View Single Post
Old 08-07-2007, 12:14 PM   #7 (permalink)
andrew.bennett
Registered User
 
Join Date: Aug 2007
Posts: 12
OS: Win XP


Re: Problems with Trojan: Win32/Virtumonde.0

Code:
2003-01-30 13:52      12073    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\FAD.sys.vir
2005-10-10 19:29      510    --a------    C:\Qoobox\Quarantine\C\WINDOWS\Unist1.htm.vir
2006-09-15 17:22      480    --a------    C:\Qoobox\Quarantine\C\WINDOWS\Uninst2.htm.vir
2007-04-24 12:21      9248    --a------    C:\Qoobox\Quarantine\C\Temp\0c2\tmpFF.log.vir
2007-06-25 09:54      53248    --a------    C:\Qoobox\Quarantine\C\WINDOWS\uni_eh44.exe.vir
2007-07-20 13:04      270336    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\X9\wb720.exe.vir
2007-08-01 10:38      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\byxyxxv.dll.vir
2007-08-01 10:38      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\tuvwvww.dll.vir
2007-08-01 10:43      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\jkkjghh.dll.vir
2007-08-01 10:48      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\cbxxwtr.dll.vir
2007-08-01 10:57      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\vtuurpo.dll.vir
2007-08-01 10:58      20    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode.vir
2007-08-01 10:58      5    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr.vir
2007-08-01 10:59      0    --a------    C:\Qoobox\Quarantine\C\Program Files\Common Files\WinAntiSpyware 2007\err.log.vir
2007-08-01 10:59      1814    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\MailRoom\APPLIC~1\WinAntiSpyware 2007\Logs\update.log.vir
2007-08-01 11:03      31254    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\ljjiheb.dll.vir
2007-08-02 08:22      30208    --a------    C:\Qoobox\Quarantine\C\WINDOWS\csrss.exe.vir
2007-08-02 08:23      1236    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\ldinfo.ldr.vir
2007-08-02 08:23      16    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\LOCALS~1\APPLIC~1\.rdr.ini.vir
2007-08-02 08:23      16    --a------    C:\Qoobox\Quarantine\C\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini.vir
2007-08-02 08:23      930    --a------    C:\Qoobox\Quarantine\C\Temp\brr\tmpZTF.log.vir
2007-08-02 08:23      932    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\winpfz32.sys.vir
2007-08-02 08:25      69184    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\muxxdvdt.dll.vir
2007-08-02 08:35      221    --a------    C:\Qoobox\Quarantine\C\WINDOWS\wr.txt.vir
2007-08-02 09:43      282624    --a------    C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\meqocan4444.dll.vir
2007-08-02 11:25      169147    --a------    C:\Qoobox\Quarantine\C\WINDOWS\TTC-4444.exe.vir
2007-08-06 08:27      228960    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\awtsq.dll.vir
2007-08-06 08:27      6467    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\qstwa.bak1.vir
2007-08-06 08:34      6632    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\qstwa.tmp.vir
2007-08-06 10:04      8199    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\qstwa.ini.vir
2007-08-07 11:15      125504    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lviyfqri.dll.vir
2007-08-07 11:15      345    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\irqfyivl.ini.vir
2007-08-07 12:03      1757796    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\qstwa.bak2.vir
2007-08-07 12:12      125504    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lgegjevg.dll.vir
2007-08-07 13:18      1190868    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\gvejgegl.ini.vir
2007-08-07 13:21      1763370    --a------    C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\qstwa.ini2.vir
2007-08-07 13:21      2242    --a------    C:\Qoobox\Quarantine\Registry_backups\services_ApiMon.reg.cf
2007-08-07 13:21      352    --a------    C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf
2007-08-07 13:22      237860    --a------    C:\Qoobox\Quarantine\catchme2007-08-07_133647.12.zip
2007-08-07 13:22      309    --a------    C:\Qoobox\Quarantine\catchme.log


Folder PATH listing
Volume serial number is 4CD0-5004
C:\QOOBOX
\---Quarantine
    |   catchme.log
    |   catchme2007-08-07_133647.12.zip
    |   
    +---C
    |   +---DOCUME~1
    |   |   +---ALLUSE~1
    |   |   |   \---APPLIC~1
    |   |   |       \---WinAntiSpyware 2007
    |   |   |           \---Data
    |   |   |                   Abbr.vir
    |   |   |                   ProductCode.vir
    |   |   |                   
    |   |   +---LOCALS~1
    |   |   |   \---APPLIC~1
    |   |   |           .rdr.ini.vir
    |   |   |           
    |   |   +---MailRoom
    |   |   |   \---APPLIC~1
    |   |   |       \---WinAntiSpyware 2007
    |   |   |           \---Logs
    |   |   |                   update.log.vir
    |   |   |                   
    |   |   \---NETWOR~1
    |   |       \---APPLIC~1
    |   |               .rdr.ini.vir
    |   |               
    |   +---Program Files
    |   |   +---Common Files
    |   |   |   \---WinAntiSpyware 2007
    |   |   |           err.log.vir
    |   |   |           
    |   |   \---Internet Explorer
    |   |           meqocan4444.dll.vir
    |   |           
    |   +---Temp
    |   |   +---0c2
    |   |   |       tmpFF.log.vir
    |   |   |       
    |   |   \---brr
    |   |           tmpZTF.log.vir
    |   |           
    |   \---WINDOWS
    |       |   csrss.exe.vir
    |       |   TTC-4444.exe.vir
    |       |   Uninst2.htm.vir
    |       |   Unist1.htm.vir
    |       |   uni_eh44.exe.vir
    |       |   wr.txt.vir
    |       |   
    |       \---SYSTEM32
    |           |   awtsq.dll.vir
    |           |   byxyxxv.dll.vir
    |           |   cbxxwtr.dll.vir
    |           |   gvejgegl.ini.vir
    |           |   irqfyivl.ini.vir
    |           |   jkkjghh.dll.vir
    |           |   ldinfo.ldr.vir
    |           |   lgegjevg.dll.vir
    |           |   ljjiheb.dll.vir
    |           |   lviyfqri.dll.vir
    |           |   muxxdvdt.dll.vir
    |           |   qstwa.bak1.vir
    |           |   qstwa.bak2.vir
    |           |   qstwa.ini.vir
    |           |   qstwa.ini2.vir
    |           |   qstwa.tmp.vir
    |           |   tuvwvww.dll.vir
    |           |   vtuurpo.dll.vir
    |           |   winpfz32.sys.vir
    |           |   
    |           +---DRIVERS
    |           |       FAD.sys.vir
    |           |       
    |           \---X9
    |                   wb720.exe.vir
    |                   
    \---Registry_backups
            services_ApiMon.reg.cf
            services_nm.reg.cf
andrew.bennett is offline