This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Combo Fix Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Continuation of previous topic:

http://forums.whatthetech.com/Hijack_Log_t100861.html

Combo Fix Log:

ComboFix 09-03-15.01 - Kodiak 2009-03-15 21:12:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1069 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Panda Antivirus Platinum 7 *On-access scanning disabled* (Outdated)
FW: Panda Antivirus Platinum 7 *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Kodiak\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Kodiak\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\poppers.exe
c:\windows\services.exe
c:\windows\system32\abiyanek.ini
c:\windows\system32\agifofih.ini
c:\windows\system32\ajuyodul.ini
c:\windows\system32\akufuvoh.ini
c:\windows\system32\amiriyan.ini
c:\windows\system32\anojireb.ini
c:\windows\system32\bahezido.dll
c:\windows\system32\berijona.dll
c:\windows\system32\cdpqey.dll
c:\windows\system32\cgehfq.dll
c:\windows\system32\dazimowe.dll
c:\windows\system32\dijuzihi.dll
c:\windows\system32\duvafiyi.dll
c:\windows\system32\duzileru.dll
c:\windows\system32\ejususig.ini
c:\windows\system32\elolofim.ini
c:\windows\system32\esunodey.ini
c:\windows\system32\etukezoy.ini
c:\windows\system32\exwzjo.dll
c:\windows\system32\fasapako.dll
c:\windows\system32\fesumuye.dll
c:\windows\system32\fiwobifi.dll
c:\windows\system32\fuzedanu.dll
c:\windows\system32\fwomqs.dll
c:\windows\system32\gisusuje.dll
c:\windows\system32\gomebomu.dll
c:\windows\system32\guteheso.dll
c:\windows\system32\hajiruno.dll
c:\windows\system32\hbpuwu.dll
c:\windows\system32\hgddxb.dll
c:\windows\system32\hifofiga.dll
c:\windows\system32\hnzjxi.dll
c:\windows\system32\hovufuka.dll
c:\windows\system32\hupezivu.dll
c:\windows\system32\ifibowif.ini
c:\windows\system32\imebetej.ini
c:\windows\system32\inikegoj.ini
c:\windows\system32\ipejiriw.ini
c:\windows\system32\jasoreje.dll
c:\windows\system32\jawegafa.dll
c:\windows\system32\jetebemi.dll
c:\windows\system32\jijejamu.dll
c:\windows\system32\jogekini.dll
c:\windows\system32\juguteto.dll
c:\windows\system32\juvoludi.dll
c:\windows\system32\kenayiba.dll
c:\windows\system32\kvrmtg.dll
c:\windows\system32\laviweta.dll
c:\windows\system32\leyoyoji.dll
c:\windows\system32\lipjvh.dll
c:\windows\system32\loyuvejo.dll
c:\windows\system32\ludoyuja.dll
c:\windows\system32\mifolole.dll
c:\windows\system32\mivalivo.dll
c:\windows\system32\muyipigu.dll
c:\windows\system32\nagomone.dll
c:\windows\system32\nahibozo.dll
c:\windows\system32\nayirima.dll
c:\windows\system32\niwezufa.dll
c:\windows\system32\novituto.dll
c:\windows\system32\nugedoka.dll
c:\windows\system32\onerabus.ini
c:\windows\system32\oteraget.ini
c:\windows\system32\pihuzura.dll
c:\windows\system32\popezaho.dll
c:\windows\system32\qmbcet.dll
c:\windows\system32\qvfplh.dll
c:\windows\system32\ravoruna.dll
c:\windows\system32\remebeyi.dll
c:\windows\system32\ridilave.dll
c:\windows\system32\ritibiji.dll
c:\windows\system32\sehcqh.dll
c:\windows\system32\sojohehu.dll
c:\windows\system32\sqpehm.dll
c:\windows\system32\subareno.dll
c:\windows\system32\tegareto.dll
c:\windows\system32\tepepife.dll
c:\windows\system32\uhehojos.ini
c:\windows\system32\uktuir.dll
c:\windows\system32\unadezuf.ini
c:\windows\system32\vabuzano.dll
c:\windows\system32\vbbgdf.dll
c:\windows\system32\vijogojo.dll
c:\windows\system32\vliixo.dll
c:\windows\system32\vuhugeya.dll
c:\windows\system32\wirijepi.dll
c:\windows\system32\wisahiri.dll
c:\windows\system32\wnbzup.dll
c:\windows\system32\wyjnux.dll
c:\windows\system32\yedonuse.dll
c:\windows\system32\yozekute.dll
c:\windows\system32\zesupoma.dll
c:\windows\system32\zotovebu.dll

—– BITS: Possible infected sites —–

hxxp://82.98.235.205
.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.

2009-03-10 05:23 . 2009-03-10 06:12 d——– c:\documents and settings\Kodiak\Application Data\HouseCall 6.6
2009-03-10 01:55 . 2009-03-10 01:55 20,709 –a—— c:\windows\system32\AAWService_2009_03_10_01_55_10.dmp
2009-03-10 01:16 . 2009-03-10 01:16 d——– c:\program files\Trend Micro
2009-02-23 09:59 . 2009-02-23 09:59 22,899 –a—— c:\windows\system32\AAWService_2009_02_23_08_59_04.dmp
2009-02-20 19:40 . 2009-02-20 19:38 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2009-02-20 19:38 . 2009-03-10 03:53 d——– c:\documents and settings\Kodiak\.housecall6.6
2009-02-20 19:32 . 2009-02-20 19:32 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_18_32_16.dmp
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-02-20 11:20 . 2009-02-20 11:20 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-02-20 11:17 . 2009-02-20 11:17 23,077 –a—— c:\windows\system32\AAWService_2009_02_20_10_17_53.dmp
2009-02-20 11:16 . 2009-03-10 01:10 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-20 10:30 . 2009-03-10 01:03 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-02-19 17:12 . 2009-03-12 08:52 69 –a—— c:\windows\NeroDigital.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 05:02 ——— d—–w c:\program files\SpywareBlaster
2009-02-04 15:11 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2009-02-04 14:39 ——— d—–w c:\program files\CCleaner
2009-02-04 13:28 ——— d—–w c:\program files\VideoLAN
2009-02-03 13:50 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 13:43 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-02 16:16 ——— d—–w c:\program files\UltraMon
2009-02-02 16:16 ——— d—–w c:\program files\Common Files\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\Kodiak\Application Data\Realtime Soft
2009-02-02 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\Realtime Soft
2009-02-02 14:13 ——— d—–w c:\documents and settings\Kodiak\Application Data\acccore
2009-02-02 14:13 ——— d—–w c:\documents and settings\All Users\Application Data\AOL OCP
2009-02-02 04:46 ——— d—–w c:\program files\Avaya
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Macrovision
2009-02-02 04:46 ——— d—–w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-02-02 02:08 ——— d—–w c:\program files\UltraVNC
2009-02-02 01:25 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-02 01:23 ——— dc-h–w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-02 01:23 ——— d—–w c:\program files\Lavasoft
2009-02-02 01:23 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-02 00:56 ——— d—–w c:\documents and settings\Kodiak\Application Data\UltraVNC
2009-02-02 00:31 ——— d—–w c:\program files\PingPlotter Standard
2009-02-01 23:49 ——— d—–w c:\program files\Common Files\Adobe
2009-02-01 23:34 ——— d—–w c:\program files\Java
2009-02-01 23:25 ——— d—–w c:\program files\Citrix
2009-02-01 23:24 ——— d—–w c:\program files\Tftpd32
2009-02-01 23:19 ——— d—–w c:\program files\AIM6
2009-02-01 23:16 ——— d—–w c:\program files\Viewpoint
2009-02-01 23:16 ——— d—–w c:\program files\Common Files\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2009-02-01 23:16 ——— d—–w c:\documents and settings\All Users\Application Data\acccore
2009-02-01 23:13 ——— d—–w c:\program files\Network Stumbler
2009-01-31 12:31 44 —h–w c:\program files\4258afe9.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-31 339968]
"UltraMon"="c:\program files\UltraMon\UltraMon.exe" [2005-05-14 187904]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Network Nomad Beta"="c:\utill\Network Nomad\Nomad.exe" [2004-10-15 65536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
–a—— 2009-03-10 01:09 515416 c:\program files\Lavasoft\Ad-Aware\AAWTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 03:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-21 13:09 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoToAssist Express Expert]
–a—— 2009-02-11 12:33 72504 c:\program files\Citrix\GoToAssist Express Expert\148\g2ax_start.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network Nomad Beta]
–a—— 2004-10-15 11:06 65536 c:\utill\Network Nomad\Nomad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2009-02-01 19:34 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avaya\\IP Office\\Phone Manager\\PhoneManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\Tftpd32\\tftpd32.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-01 64160]
R2 BVRPNDIS;BVRPNDIS Protocol Driver U/I;c:\utill\Network Nomad\BVRPNDIS.sys [2004-12-30 35328]
R2 Nomad;Network Nomad;c:\utill\Network Nomad\NomadSvr.exe [2004-12-30 65536]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2005-06-02 10496]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2009-02-01 24652]
R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [2005-05-14 3328]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb16c8b9-f0b5-11dd-816d-000f1fcebe93}]
\Shell\Auto\command - adp.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL adp.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-10 01:09]
.
- - - - ORPHANS REMOVED - - - -

BHO-{14171d40-aa84-42be-b6d4-d11a1f3550e6} - c:\windows\system32\kvrmtg.dll
BHO-{60994f74-00d1-4f8b-a7e7-3fd845a1a1de} - c:\windows\system32\dazimowe.dll
MSConfigStartUp-bc55cb6d - c:\windows\system32\mifolole.dll
MSConfigStartUp-CPMbf66f8f1 - c:\windows\system32\duzileru.dll
MSConfigStartUp-pokudopeku - c:\windows\system32\hupezivu.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {B1D475FE-75CD-11D2-8301-0060B0B32E16} - hxxps://ca.cdc.gov/vsimport.cab
DPF: {B57F9ACB-FD32-433E-8F30-515B2D8226F6} - hxxps://ca.cdc.gov/sdncode/sdnapp/common/chkperm.cab
FF - ProfilePath - c:\documents and settings\Kodiak\Application Data\Mozilla\Firefox\Profiles\jyr9yjqr.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 21:15:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WLTRAY.EXE
c:\program files\UltraMon\UltraMonTaskbar.exe
.
**************************************************************************
.
Completion time: 2009-03-15 21:18:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-16 01:17:59

Pre-Run: 5,845,340,160 bytes free
Post-Run: 5,775,974,400 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

286 — E O F — 2009-02-01 23:27:37
you should have PMed me to re-open the topic

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb16c8b9-f0b5-11dd-816d-000f1fcebe93}]
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Download Flash_Disinfector.exe from here and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you run it. Don't delete this folder…it will help protect your drives from future infection.



Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI