This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde and other Trojans

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

are you saying run combofix again or just repost the last log?

how do I check the NIC card?

Yes, run a new combofix scan and post the log.

NIC.
Right Click My Computer> select Properties> select Hardware> select Device Manager>
See if anything listed has a Red X or Orange ?

no red x
last time I ran combofix, I dragged CFscript into it, and it removed Zonealarm

is it ok to run this?

yes. I want to check to see if I missed anything.
I have a CD that says Dell Connect Direct "Dell's directconnection to the Internet" probably came with the pc 2 years ago Note: For Recovery Purposes Only 1. Uninstall…… 2. Insert CD………. 3. Follow instructions……. should I try it?
ComboFix 07-12-31.4 - Mark 2008-01-06 19:46:00.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.222 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.

2008-01-06 16:43 . 2008-01-06 16:43 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-06 16:43 . 2008-01-06 16:43 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-05 21:03 . 2008-01-05 21:03 d——– C:\Documents and Settings\Mark\Application Data\MailFrontier
2008-01-05 13:25 . 2008-01-05 13:25 d——– C:\SIMPSONS_WS
2008-01-05 13:09 . 2008-01-05 13:09 d——– C:\Program Files\Red Kawa
2008-01-05 00:11 . 2008-01-06 19:54 569,376 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-05 00:11 . 2008-01-06 15:34 7,244 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-05 00:07 . 2008-01-06 10:51 75,248 –a—— C:\WINDOWS\zllsputility.exe
2008-01-04 23:54 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-04 23:54 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-04 23:54 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-01-04 23:54 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-04 23:54 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-04 23:54 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-04 23:54 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-04 23:54 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-01 18:23 . 2008-01-01 18:23 d——– C:\Documents and Settings\Mark\DoctorWeb
2008-01-01 10:02 . 2008-01-01 10:02 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-01 10:02 . 2008-01-01 10:02 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-01 09:15 . 2007-12-31 21:26 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-01 09:15 . 2007-12-31 21:26 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-01 09:15 . 2007-12-31 21:26 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-01 09:15 . 2007-12-31 21:26 90,112 –a—— C:\WINDOWS\UpdReg.EXE
2008-01-01 09:15 . 2007-12-31 21:26 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2007-12-31 21:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 15:57 . 2007-12-31 15:57 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-29 08:27 . 2008-01-06 15:36 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2008-01-05 19:01 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-25 09:58 . 2008-01-06 15:34 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 18:07 ——— d—–w C:\Program Files\Wii Video Converter
2008-01-03 01:29 ——— d—–w C:\Program Files\Quicken
2008-01-01 14:15 ——— d—–w C:\Program Files\QuickTime
2008-01-01 14:15 ——— d—–w C:\Program Files\DellSupport
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-30 22:19 ——— d—–w C:\Program Files\IZArc
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-14 21:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 22:04 19,659,826 —-a-w C:\WINDOWS\system32\lebronjames0607.scr
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-31_22.31.10.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-01 02:26:53 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2007-01-08 19:28:40 796,312 —-a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
+ 2007-11-14 21:04:46 796,048 —-a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
- 2007-12-26 17:41:52 2,507,528 —-a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-01-06 20:34:56 211,144 —-a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-01-01 02:26:21 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
- 2007-12-31 20:59:39 4,212 —ha-w C:\WINDOWS\system32\zllictbl.dat
+ 2008-01-05 05:09:36 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
+ 2008-01-06 20:35:56 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_6e8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-31 21:27 15360]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-31 21:27 460784]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-31 21:27 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-31 21:25 132496]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-31 21:26 221184]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-31 21:26 57344]
"P17Helper"="P17.dll" [2004-06-10 16:51 60928 C:\WINDOWS\system32\P17.dll]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-31 21:26 86960]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-31 21:26 86016]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-31 21:26 99840]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-31 21:26 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-31 21:26 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-31 21:26 114688]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-31 21:26 406016]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2005-12-21 09:14 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-31 21:26 32768]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-31 21:26 122941]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-31 21:26 39792]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-31 21:27 1065800]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""


.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 22:16:49 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-01-07 00:55:40 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 19:54:56
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
.
Completion time: 2008-01-06 19:58:47
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-07 00:58:37
C:\qoobox\ComboFix2.txt 2008-01-06 02:25:54
C:\qoobox\ComboFix3.txt 2008-01-05 05:33:09
C:\qoobox\ComboFix4.txt 2008-01-02 16:16:05
C:\qoobox\ComboFix5.txt 2008-01-01 14:30:04
.
2007-12-27 12:33:26 — E O F —
I can see anything that I missed.

Do you have your windows cd?

Try this if you do.

You can use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)
I have a CD that says Dell Connect Direct "Dell's directconnection to the Internet" probably came with the pc 2 years ago Note: For Recovery Purposes Only 1. Uninstall…… 2. Insert CD………. 3. Follow instructions……. should I try it?
I have a CD that says Dell Connect Direct "Dell's directconnection to the Internet" probably came with the pc 2 years ago Note: For Recovery Purposes Only 1. Uninstall…… 2. Insert CD………. 3. Follow instructions……. should I try it?
the cd was not for this pc I did not receive a XP cd with this Dell I have a piece of heavy paper that looks like a cd but says Your computer does not require an op sys cd or drivers cd………..use one these methods MS Windows System restore or Dell PC Restore Double click Owners Manual icon??????????? it's not there

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI