This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virtumonde trouble and port-scanning annoyance

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

Many thanks for the support provided. I have described the problem below to the best of my ability. Please let me know if you need any additional info.

–Singseeker

Here are the details of the problem:

ENVIRONMENT:
I have Windows XP SP2, running McAfee (provided by Comcast) and Spyware Doctor OnGuard. I have uninstalled Norton antivirus that came preinstalled with the machine. I have Anti-Malware, Ad-Aware, Spybot S&D in addition to the above. Since this problem came about, I exclusively use Firefox (not updated to the latest version) and that really seems to help, but I am not sure.

PROBLEM SUMMARY:
Virtumonde infection detected by Spyware Doctor,
Web-requests (not https requests) seem to go to a lot of places before actually going to the correct site (e.g. google-analytics)
Several open ports being targeted by untraceable IPs (e.g. port numbers 9100, 2191, NetBIOS session targeted by 192.168.1.102!)
At one point, web-surfing became very slow, but that seemed to have been resolved by running FixVundo.exe and FixVMonde.exe
Virtumonde infection severity was earlier 'high risk' in Spyware Doctor, but after running FixVundo and FixVMonde, it has been downgraded to 'Medium'.
I followed all instructions while running the above two programs to clear Virtumonde, but was unsuccessful
I have disabled a lot of processes to close ports and that has helped with the port-scanning problem. I have also banned several IPs originating from Russia, Mexico, China etc. that showed up in McAfee logs. However, I don't know how to block the 192.168 series IPs and the remaining open ports.

HIJACKTHIS LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:06 PM, on 7/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MIT\Kerberos\bin\leash32.exe
C:\Program Files\MIT\Kerberos\bin\krbcc32s.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\PROGRA~1\McAfee\MSC\mcshell.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - Global Startup: Leash Ticket Manager.lnk = C:\Program Files\MIT\Kerberos\bin\leash32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
O16 - DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF} (JInitiator 1.3.1.17) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8439 bytes
Hi

You neednt try to block the 192.168 series of IP addresses. They relate to your computer/network and router.

I dont see any signs of Vundo in the HijackThis log, so lets take a wider look


Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
Hello.

Many thanks for the quick response.

>> Yes, I understand that 198.162 series is my own network. What is surprising is the port scanning done from 'apparently' these local IPs! I, for sure, am not and I don't have any other machines on this network either. Someone seems to be faking their IP and doing the port-scan, and I am not able to block them out by the IP-banning method. Sorry, maybe I wasn't communicating clearly the first time around. Also, if this question does not belong on this forum, or if it is not related to this problem, please let me know and I'll edit the post with apologies.

>> FixVundo.exe and VixVMonde.exe both report 'no infection' just like you say. However, Spyware Doctor does show '10 infections' of 'Medium' severity.

>> Please find the logs posted below from DSS

MAIN:
———
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-03 23:31:16
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
19: 2008-07-04 03:31:30 UTC - RP565 - Deckard's System Scanner Restore Point
18: 2008-06-28 14:03:13 UTC - RP564 - Software Distribution Service 3.0
17: 2008-06-28 02:27:41 UTC - RP563 - System Checkpoint
16: 2008-06-21 17:19:41 UTC - RP562 - System Checkpoint
15: 2008-06-14 18:28:46 UTC - RP561 - Software Distribution Service 3.0


– First Restore Point –
1: 2008-04-08 15:27:09 UTC - RP547 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Ramesh.exe) ———————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:35:33 PM, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MIT\Kerberos\bin\leash32.exe
C:\Program Files\MIT\Kerberos\bin\krbcc32s.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Documents and Settings\Ramesh\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ramesh.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - Global Startup: Leash Ticket Manager.lnk = C:\Program Files\MIT\Kerberos\bin\leash32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q304&bd;=presario&pf;=laptop
O16 - DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF} (JInitiator 1.3.1.17) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8361 bytes

– File Associations ———————————————————–

.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys
Hello again.

I have a Spyware Doctor log that shows the Virtumonde infection instances. Please find it in the attached logfile.

One other thing:
I am not sure which software told me this, but the suspicious program seems to be one 'esoftware', which you can see in the DSS log as well.

I hope this provides additional useful information.

Many thanks for your help.

–singseeker.
Hi

Looks like a leftover key. And we shall remove that eSoftware folder. BTW, you seem to be missing XP updates.

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once Recovery Console is installed, you should see a blue screen prompt like the one below:

[external image: Posted Image]

Click Yes to allow Combofix to continue scanning for malware.

When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
Hello.

Please find below the logs as requested. There are three logs (Combofix.txt, Hijackthis.log, Log.txt) in that order.

I had disabled Spyware Doctor, but did not manage to disable McAfee. Perhaps because of this, I am not sure, but I got a battery of pop ups from the antivirus software.

One particular alert was about having blocked a 'high risk' trojan! I was a little scared to proceed, but went ahead and installed the recovery console as well as the combofix utility. Thereafter, I also got a quarantine alert for pv.cfexe just before combofix started to run!


If you need any additional information, I'll be glad to answer.

Many thanks yet again.

–singseeker

COMBOFIX.TXT:
—————————

ComboFix 08-07-04.1 - Ramesh 2008-07-04 16:33:24.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ramesh\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol

.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.

2008-07-03 23:30 . 2008-07-03 23:30 d——– C:\Deckard
2008-06-11 21:59 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 21:59 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 20:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-04 20:17 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\Skype
2008-07-04 03:28 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\AdobeUM
2008-07-03 02:36 ——— d—–w C:\Program Files\Spyware Doctor
2008-06-21 19:39 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-02 08:30 ——— d—–w C:\Program Files\eSoftware
2008-06-02 03:06 ——— d—–w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-02 03:06 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\Malwarebytes
2008-06-02 03:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-30 05:06 34,296 —-a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-30 05:06 15,864 —-a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-05-24 03:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-24 03:18 ——— d—–w C:\Program Files\Lavasoft
2008-05-24 03:17 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 15:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-11 10:53 ——— d—–w C:\Program Files\Trend Micro
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-21 07:04 615,936 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-04-21 07:04 474,112 —-a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:04 1,494,528 —-a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-17 10:52 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-01-11 00:52 15,186,133 —-a-w C:\Program Files\if3014a.exe
2007-09-07 01:56 6,725,320 —-a-w C:\Program Files\Thunderbird Setup 2.0.0.6.exe
2007-04-07 19:21 20,409,656 —-a-w C:\Program Files\FSS_PH60.exe
2007-03-24 01:00 433,024 —-a-w C:\Program Files\x264.exe
2007-03-24 00:59 3,376,597 —-a-w C:\Program Files\FFDSHOW.exe
2007-03-24 00:49 11,868,792 —-a-w C:\Program Files\winamp533_full_bundle_emusic-7plus.exe
2007-03-21 01:07 12,307,656 —-a-w C:\Program Files\wdviewer.exe
2007-03-06 02:43 5,111,302 —-a-w C:\Program Files\CricketStreamZSetup.exe
2007-03-04 19:50 61,139,088 —-a-w C:\Program Files\Quicken_Basic_2007.exe
2006-01-28 14:09 44,592 —-a-w C:\Documents and Settings\Ramesh\Application Data\GDIPFONTCACHEV1.DAT
2005-05-26 22:17 1,973 —-a-w C:\Program Files\Installation and user guide.txt
2004-01-02 17:18 868,291 —-a-r C:\Program Files\DigtalSignatureVerifierSetup.exe
2003-08-05 16:41 53,248 —-a-w C:\WINDOWS\inf\ap561.exe
2002-11-26 21:24 32,768 —-a-w C:\WINDOWS\inf\Remove561.exe
2002-11-22 20:56 118,784 —-a-w C:\WINDOWS\inf\ShowBmp.exe
2002-10-29 23:07 36,864 —-a-w C:\WINDOWS\inf\Setup8a.exe
2002-10-01 19:43 119,798 —-a-w C:\WINDOWS\inf\spca561.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 110,592 2003-08-19 08:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

—-a-w 49,152 2005-02-17 04:11:42 C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe

—-a-w 49,152 2003-05-23 03:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe

—-a-w 208,958 2004-04-30 17:32:46 C:\Program Files\HPQ\Default Settings\bak\cpqset.exe

—-a-w 286,720 2004-07-30 15:33:44 C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe

—-a-w 256,576 2006-10-30 14:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\iTunes\iTunesHelper.exe

—-a-w 49,263 2006-10-12 08:10:54 C:\Program Files\Java\jre1.5.0_09\bin\bak\jusched.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

—-a-w 282,624 2006-10-25 23:58:18 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\QuickTime\qttask.exe

—-a-w 1,773,568 2007-03-07 14:58:20 C:\Program Files\support.com\bin\bak\tgcmd.exe

—-a-w 536,576 2004-05-26 17:15:16 C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe

—-a-w 98,304 2004-05-26 17:15:42 C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe

—-a-w 35,328 2007-02-13 18:29:00 C:\Program Files\Winamp\bak\winampa.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Winamp\winampa.exe

—-a-w 4,670,968 2007-03-27 19:22:56 C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE

—-a-w 507,904 2006-02-14 23:32:14 C:\WINDOWS\Samsung\PanelMgr\bak\ssmmgr.exe

—-a-w 15,360 2004-08-04 08:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-04 13:00:00 C:\WINDOWS\system32\ctfmon.exe

—-a-w 118,784 2003-10-30 08:33:50 C:\WINDOWS\system32\bak\hkcmd.exe

—-a-w 483,328 2003-05-23 02:55:38 C:\WINDOWS\system32\bak\hphmon05.exe

—-a-w 155,648 2003-10-30 08:46:52 C:\WINDOWS\system32\bak\igfxtray.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:00 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [N/A]

C:\Documents and Settings\Suja\Start Menu\Programs\Startup\
WKCALREM.LNK.disabled [2005-05-23 09:21:26 930]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Leash Ticket Manager.lnk - C:\Program Files\MIT\Kerberos\bin\leash32.exe [2004-09-17 02:53:54 770048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 04:15:54 65588]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ramesh^Start Menu^Programs^Startup^Password Safe.lnk]
path=C:\Documents and Settings\Ramesh\Start Menu\Programs\Startup\Password Safe.lnk
backup=C:\WINDOWS\pss\Password Safe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]
[X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-27 12:38 14348 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-10-25 19:58 282624 C:\Program Files\QuickTime\bak\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
C:\Program Files\Support.com\bin\tgcmd.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CVPND"=2 (0x2)
"AOL ACS"=2 (0x2)
"OracleServiceDB1"=2 (0x2)
"OracleOraWBClientCache"=3 (0x3)
"OracleOraToolsClientCache"=3 (0x3)
"OracleOraHome10TNSListener"=2 (0x2)
"OracleOraHome10SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome10SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome10iSQL*Plus"=2 (0x2)
"OracleOraComp10ProcessManager"=2 (0x2)
"OracleDBConsoleDB1"=2 (0x2)
"OracleCSService"=2 (0x2)
"iPod Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\jre\\bin\\java.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\bin\\java.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\OPNET EDU\\9.1.A\\sys\\pc_intel_win32\\bin\\itguru.exe"=
"C:\\oracle\\product\\10.1.0\\OraHome10\\jdk\\jre\\bin\\java.exe"=
"C:\\oracle\\product\\10.1.0\\OraHome10\\jdk\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S3 SM_sugo3_FUService;sugo3 Status Monitor Service;"C:\Program Files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service []
S4 OracleCSService;OracleCSService;C:\oracle\product\10.1.0\OraHome10\bin\ocssd.exe service []
S4 OracleDBConsoleDB1;OracleDBConsoleDB1;C:\oracle\product\10.1.0\OraHome10\bin\nmesrvc.exe [2004-03-05 00:33]
S4 OracleJobSchedulerDB1;OracleJobSchedulerDB1;c:\oracle\product\10.1.0\orahome10\Bin\extjob.exe DB1 []
S4 OracleOraComp10ProcessManager;OracleOraComp10ProcessManager;C:\oracle\product\10.1.0\OraComp10\opmn\bin\opmn.exe [2004-03-05 04:03]
S4 OracleOraHome10iSQL*Plus;OracleOraHome10iSQL*Plus;C:\oracle\product\10.1.0\OraHome10\bin\isqlplussvc.exe [2006-12-31 12:30]
S4 OracleOraHome10SNMPPeerEncapsulator;OracleOraHome10SNMPPeerEncapsulator;C:\oracle\product\10.1.0\OraHome10\BIN\ENCSVC.EXE [2006-12-31 12:33]
S4 OracleOraHome10SNMPPeerMasterAgent;OracleOraHome10SNMPPeerMasterAgent;C:\oracle\product\10.1.0\OraHome10\BIN\AGNTSVC.EXE [2006-12-31 12:33]
S4 OracleOraHome10TNSListener;OracleOraHome10TNSListener;C:\oracle\product\10.1.0\OraHome10\BIN\TNSLSNR []
S4 OracleOraToolsClientCache;OracleOraToolsClientCache;c:\OraTools\BIN\ONRSD.EXE [2004-03-24 14:50]
S4 OracleOraWBClientCache;OracleOraWBClientCache;c:\oraWB\BIN\ONRSD.EXE [2002-04-26 20:34]
S4 OracleServiceDB1;OracleServiceDB1;c:\oracle\product\10.1.0\orahome10\bin\ORACLE.EXE DB1 []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19d51ec4-f9cf-11db-ac3a-00904bb919e4}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 10:37:32 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-05-01 05:00:20 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-04 16:43:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome10TNSListener]
"ImagePath"="C:\oracle\product\10.1.0\OraHome10\BIN\TNSLSNR "

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SM_sugo3_FUService]
"ImagePath"="\"C:\Program Files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service"
.
Completion time: 2008-07-04 16:51:39
ComboFix-quarantined-files.txt 2008-07-04 20:51:33

Pre-Run: 7,899,987,968 bytes free
Post-Run: 8,286,609,408 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

235 — E O F — 2008-06-28 14:05:00


HIJACKTHIS.LOG:
————————-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:09:30 PM, on 7/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MIT\Kerberos\bin\leash32.exe
C:\Program Files\MIT\Kerberos\bin\krbcc32s.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {D83A7B12-A4D4-4984-8F72-D41C6B4C1E6E} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Leash Ticket Manager.lnk = C:\Program Files\MIT\Kerberos\bin\leash32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} -
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} -
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} -
O16 - DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF} (JInitiator 1.3.1.17) -
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8671 bytes


LOG.TXT:
—————
ComboFix 08-07-04.1 - Ramesh 2008-07-04 16:33:24.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ramesh\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\#SharedObjects\ALNDCDVL\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Ramesh\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol

.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.

2008-07-03 23:30 . 2008-07-03 23:30 d——– C:\Deckard
2008-06-11 21:59 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 21:59 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 20:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-04 20:17 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\Skype
2008-07-04 03:28 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\AdobeUM
2008-07-03 02:36 ——— d—–w C:\Program Files\Spyware Doctor
2008-06-21 19:39 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-02 08:30 ——— d—–w C:\Program Files\eSoftware
2008-06-02 03:06 ——— d—–w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-02 03:06 ——— d—–w C:\Documents and Settings\Ramesh\Application Data\Malwarebytes
2008-06-02 03:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-30 05:06 34,296 —-a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-30 05:06 15,864 —-a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-05-24 03:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-24 03:18 ——— d—–w C:\Program Files\Lavasoft
2008-05-24 03:17 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 15:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-11 10:53 ——— d—–w C:\Program Files\Trend Micro
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 07:04 659,456 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-21 07:04 615,936 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-04-21 07:04 474,112 —-a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:04 1,494,528 —-a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-17 10:52 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-01-11 00:52 15,186,133 —-a-w C:\Program Files\if3014a.exe
2007-09-07 01:56 6,725,320 —-a-w C:\Program Files\Thunderbird Setup 2.0.0.6.exe
2007-04-07 19:21 20,409,656 —-a-w C:\Program Files\FSS_PH60.exe
2007-03-24 01:00 433,024 —-a-w C:\Program Files\x264.exe
2007-03-24 00:59 3,376,597 —-a-w C:\Program Files\FFDSHOW.exe
2007-03-24 00:49 11,868,792 —-a-w C:\Program Files\winamp533_full_bundle_emusic-7plus.exe
2007-03-21 01:07 12,307,656 —-a-w C:\Program Files\wdviewer.exe
2007-03-06 02:43 5,111,302 —-a-w C:\Program Files\CricketStreamZSetup.exe
2007-03-04 19:50 61,139,088 —-a-w C:\Program Files\Quicken_Basic_2007.exe
2006-01-28 14:09 44,592 —-a-w C:\Documents and Settings\Ramesh\Application Data\GDIPFONTCACHEV1.DAT
2005-05-26 22:17 1,973 —-a-w C:\Program Files\Installation and user guide.txt
2004-01-02 17:18 868,291 —-a-r C:\Program Files\DigtalSignatureVerifierSetup.exe
2003-08-05 16:41 53,248 —-a-w C:\WINDOWS\inf\ap561.exe
2002-11-26 21:24 32,768 —-a-w C:\WINDOWS\inf\Remove561.exe
2002-11-22 20:56 118,784 —-a-w C:\WINDOWS\inf\ShowBmp.exe
2002-10-29 23:07 36,864 —-a-w C:\WINDOWS\inf\Setup8a.exe
2002-10-01 19:43 119,798 —-a-w C:\WINDOWS\inf\spca561.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 110,592 2003-08-19 08:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

—-a-w 49,152 2005-02-17 04:11:42 C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe

—-a-w 49,152 2003-05-23 03:03:16 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe

—-a-w 208,958 2004-04-30 17:32:46 C:\Program Files\HPQ\Default Settings\bak\cpqset.exe

—-a-w 286,720 2004-07-30 15:33:44 C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe

—-a-w 256,576 2006-10-30 14:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\iTunes\iTunesHelper.exe

—-a-w 49,263 2006-10-12 08:10:54 C:\Program Files\Java\jre1.5.0_09\bin\bak\jusched.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

—-a-w 282,624 2006-10-25 23:58:18 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\QuickTime\qttask.exe

—-a-w 1,773,568 2007-03-07 14:58:20 C:\Program Files\support.com\bin\bak\tgcmd.exe

—-a-w 536,576 2004-05-26 17:15:16 C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe

—-a-w 98,304 2004-05-26 17:15:42 C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe

—-a-w 35,328 2007-02-13 18:29:00 C:\Program Files\Winamp\bak\winampa.exe
—-a-w 14,348 2008-02-27 16:38:56 C:\Program Files\Winamp\winampa.exe

—-a-w 4,670,968 2007-03-27 19:22:56 C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE

—-a-w 507,904 2006-02-14 23:32:14 C:\WINDOWS\Samsung\PanelMgr\bak\ssmmgr.exe

—-a-w 15,360 2004-08-04 08:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-04 13:00:00 C:\WINDOWS\system32\ctfmon.exe

—-a-w 118,784 2003-10-30 08:33:50 C:\WINDOWS\system32\bak\hkcmd.exe

—-a-w 483,328 2003-05-23 02:55:38 C:\WINDOWS\system32\bak\hphmon05.exe

—-a-w 155,648 2003-10-30 08:46:52 C:\WINDOWS\system32\bak\igfxtray.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:00 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [N/A]

C:\Documents and Settings\Suja\Start Menu\Programs\Startup\
WKCALREM.LNK.disabled [2005-05-23 09:21:26 930]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Leash Ticket Manager.lnk - C:\Program Files\MIT\Kerberos\bin\leash32.exe [2004-09-17 02:53:54 770048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 04:15:54 65588]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ramesh^Start Menu^Programs^Startup^Password Safe.lnk]
path=C:\Documents and Settings\Ramesh\Start Menu\Programs\Startup\Password Safe.lnk
backup=C:\WINDOWS\pss\Password Safe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]
[X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-27 12:38 14348 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-10-25 19:58 282624 C:\Program Files\QuickTime\bak\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
C:\Program Files\Support.com\bin\tgcmd.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-02-27 12:38 14348 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CVPND"=2 (0x2)
"AOL ACS"=2 (0x2)
"OracleServiceDB1"=2 (0x2)
"OracleOraWBClientCache"=3 (0x3)
"OracleOraToolsClientCache"=3 (0x3)
"OracleOraHome10TNSListener"=2 (0x2)
"OracleOraHome10SNMPPeerMasterAgent"=3 (0x3)
"OracleOraHome10SNMPPeerEncapsulator"=3 (0x3)
"OracleOraHome10iSQL*Plus"=2 (0x2)
"OracleOraComp10ProcessManager"=2 (0x2)
"OracleDBConsoleDB1"=2 (0x2)
"OracleCSService"=2 (0x2)
"iPod Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\jre\\bin\\java.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\bin\\java.exe"=
"C:\\Program Files\\Java\\jdk1.5.0_06\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\OPNET EDU\\9.1.A\\sys\\pc_intel_win32\\bin\\itguru.exe"=
"C:\\oracle\\product\\10.1.0\\OraHome10\\jdk\\jre\\bin\\java.exe"=
"C:\\oracle\\product\\10.1.0\\OraHome10\\jdk\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S3 SM_sugo3_FUService;sugo3 Status Monitor Service;"C:\Program Files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service []
S4 OracleCSService;OracleCSService;C:\oracle\product\10.1.0\OraHome10\bin\ocssd.exe service []
S4 OracleDBConsoleDB1;OracleDBConsoleDB1;C:\oracle\product\10.1.0\OraHome10\bin\nmesrvc.exe [2004-03-05 00:33]
S4 OracleJobSchedulerDB1;OracleJobSchedulerDB1;c:\oracle\product\10.1.0\orahome10\Bin\extjob.exe DB1 []
S4 OracleOraComp10ProcessManager;OracleOraComp10ProcessManager;C:\oracle\product\10.1.0\OraComp10\opmn\bin\opmn.exe [2004-03-05 04:03]
S4 OracleOraHome10iSQL*Plus;OracleOraHome10iSQL*Plus;C:\oracle\product\10.1.0\OraHome10\bin\isqlplussvc.exe [2006-12-31 12:30]
S4 OracleOraHome10SNMPPeerEncapsulator;OracleOraHome10SNMPPeerEncapsulator;C:\oracle\product\10.1.0\OraHome10\BIN\ENCSVC.EXE [2006-12-31 12:33]
S4 OracleOraHome10SNMPPeerMasterAgent;OracleOraHome10SNMPPeerMasterAgent;C:\oracle\product\10.1.0\OraHome10\BIN\AGNTSVC.EXE [2006-12-31 12:33]
S4 OracleOraHome10TNSListener;OracleOraHome10TNSListener;C:\oracle\product\10.1.0\OraHome10\BIN\TNSLSNR []
S4 OracleOraToolsClientCache;OracleOraToolsClientCache;c:\OraTools\BIN\ONRSD.EXE [2004-03-24 14:50]
S4 OracleOraWBClientCache;OracleOraWBClientCache;c:\oraWB\BIN\ONRSD.EXE [2002-04-26 20:34]
S4 OracleServiceDB1;OracleServiceDB1;c:\oracle\product\10.1.0\orahome10\bin\ORACLE.EXE DB1 []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19d51ec4-f9cf-11db-ac3a-00904bb919e4}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 10:37:32 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-05-01 05:00:20 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-04 16:43:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome10TNSListener]
"ImagePath"="C:\oracle\product\10.1.0\OraHome10\BIN\TNSLSNR "

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SM_sugo3_FUService]
"ImagePath"="\"C:\Program Files\Samsung\Samsung ML-2510 Series\SPanel\ssmsrvc /Service"
.
Completion time: 2008-07-04 16:51:39
ComboFix-quarantined-files.txt 2008-07-04 20:51:33

Pre-Run: 7,899,987,968 bytes free
Post-Run: 8,286,609,408 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

235 — E O F — 2008-06-28 14:05:00
Hi

Seeing as you have McAfee installed, you still need to remove the Norton/Symantec leftovers. Use the link below to see how to run the Norton Removal Tool
http://service1.symantec.com/SUPPORT/tsgen…005033108162039



Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\Program Files\if3014a.exe

Folder::
C:\Program Files\eSoftware

AWF::
C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
C:\Program Files\HPQ\Default Settings\bak\cpqset.exe
C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe
C:\Program Files\iTunes\bak\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_09\bin\bak\jusched.exe
C:\Program Files\QuickTime\bak\qttask.exe
C:\Program Files\support.com\bin\bak\tgcmd.exe
C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe
C:\Program Files\Winamp\bak\winampa.exe
C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE
C:\WINDOWS\Samsung\PanelMgr\bak\ssmmgr.exe
C:\WINDOWS\system32\bak\ctfmon.exe
C:\WINDOWS\system32\bak\hkcmd.exe
C:\WINDOWS\system32\bak\hphmon05.exe
C:\WINDOWS\system32\bak\igfxtray.exe

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.


Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet and disable your anti-virus, to reduce scanning time. Re-enable the anti-virus before reconnecting to the Internet.
Instructions on disabling a variety of security programs can be found at the link below.

http://www.bleepingcomputer.com/forums/topic114351.html

In your next reply post:
ComboFix.txt
Kaspersky report
New HijackThis log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI