w c:\program files\AIM6
2009-02-01 23:16 ——— d—–w c:\program files\Viewpoint
2009-02-01 23:16 ——— d—–w c:\program files\Common Files\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2009-02-01 23:13 ——— d—–w c:\program files\Network Stumbler
2009-01-31 12:31 44 —h–w c:\program files\4258afe9.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-31 339968]
"UltraMon"="c:\program files\UltraMon\UltraMon.exe" [2005-05-14 187904]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Network Nomad Beta"="c:\utill\Network Nomad\Nomad.exe" [2004-10-15 65536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
–a—— 2009-03-10 01:09 515416 c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 03:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-21 13:09 50472 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoToAssist Express Expert]
–a—— 2009-02-11 12:33 72504 c:\program files\Citrix\GoToAssist Express Expert\148\g2ax_start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network Nomad Beta]
–a—— 2004-10-15 11:06 65536 c:\utill\Network Nomad\Nomad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2009-02-01 19:34 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avaya\\IP Office\\Phone Manager\\PhoneManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\Tftpd32\\tftpd32.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-01 64160]
R2 BVRPNDIS;BVRPNDIS Protocol Driver U/I;c:\utill\Network Nomad\BVRPNDIS.sys [2004-12-30 35328]
R2 Nomad;Network Nomad;c:\utill\Network Nomad\NomadSvr.exe [2004-12-30 65536]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2005-06-02 10496]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2009-02-01 24652]
R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [2005-05-14 3328]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb16c8b9-f0b5-11dd-816d-000f1fcebe93}]
\Shell\Auto\command - adp.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL adp.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-10 01:09]
.
- - - - ORPHANS REMOVED - - - -
BHO-{14171d40-aa84-42be-b6d4-d11a1f3550e6} - c:\windows\system32\kvrmtg.dll
BHO-{60994f74-00d1-4f8b-a7e7-3fd845a1a1de} - c:\windows\system32\dazimowe.dll
MSConfigStartUp-bc55cb6d - c:\windows\system32\mifolole.dll
MSConfigStartUp-CPMbf66f8f1 - c:\windows\system32\duzileru.dll
MSConfigStartUp-pokudopeku - c:\windows\system32\hupezivu.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {B1D475FE-75CD-11D2-8301-0060B0B32E16} - hxxps://ca.cdc.gov/vsimport.cab
DPF: {B57F9ACB-FD32-433E-8F30-515B2D8226F6} - hxxps://ca.cdc.gov/sdncode/sdnapp/common/chkperm.cab
FF - ProfilePath - c:\documents and settings\Kodiak\Application Data\Mozilla\Firefox\Profiles\jyr9yjqr.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 21:15:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WLTRAY.EXE
c:\program files\UltraMon\UltraMonTaskbar.exe
.
**************************************************************************
.
Completion time: 2009-03-15 21:18:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-16 01:17:59
Pre-Run: 5,845,340,160 bytes free
Post-Run: 5,775,974,400 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
286 — E O F — 2009-02-01 23:27:37
http://forums.whatthetech.com/Hijack_Log_t100861.html
Combo Fix Log:
ComboFix 09-03-15.01 - Kodiak 2009-03-15 21:12:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1069 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Panda Antivirus Platinum 7 *On-access scanning disabled* (Outdated)
FW: Panda Antivirus Platinum 7 *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Kodiak\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Kodiak\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\poppers.exe
c:\windows\services.exe
c:\windows\system32\abiyanek.ini
c:\windows\system32\agifofih.ini
c:\windows\system32\ajuyodul.ini
c:\windows\system32\akufuvoh.ini
c:\windows\system32\amiriyan.ini
c:\windows\system32\anojireb.ini
c:\windows\system32\bahezido.dll
c:\windows\system32\berijona.dll
c:\windows\system32\cdpqey.dll
c:\windows\system32\cgehfq.dll
c:\windows\system32\dazimowe.dll
c:\windows\system32\dijuzihi.dll
c:\windows\system32\duvafiyi.dll
c:\windows\system32\duzileru.dll
c:\windows\system32\ejususig.ini
c:\windows\system32\elolofim.ini
c:\windows\system32\esunodey.ini
c:\windows\system32\etukezoy.ini
c:\windows\system32\exwzjo.dll
c:\windows\system32\fasapako.dll
c:\windows\system32\fesumuye.dll
c:\windows\system32\fiwobifi.dll
c:\windows\system32\fuzedanu.dll
c:\windows\system32\fwomqs.dll
c:\windows\system32\gisusuje.dll
c:\windows\system32\gomebomu.dll
c:\windows\system32\guteheso.dll
c:\windows\system32\hajiruno.dll
c:\windows\system32\hbpuwu.dll
c:\windows\system32\hgddxb.dll
c:\windows\system32\hifofiga.dll
c:\windows\system32\hnzjxi.dll
c:\windows\system32\hovufuka.dll
c:\windows\system32\hupezivu.dll
c:\windows\system32\ifibowif.ini
c:\windows\system32\imebetej.ini
c:\windows\system32\inikegoj.ini
c:\windows\system32\ipejiriw.ini
c:\windows\system32\jasoreje.dll
c:\windows\system32\jawegafa.dll
c:\windows\system32\jetebemi.dll
c:\windows\system32\jijejamu.dll
c:\windows\system32\jogekini.dll
c:\windows\system32\juguteto.dll
c:\windows\system32\juvoludi.dll
c:\windows\system32\kenayiba.dll
c:\windows\system32\kvrmtg.dll
c:\windows\system32\laviweta.dll
c:\windows\system32\leyoyoji.dll
c:\windows\system32\lipjvh.dll
c:\windows\system32\loyuvejo.dll
c:\windows\system32\ludoyuja.dll
c:\windows\system32\mifolole.dll
c:\windows\system32\mivalivo.dll
c:\windows\system32\muyipigu.dll
c:\windows\system32\nagomone.dll
c:\windows\system32\nahibozo.dll
c:\windows\system32\nayirima.dll
c:\windows\system32\niwezufa.dll
c:\windows\system32\novituto.dll
c:\windows\system32\nugedoka.dll
c:\windows\system32\onerabus.ini
c:\windows\system32\oteraget.ini
c:\windows\system32\pihuzura.dll
c:\windows\system32\popezaho.dll
c:\windows\system32\qmbcet.dll
c:\windows\system32\qvfplh.dll
c:\windows\system32\ravoruna.dll
c:\windows\system32\remebeyi.dll
c:\windows\system32\ridilave.dll
c:\windows\system32\ritibiji.dll
c:\windows\system32\sehcqh.dll
c:\windows\system32\sojohehu.dll
c:\windows\system32\sqpehm.dll
c:\windows\system32\subareno.dll
c:\windows\system32\tegareto.dll
c:\windows\system32\tepepife.dll
c:\windows\system32\uhehojos.ini
c:\windows\system32\uktuir.dll
c:\windows\system32\unadezuf.ini
c:\windows\system32\vabuzano.dll
c:\windows\system32\vbbgdf.dll
c:\windows\system32\vijogojo.dll
c:\windows\system32\vliixo.dll
c:\windows\system32\vuhugeya.dll
c:\windows\system32\wirijepi.dll
c:\windows\system32\wisahiri.dll
c:\windows\system32\wnbzup.dll
c:\windows\system32\wyjnux.dll
c:\windows\system32\yedonuse.dll
c:\windows\system32\yozekute.dll
c:\windows\system32\zesupoma.dll
c:\windows\system32\zotovebu.dll
—– BITS: Possible infected sites —–
hxxp://82.98.235.205
.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.
2009-03-10 05:23 . 2009-03-10 06:12 d——– c:\documents and settings\Kodiak\Application Data\HouseCall 6.6
2009-03-10 01:55 . 2009-03-10 01:55 20,709 –a—— c:\windows\system32\AAWService_2009_03_10_01_55_10.dmp
2009-03-10 01:16 . 2009-03-10 01:16 d——– c:\program files\Trend Micro
2009-02-23 09:59 . 2009-02-23 09:59 22,899 –a—— c:\windows\system32\AAWService_2009_02_23_08_59_04.dmp
2009-02-20 19:40 . 2009-02-20 19:38 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2009-02-20 19:38 . 2009-03-10 03:53 d——– c:\documents and settings\Kodiak\.housecall6.6
2009-02-20 19:32 . 2009-02-20 19:32 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_18_32_16.dmp
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-02-20 11:17 . 2009-02-20 11:17 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_10_17_53.dmp
2009-02-20 11:16 . 2009-03-10 01:10 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-20 10:30 . 2009-03-10 01:03 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-02-19 17:12 . 2009-03-12 08:52 69 –a—— c:\windows\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 05:02 ——— d—–w c:\program files\SpywareBlaster
2009-02-04 15:11 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2009-02-04 14:39 ——— d—–w c:\program files\CCleaner
2009-02-04 13:28 ——— d—–w c:\program files\VideoLAN
2009-02-03 13:50 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 13:43 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-02 16:16 ——— d—–w c:\program files\UltraMon
2009-02-02 16:16 ——— d—–w c:\program files\Common Files\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\Kodiak\Application Data\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\Realtime Soft
2009-02-02 14:13 ——— d—–w c:\documents and settings\Kodiak\Application Data\acccore
2009-02-02 14:13 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2009-02-02 04:46 ——— d—–w c:\program files\Avaya
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Macrovision
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-02-02 02:08 ——— d—–w c:\program files\UltraVNC
2009-02-02 01:25 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-02 01:23 ——— dc-h–w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-02 01:23 ——— d—–w c:\program files\Lavasoft
2009-02-02 01:23 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-02 00:56 ——— d—–w c:\documents and settings\Kodiak\Application Data\UltraVNC
2009-02-02 00:31 ——— d—–w c:\program files\PingPlotter Standard
2009-02-01 23:49 ——— d—–w c:\program files\Common Files\Adobe
2009-02-01 23:34 ——— d—–w c:\program files\Java
2009-02-01 23:25 ——— d—–w c:\program files\Citrix
2009-02-01 23:24 ——— d—–w c:\program files\Tftpd32
2009-02-01 23:19 ——— d—–w c:\program files\AIM6
2009-02-01 23:16 ——— d—–w c:\program files\Viewpoint
2009-02-01 23:16 ——— d—–w c:\program files\Common Files\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2009-02-01 23:13 ——— d—–w c:\program files\Network Stumbler
2009-01-31 12:31 44 —h–w c:\program files\4258afe9.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-31 339968]
"UltraMon"="c:\program files\UltraMon\UltraMon.exe" [2005-05-14 187904]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Network Nomad Beta"="c:\utill\Network Nomad\Nomad.exe" [2004-10-15 65536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
–a—— 2009-03-10 01:09 515416 c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 03:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-21 13:09 50472 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoToAssist Express Expert]
–a—— 2009-02-11 12:33 72504 c:\program files\Citrix\GoToAssist Express Expert\148\g2ax_start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network Nomad Beta]
–a—— 2004-10-15 11:06 65536 c:\utill\Network Nomad\Nomad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2009-02-01 19:34 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avaya\\IP Office\\Phone Manager\\PhoneManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\Tftpd32\\tftpd32.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-01 64160]
R2 BVRPNDIS;BVRPNDIS Protocol Driver U/I;c:\utill\Network Nomad\BVRPNDIS.sys [2004-12-30 35328]
R2 Nomad;Network Nomad;c:\utill\Network Nomad\NomadSvr.exe [2004-12-30 65536]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2005-06-02 10496]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2009-02-01 24652]
R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [2005-05-14 3328]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb16c8b9-f0b5-11dd-816d-000f1fcebe93}]
\Shell\Auto\command - adp.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL adp.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-10 01:09]
.
- - - - ORPHANS REMOVED - - - -
BHO-{14171d40-aa84-42be-b6d4-d11a1f3550e6} - c:\windows\system32\kvrmtg.dll
BHO-{60994f74-00d1-4f8b-a7e7-3fd845a1a1de} - c:\windows\system32\dazimowe.dll
MSConfigStartUp-bc55cb6d - c:\windows\system32\mifolole.dll
MSConfigStartUp-CPMbf66f8f1 - c:\windows\system32\duzileru.dll
MSConfigStartUp-pokudopeku - c:\windows\system32\hupezivu.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {B1D475FE-75CD-11D2-8301-0060B0B32E16} - hxxps://ca.cdc.gov/vsimport.cab
DPF: {B57F9ACB-FD32-433E-8F30-515B2D8226F6} - hxxps://ca.cdc.gov/sdncode/sdnapp/common/chkperm.cab
FF - ProfilePath - c:\documents and settings\Kodiak\Application Data\Mozilla\Firefox\Profiles\jyr9yjqr.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 21:15:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WLTRAY.EXE
c:\program files\UltraMon\UltraMonTaskbar.exe
.
**************************************************************************
.
Completion time: 2009-03-15 21:18:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-16 01:17:59
Pre-Run: 5,845,340,160 bytes free
Post-Run: 5,775,974,400 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
286 — E O F — 2009-02-01 23:27:37