This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde Virus

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I read a few other threads, but nothing I read was exactly the same problem as mine, so basically I run webroot security scan and it finds some adware/trojan/virus and google told me it was all coming from one main virus known as Virtumonde, each time I scan with webroot it comes up, when I delete it, it finds a way back to my computer, making it impossible to use windows updater by switching it off every minute or two and the same with my virus protection. I can't use windows updater with Internet Explorer because the virus is stopping me from viewing the page. I used HJT to come up with this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:33:21 PM, on 8/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Multimedia Card Reader\readericon10.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O1 - Hosts: 80.15.232.4 nprotect.nefficient.com
O1 - Hosts: 80.15.232.1 nprotect.nefficient.com
O1 - Hosts: 80.15.232.2 nprotect.nefficient.com
O1 - Hosts: 80.15.232.3 nprotect.nefficient.com
O1 - Hosts: 80.15.232.5 nprotect.nefficient.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8fc99202-224f-4666-b16f-805fd53dc23a} - C:\WINDOWS\system32\dowosaze.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [UpdReg] "C:\WINDOWS\UpdReg.EXE"
O4 - HKLM\..\Run: [P17Helper] "Rundll32" P17.dll,P17Helper
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [readericon10] "C:\Program Files\Multimedia Card Reader\readericon10.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MBkLogOnHook] "C:\Program Files\McAfee\MBK\LogOnHook.exe"
O4 - HKLM\..\Run: [netivuwuwe] Rundll32.exe "C:\WINDOWS\system32\haruferi.dll",s
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CPM2f592ec1] "Rundll32.exe" "c:\windows\system32\soyozisu.dll",a
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKUS\S-1-5-18\..\Run: [userinit] C:\WINDOWS\system32\sdra64.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [userinit] C:\WINDOWS\system32\sdra64.exe (User 'Default user')
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/beta/SP.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by114fd.bay114.hotmail.msn.com/resources/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8111CD6-49A3-4B0F-9F01-0041CEC2DCDB}: NameServer = 68.189.122.26,68.116.46.115
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD7EEB46-63C8-4CAE-90E0-E012BF0A99F2}: NameServer = 10.0.0.1,10.0.0.2
O20 - AppInit_DLLs: C:\WINDOWS\system32\wahijisa.dll c:\windows\system32\soyozisu.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

–
End of file - 12766 bytes

I also downloaded the latest version of Malwarebytes' Anti-Malware, but I keep getting a runtime error and they said on their site that it's supposed to be fixed. I looked around the internet for solutions to my problem and everyone says to reinstall the OS. I don't know where my CD for my XP OS went and no it is not a pirated version, I DID pay for it. I also can't do a system restore if this even works in this situation because the only restore point on my computer now is set for the same day I acquired this stupid virus :smack:

Hope you can help, thanks in advance.

-Tonym209

Hello tonym209,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

tonym209,

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Reboot, on your next post please provide the following:
  • Gmer.txt

It's telling me the file is too big, in it's properties it's exactly 1.58MB in size and I'm only allowed 250k of attachment space. I cut it into 8 parts labeled 'Gmer1.txt' through 'Gmer8.txt'. I'll upload one part in each post, hope that's okay.

Attachments:

tonym209,

Please download ComboFix from one of these locations:

Link 1
Link 2

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

On your next post please provide:
  • ComboFix.txt

ComboFix 09-08-10.06 - Mejia 08/13/2009 14:04.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.1036 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\program files\AWS\WEATHE~1\MINIBU~1.DLL
c:\windows\Installer\a1a591a.msp
c:\windows\run.log
c:\windows\system32\AdCache
c:\windows\system32\AdCache\B_434_0_0_446000.htm
c:\windows\system32\AdCache\B_434_1_0_448500.htm
c:\windows\system32\AdCache\B_434_1_0_448600.htm
c:\windows\system32\AdCache\B_434_1_0_453800.htm
c:\windows\system32\bowiteko.dll
c:\windows\system32\Data
c:\windows\system32\disarada.dll
c:\windows\system32\fahokipa.dll
c:\windows\system32\gagepebi.dll
c:\windows\system32\gegupota.dll
c:\windows\system32\guporobe.dll
c:\windows\system32\kazifopo.dll
c:\windows\system32\lizepise.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\matumise.dll
c:\windows\system32\metefovu.dll
c:\windows\system32\nuhahezo.dll
c:\windows\system32\nujugeze.dll
c:\windows\system32\pakapedi.dll
c:\windows\system32\putosejo.dll
c:\windows\system32\puwisuro.dll
c:\windows\system32\ravababo.dll
c:\windows\system32\rawutebe.dll
c:\windows\system32\ridejamo.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\sovelune.dll
c:\windows\system32\sugonafo.dll
c:\windows\system32\varapogo.dll
c:\windows\system32\waderero.dll
c:\windows\system32\wofohuli.dll
c:\windows\system32\yasavodi.dll
c:\windows\system32\yerehajo.dll
c:\windows\system32\yevazani.dll
c:\windows\system32\yiguseda.dll
c:\windows\system32\yikuhawa.dll
c:\windows\system32\zowohuku.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete

—– BITS: Possible infected sites —–

hxxp://82.98.231.96

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_OREANS32
——-\Service_oreans32


((((((((((((((((((((((((( Files Created from 2009-07-13 to 2009-08-13 )))))))))))))))))))))))))))))))
.

2009-08-13 11:15 . 2009-08-13 11:15 84480 -csha-w- c:\windows\system32\joseloho.dll
2009-08-12 23:14 . 2009-08-12 23:15 49664 -csha-w- c:\windows\system32\feboyonu.dll
2009-08-12 11:14 . 2009-08-12 11:14 84992 -csha-w- c:\windows\system32\yekenize.dll
2009-08-11 23:10 . 2009-08-12 00:02 83968 -c–a-w- c:\windows\system32\nudewolu.dll
2009-08-11 11:14 . 2009-08-11 12:02 50176 -c–a-w- c:\windows\system32\munuropi.dll
2009-08-11 00:24 . 2009-08-11 00:24 ——– dc—-w- c:\program files\Trend Micro
2009-08-11 00:16 . 2009-08-03 20:36 38160 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-11 00:16 . 2009-08-11 00:16 ——– dc—-w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-11 00:16 . 2009-08-03 20:36 19096 -c–a-w- c:\windows\system32\drivers\mbam.sys
2009-08-11 00:16 . 2009-08-11 00:24 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2009-08-10 23:14 . 2009-08-10 23:42 50176 -c–a-w- c:\windows\system32\hebebubo.dll
2009-08-10 20:42 . 2009-08-10 20:42 ——– dc—-w- c:\documents and settings\Mejia\Application Data\Roxio
2009-08-10 11:15 . 2009-08-10 11:15 84480 -csha-w- c:\windows\system32\mirupuho.dll
2009-08-09 23:13 . 2009-08-09 23:13 84992 -csha-w- c:\windows\system32\dukemido.dll
2009-08-07 18:54 . 2009-08-07 18:55 ——– dc—-w- c:\program files\iTunes
2009-08-07 18:49 . 2009-08-07 18:50 ——– dc—-w- c:\program files\QuickTime
2009-07-15 09:53 . 2009-08-13 03:08 ——– dc—-w- c:\program files\Heroes of Newerth

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-12 23:10 . 2009-08-12 23:10 84992 -c-h–w- c:\windows\system32\BIT1E4.tmp
2009-08-12 23:10 . 2009-08-12 23:10 38400 -c-h–w- c:\windows\system32\BIT1E5.tmp
2009-08-10 09:28 . 2009-08-10 09:28 1234612 -c–a-w- c:\windows\system32\xa.tmp
2009-08-08 07:27 . 2009-05-08 07:27 84480 -csha-w- c:\windows\system32\vopugoke.dll
2009-08-07 19:27 . 2009-05-07 19:27 84992 -csha-w- c:\windows\system32\banewelu.dll
2009-08-07 18:59 . 2007-10-02 01:04 ——– dc—-w- c:\documents and settings\All Users\Application Data\Apple
2009-08-07 18:54 . 2005-04-10 22:04 ——– dc—-w- c:\program files\iPod
2009-08-07 18:54 . 2007-10-02 01:07 ——– dc—-w- c:\program files\Common Files\Apple
2009-08-06 07:26 . 2009-05-06 07:26 84992 -csha-w- c:\windows\system32\bonipola.dll
2009-08-05 19:25 . 2009-05-05 19:25 50176 -csha-w- c:\windows\system32\subivula.dll
2009-08-05 19:25 . 2009-05-05 19:25 85504 -csha-w- c:\windows\system32\zeliyagi.dll
2009-08-05 07:25 . 2009-05-05 07:25 84992 -csha-w- c:\windows\system32\hulizoki.dll
2009-08-04 19:25 . 2009-05-04 19:25 84992 -csha-w- c:\windows\system32\porowuru.dll
2009-08-04 07:25 . 2009-05-04 07:25 85504 -csha-w- c:\windows\system32\paviviwa.dll
2009-08-04 04:55 . 2007-10-15 21:06 ——– dc—-w- c:\documents and settings\Mejia\Application Data\LimeWire
2009-08-03 19:25 . 2009-05-03 19:24 50688 -csha-w- c:\windows\system32\bilefola.dll
2009-07-24 22:16 . 2007-10-12 18:24 1878984 -c–a-w- c:\documents and settings\Mejia\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-07-24 16:11 . 2009-06-18 02:55 ——– dc—-w- c:\program files\Steam
2009-07-24 16:08 . 2008-03-25 18:19 ——– dc—-w- c:\program files\Warcraft III
2009-07-20 19:47 . 2009-04-01 21:00 ——– dc—-w- c:\program files\Common Files\Blizzard Entertainment
2009-07-16 01:02 . 2009-07-13 02:07 ——– dc—-w- c:\documents and settings\Mejia\Application Data\Audacity
2009-07-15 07:45 . 2008-05-21 08:05 189488 -c–a-w- c:\windows\system32\PnkBstrB.exe
2009-07-15 07:41 . 2008-05-21 08:05 139016 -c–a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-15 05:30 . 2009-05-03 01:09 ——– dc—-w- c:\program files\World of Warcraft
2009-07-14 02:48 . 2005-01-07 04:36 ——– dc-h–w- c:\program files\InstallShield Installation Information
2009-07-13 21:22 . 2009-07-13 21:22 75048 -c–a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-13 02:07 . 2009-07-13 02:07 ——– dc—-w- c:\program files\Audacity 1.3 Beta (Unicode)
2009-07-09 19:16 . 2009-04-25 22:48 39424 -c–a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 19:16 . 2009-04-25 22:48 2060288 -c–a-w- c:\windows\system32\usbaaplrc.dll
2009-07-07 07:19 . 2009-07-07 07:19 139152 -c–a-w- c:\documents and settings\Mejia\Application Data\PnkBstrK.sys
2009-07-07 07:19 . 2009-07-07 07:19 139152 -c–a-w- c:\documents and settings\Mejia\Application Data\PnkBstrK.sys
2009-07-07 07:18 . 2008-05-21 08:05 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-07-07 07:18 . 2009-07-07 07:18 794408 -c–a-w- c:\windows\system32\pbsvc.exe
2009-07-07 06:49 . 2009-07-07 06:49 ——– dc—-w- c:\program files\EA Games
2009-06-25 23:36 . 2009-07-07 06:49 1291640 -c–a-w- c:\documents and settings\Mejia\Application Data\Mozilla\Firefox\Profiles\cc5597j2.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
2009-06-25 23:36 . 2009-07-07 06:49 729088 -c–a-w- c:\documents and settings\Mejia\Application Data\Mozilla\Firefox\Profiles\cc5597j2.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
2009-06-20 07:18 . 2008-06-24 07:25 ——– dc—-w- c:\documents and settings\Mejia\Application Data\DNA
2009-06-20 07:08 . 2008-06-24 07:25 ——– dc—-w- c:\program files\DNA
2009-06-19 05:24 . 2009-05-15 23:11 ——– dc—-w- c:\program files\Screaming Bee
2009-06-19 05:20 . 2008-08-02 00:33 ——– dc—-w- c:\program files\WC3Banlist
2009-06-19 05:20 . 2008-03-04 01:31 ——– dc—-w- c:\program files\BestOn
2009-06-19 01:40 . 2009-06-19 01:40 ——– dc—-w- c:\documents and settings\Mejia\Application Data\ATI
2009-06-19 01:40 . 2009-06-19 01:40 ——– dc—-w- c:\documents and settings\All Users\Application Data\ATI
2009-06-19 01:39 . 2009-06-19 01:39 0 -c–a-w- c:\windows\ativpsrm.bin
2009-06-19 01:34 . 2009-06-19 01:31 ——– dc—-w- c:\program files\ATI Technologies
2009-06-15 15:40 . 2005-04-09 18:23 ——– dc—-w- c:\program files\Samsung
2009-06-02 02:56 . 2009-06-02 02:57 410984 -c–a-w- c:\windows\system32\deploytk.dll
2009-06-02 02:56 . 2009-06-02 02:56 152576 -c–a-w- c:\documents and settings\Mejia\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-05-16 00:22 . 2009-05-16 00:22 164 -c–a-w- c:\windows\install.dat
2009-05-16 00:21 . 2009-05-16 00:25 108296 -c–a-w- c:\windows\system32\drivers\pwipf6.sys
2009-05-05 19:26 . 2009-05-05 19:26 50176 -csha-w- c:\windows\SYSTEM32\dowosaze.dll.tmp
2009-05-12 23:15 . 2009-05-12 23:15 49664 -csha-w- c:\windows\SYSTEM32\gojajado.dll
2009-05-05 19:26 . 2009-05-05 19:26 50176 -csha-w- c:\windows\SYSTEM32\haruferi.dll.tmp
2009-05-03 19:25 . 2009-05-03 19:25 50688 -csha-w- c:\windows\SYSTEM32\pukuzope.dll.tmp
2009-05-12 23:15 . 2009-05-12 23:15 49664 -csha-w- c:\windows\SYSTEM32\repunowe.dll
2009-05-03 19:25 . 2009-05-03 19:25 50688 -csha-w- c:\windows\SYSTEM32\teyowike.dll.tmp
2009-05-03 19:25 . 2009-05-03 19:25 50688 -csha-w- c:\windows\SYSTEM32\tikikele.dll.tmp
2009-05-05 19:26 . 2009-05-05 19:26 50176 -csha-w- c:\windows\SYSTEM32\wahijisa.dll.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8fc99202-224f-4666-b16f-805fd53dc23a}]
2009-05-12 23:15 49664 -csha-w- c:\windows\SYSTEM32\repunowe.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2009-04-06 20:26 238968 -c–a-w- c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"readericon10"="c:\program files\Multimedia Card Reader\readericon10.exe" [2007-05-03 131072]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"netivuwuwe"="c:\windows\system32\gojajado.dll" [2009-05-12 49664]
"CPM2f592ec1"="c:\windows\system32\joseloho.dll" [2009-08-13 84480]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-04-06 6345840]
"P17Helper"="P17.dll" - c:\windows\SYSTEM32\P17.dll [2004-06-10 60928]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"netivuwuwe"="c:\windows\system32\gojajado.dll" [2009-05-12 49664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\joseloho.dll" [2009-08-13 84480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\joseloho.dll [2009-08-13 84480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Mejia^Start Menu^Programs^Startup^My_AutoWarkey_Script.lnk]
path=c:\documents and settings\Mejia\Start Menu\Programs\Startup\My_AutoWarkey_Script.lnk
backup=c:\windows\pss\My_AutoWarkey_Script.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\WINDOWS\\SYSTEM32\\java.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\tm27\\condition zero\\hl.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\tm27\\counter-strike source\\hl2.exe"=
"c:\\WINDOWS\\SYSTEM32\\PnkBstrA.exe"=
"c:\\WINDOWS\\SYSTEM32\\PnkBstrB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Dell Wireless\\PRISMCFG.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15727:TCP"= 15727:TCP:*:Disabled:BitComet 15727 TCP
"15727:UDP"= 15727:UDP:*:Disabled:BitComet 15727 UDP

R0 ssfs0bbc;ssfs0bbc;c:\windows\SYSTEM32\DRIVERS\ssfs0bbc.sys [4/2/2009 2:30 PM 29808]
R1 pwipf6;pwipf6;c:\windows\SYSTEM32\DRIVERS\pwipf6.sys [5/15/2009 5:25 PM 108296]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 12:03 PM 169312]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/10/2007 3:12 PM 24652]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [5/15/2009 5:25 PM 1181040]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" –> c:\program files\McAfee\SiteAdvisor\McSACore.exe [?]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [11/6/2007 1:22 PM 34064]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\SYSTEM32\DRIVERS\wg111v2.sys [3/3/2008 12:45 PM 194304]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\SYSTEM32\DRIVERS\ScreamingBAudio.sys [11/22/2008 12:53 PM 23064]
S4 PRISMSVC;PRISMSVC;c:\windows\SYSTEM32\PRISMSVC.exe [1/6/2005 9:36 PM 57344]
.
Contents of the 'Scheduled Tasks' folder

2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-08-11 c:\windows\Tasks\wrSpySweeper_LA85FEF5A94D84C84A091D8A63649CD9C.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-05-16 20:32]

2009-08-11 c:\windows\Tasks\wrSpySweeper_LA85FEF5A94D84C84A091D8A63649CD9C.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-05-16 20:32]

2009-08-13 c:\windows\Tasks\wrSpySweeper_LB7EF57EEAF3847A68AAB38658003BF0D.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-05-16 20:32]

2009-08-13 c:\windows\Tasks\wrSpySweeper_LB7EF57EEAF3847A68AAB38658003BF0D.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-05-16 20:32]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Microsoft Works Update Detection - c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell4me.com/mywaybiz
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {B8111CD6-49A3-4B0F-9F01-0041CEC2DCDB} = 68.189.122.26,68.116.46.115
TCP: {FD7EEB46-63C8-4CAE-90E0-E012BF0A99F2} = 10.0.0.1,10.0.0.2
FF - ProfilePath - c:\documents and settings\Mejia\Application Data\Mozilla\Firefox\Profiles\cc5597j2.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?query=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\Mejia\Application Data\Mozilla\Firefox\Profiles\cc5597j2.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-13 14:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\documents and settings\Mejia\Application Data\Webroot\Spy Sweeper\Reports\ml-20090813024116765.zip 3684 bytes
c:\documents and settings\Mejia\Application Data\Webroot\Spy Sweeper\Temp\SS9.tmp 52747 bytes

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\.mfp]
@DACL=(02 0000)
@="MacromediaFlashPaper.MacromediaFlashPaper"
"Content Type"="application/x-shockwave-flash"

[HKEY_LOCAL_MACHINE\software\Classes\.sol]
@DACL=(02 0000)
"Content Type"="text/plain"

[HKEY_LOCAL_MACHINE\software\Classes\.sor]
@DACL=(02 0000)
"Content Type"="text/plain"

[HKEY_LOCAL_MACHINE\software\Classes\.spl]
@DACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash"
"Content Type"="application/futuresplash"

[HKEY_LOCAL_MACHINE\software\Classes\.swf]
@DACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash"
"Content Type"="application/x-shockwave-flash"

[HKEY_LOCAL_MACHINE\software\Classes\FlashProp.FlashProp]
@DACL=(02 0000)
@="FlashProp Class"

[HKEY_LOCAL_MACHINE\software\Classes\FlashProp.FlashProp.1]
@DACL=(02 0000)
@="FlashProp Class"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\RtlGina2.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3352)
c:\windows\system32\joseloho.dll
c:\windows\system32\gojajado.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\progra~1\WINDOW~2\wmpband.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\windows\SYSTEM32\PRISMSVR.exe
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\windows\SYSTEM32\PnkBstrA.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\SYSTEM32\rundll32.exe
c:\windows\SYSTEM32\MsPMSPSv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Dell Wireless\PRISMCFG.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-08-13 14:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-13 21:23

Pre-Run: 15,567,106,048 bytes free
Post-Run: 15,736,258,560 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

361 — E O F — 2009-06-14 05:01

tonym209,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quote box below into it:

File::
c:\windows\system32\joseloho.dll
c:\windows\system32\feboyonu.dll
c:\windows\system32\yekenize.dll
c:\windows\system32\nudewolu.dll
c:\windows\system32\munuropi.dll
c:\windows\system32\hebebubo.dll
c:\windows\system32\mirupuho.dll
c:\windows\system32\dukemido.dll
c:\windows\system32\BIT1E4.tmp
c:\windows\system32\BIT1E5.tmp
c:\windows\system32\xa.tmp
c:\windows\system32\vopugoke.dll
c:\windows\system32\banewelu.dll
c:\windows\system32\bonipola.dll
c:\windows\system32\subivula.dll
c:\windows\system32\zeliyagi.dll
c:\windows\system32\hulizoki.dll
c:\windows\system32\porowuru.dll
c:\windows\system32\paviviwa.dll
c:\windows\SYSTEM32\dowosaze.dll.tmp
c:\windows\SYSTEM32\gojajado.dll
c:\windows\SYSTEM32\haruferi.dll.tmp
c:\windows\SYSTEM32\pukuzope.dll.tmp
c:\windows\SYSTEM32\repunowe.dll
c:\windows\SYSTEM32\teyowike.dll.tmp
c:\windows\SYSTEM32\tikikele.dll.tmp
c:\windows\SYSTEM32\wahijisa.dll.tmp

Reg::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8fc99202-224f-4666-b16f-805fd53dc23a}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netivuwuwe"=-
"CPM2f592ec1"=-

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"netivuwuwe"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-

Folder::
c:\program files\Viewpoint

Rootkit::
c:\documents and settings\Mejia\Application Data\Webroot\Spy Sweeper\Reports\ml-20090813024116765.zip
c:\documents and settings\Mejia\Application Data\Webroot\Spy Sweeper\Temp\SS9.tmp


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt

Reboot, on your next post please provide the following:
  • ComboFix.txt log
  • Tell me how your computer is running at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI