View Single Post
Old 05-24-2008, 05:53 PM   #5 (permalink)
stunner07
Registered User
 
Join Date: May 2008
Posts: 8
OS: xp


Re: i think i have the virus virtumonde...?

hey thanks tetonbob, but i couldt find WebVideo Support, but did delete error smart thanks, heres the log from combo fix.



ComboFix 08-05-21.3 - ShAnE 2008-05-25 9:43:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.212 [GMT 9.5:30]
Running from: C:\Documents and Settings\ShAnE\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\byndfbmj.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wxwotlga.ini
C:\WINDOWS\system32\Xxwxxyay.ini
C:\WINDOWS\system32\Xxwxxyay.ini2

.
((((((((((((((((((((((((( Files Created from 2008-04-25 to 2008-05-25 )))))))))))))))))))))))))))))))
.

2008-05-25 09:01 . 2008-05-25 09:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-21 10:08 . 2008-05-21 10:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-21 10:06 . 2008-05-21 10:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-21 10:06 . 2008-05-21 10:06 <DIR> d-------- C:\Documents and Settings\ShAnE\Application Data\SUPERAntiSpyware.com
2008-05-18 21:14 . 2007-08-10 20:46 33,656 --a------ C:\WINDOWS\system32\sprecovr.exe
2008-05-18 21:09 . 2002-08-29 21:30 13,463,552 --a------ C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-18 20:47 . 2006-12-29 04:31 19,569 --a------ C:\WINDOWS\005782_.tmp
2008-05-18 20:19 . 2008-05-18 20:53 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-18 05:23 . 2008-05-25 09:07 <DIR> d-------- C:\Program Files\ErrorSmart
2008-05-18 03:10 . 2008-05-18 05:37 <DIR> d-------- C:\Documents and Settings\ShAnE\Application Data\ErrorSmart
2008-05-17 07:40 . 2008-05-17 07:41 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVGTOOLBAR
2008-05-17 06:20 . 2008-05-17 06:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-05-17 05:39 . 2008-05-25 09:36 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 05:38 . 2008-05-17 06:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-05-17 05:38 . 2008-05-17 05:38 <DIR> d-------- C:\Documents and Settings\ShAnE\Application Data\PC Tools
2008-05-17 05:38 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-05-17 05:38 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-05-17 05:38 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-05-17 05:38 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-05-16 21:43 . 2008-05-16 21:43 <DIR> d-------- C:\Deckard
2008-05-16 06:28 . 2008-05-16 06:29 <DIR> d-------- C:\Program Files\Panda Security
2008-05-15 07:13 . 2008-05-15 07:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-15 04:55 . 2008-05-20 15:46 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-15 04:51 . 2008-05-15 04:51 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-15 04:51 . 2008-05-15 04:51 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-15 04:50 . 2008-05-24 20:46 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-15 04:50 . 2008-05-15 04:50 <DIR> d-------- C:\Program Files\AVG
2008-05-15 04:50 . 2008-05-17 05:43 <DIR> d-------- C:\Documents and Settings\ShAnE\Application Data\AVGTOOLBAR
2008-05-15 04:50 . 2008-05-15 04:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-15 04:50 . 2008-05-15 04:50 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-15 02:52 . 2008-05-15 07:14 870 ---hs---- C:\WINDOWS\system32\rxqlkqgn.ini
2008-05-15 02:44 . 2008-05-17 05:20 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-13 18:10 . 2008-05-13 18:10 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-13 18:10 . 2008-05-13 18:10 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-05-12 04:31 . 2008-05-12 04:31 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-05-12 04:31 . 2008-05-12 04:31 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-05-12 04:29 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-05-12 04:28 . 2008-05-12 04:28 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-05-12 04:27 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-12 04:27 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-05-12 04:27 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-05-12 04:27 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-05-12 04:27 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-05-12 04:27 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-05-06 22:09 . 2008-05-06 22:09 <DIR> d-------- C:\Program Files\Google
2008-05-05 14:43 . 2008-05-16 03:19 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-05 14:43 . 2008-05-05 14:43 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-29 22:25 . 2007-12-20 00:13 68,672 -ra------ C:\WINDOWS\system32\drivers\2WirePCP.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 08:18 --------- d-----w C:\Program Files\Full Tilt Poker
2008-05-22 05:49 --------- d-----w C:\Program Files\PokerStars
2008-05-21 00:35 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 11:09 --------- d-----w C:\Program Files\Pogo Games
2008-05-16 01:41 --------- d-----w C:\Program Files\Lavasoft
2008-05-16 01:41 --------- d-----w C:\Documents and Settings\ShAnE\Application Data\Lavasoft
2008-05-15 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-15 20:46 --------- d-----w C:\Program Files\Viewpoint
2008-05-15 20:41 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-15 15:32 --------- d-----w C:\Program Files\Cheat Engine
2008-05-15 13:06 --------- d-----w C:\Program Files\Holdem Indicator
2008-05-15 13:00 --------- d--h--r C:\Documents and Settings\All Users\Application Data\yahoo!
2008-05-15 13:00 --------- d-----w C:\Program Files\Yahoo!
2008-05-15 12:57 --------- d-----w C:\Program Files\Pogo Auto loader
2008-05-14 19:33 --------- d-----w C:\Documents and Settings\ShAnE\Application Data\AdobeUM
2008-05-11 19:01 --------- d-----w C:\Program Files\Nokia
2008-05-11 18:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-05-08 13:42 --------- d-----w C:\Documents and Settings\ShAnE\Application Data\Nokia
2008-04-23 08:36 --------- d-----w C:\Program Files\LimeWire
2008-04-18 01:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Emotum
2008-04-18 01:07 --------- d-----w C:\Program Files\DIFX
2008-04-18 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-28 14:27 --------- d-----w C:\Program Files\Ability Office 2002
2006-04-08 10:25 917,788 ----a-w C:\Documents and Settings\ShAnE\HandRankings2.Dat
2006-04-08 10:25 11,156 ----a-w C:\Documents and Settings\ShAnE\Cards.Dat
2005-11-05 06:18 613,728 ----a-w C:\Documents and Settings\ShAnE\ShotIndex.Dat
2005-01-22 06:04 457 ----a-w C:\Program Files\INSTALL.LOG
2004-12-18 18:14 4 ----a-w C:\Documents and Settings\ShAnE\game.dat
2005-09-15 13:36 80 --sh--r C:\WINDOWS\system32\C2D80706A3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-15 04:50 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-15 04:50 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-15 04:50 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:26 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-13 12:43 1510640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HI-SPEED USB DEVICE Coinstaller"="PL15Co2K.exe" [2003-07-10 16:59 86016 C:\WINDOWS\PL15Co2K.exe]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-30 19:10 28672]
"SoundMan"="SOUNDMAN.EXE" [2002-09-11 12:27 46592 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\system32\nwiz.exe]
"AME_CSA"="amecsa.cpl" [2004-09-10 19:25 757760 C:\WINDOWS\system32\AmeCSA.cpl]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 40960 C:\WINDOWS\ltmsg.exe]
"FastTVSync"="C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe" [2004-03-11 02:55 245760]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-06-04 21:03 1400944]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-19 00:05 684032]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"hffsrv"="c:\windows\hffext\hffsrv.exe" [2005-05-04 00:58 82432]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-01 04:09 282624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-13 02:17 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-15 04:50 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-22 13:00:46 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
InterVideo Scheduler server.lnk - C:\Program Files\InterVideo\DVD5R\SchSvr.exe [2005-02-16 18:50:48 147456]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:35:56 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FDCENT.SYS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HideFilesAndFolders_S]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\SurfAnonymous\\SurfAnonymous.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\VINCO\\VOG2\\vogshell.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-15 04:50]
R1 FDCENT;FDCENT;C:\WINDOWS\system32\drivers\FDCENT.SYS [2005-03-04 15:08]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-15 04:50]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-15 04:50]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-15 04:51]
R2 PLQ0306270;Prolific HotFix Q0306270;C:\WINDOWS\System32\HotFixQ0306270.exe [2003-07-02 22:20]
R3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys [2007-12-20 00:13]
R3 WMIBIOS;%WMIBIOS.ServiceName%;C:\WINDOWS\system32\Drivers\wmibios.sys [2002-10-15 21:33]
R3 WMIINFO;WMIINFO Driver;C:\WINDOWS\system32\Drivers\wmiinfo.sys [2002-05-13 20:16]
S3 AmeAtmPc;AmeAtmPc;C:\WINDOWS\system32\DRIVERS\AmeAtmPc.sys [2004-09-10 19:25]
S3 AtmElan;ATM Emulated LAN;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-04 15:28]
S3 AtmLane;ATM LAN Emulation;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-04 15:28]
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2001-08-17 12:19]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2007-12-20 00:13]
S3 ulusba;NEC 616 Command Port Driver;C:\WINDOWS\system32\DRIVERS\ulusba.sys [2003-06-22 23:30]
S3 ulusbc;NEC 616 CONTROL Driver;C:\WINDOWS\system32\DRIVERS\ulusbc.sys [2003-06-22 23:30]
S3 ulusbe;NEC 616 ENUMERATION Driver;C:\WINDOWS\system32\DRIVERS\ulusbe.sys [2003-06-22 23:30]
S3 ulusbm;NEC 616 Modem Driver;C:\WINDOWS\system32\DRIVERS\ulusbm.sys [2003-06-22 23:30]
S3 ulusbo;NEC 616 OBEX Port Driver;C:\WINDOWS\system32\DRIVERS\ulusbo.sys [2003-07-23 23:30]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-05-25 00:30:03 C:\WINDOWS\Tasks\ACD53933918AAB57.job"
- c:\progra~1\messhe~1\RefDogSkip.exe
"2008-05-24 23:08:40 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Program Files\ErrorSmart\ErrorSmart.ex
- C:\Program Files\ErrorSmart
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-25 09:57:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-25 10:12:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-25 00:41:09

Pre-Run: 32,376,451,072 bytes free
Post-Run: 33,091,981,312 bytes free

238 --- E O F --- 2008-05-17 17:00:49
stunner07 is offline   Reply With Quote