![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: Windows XP Professional SP 3
|
[SOLVED] Help with Vundo!grb
Starting about two days ago, I've been getting repeated McAfee notifications about Vundo!grb on my machine. McAfee reports that the following have been repaired (removed):
C:\WINDOWS\system32\ojipokul.tmp C:\WINDOWS\system32\agizuwek.tmp C:\WINDOWS\system32\orenopob.tmp Since this started, I have also been getting repeated popup ad windows in Firefox, despite having popups disabled. DDS.txt is below. Thanks for your help! DDS (Ver_09-03-16.01) - NTFSx86 Run by Dave at 7:12:12.64 on Tue 04/28/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1344 [GMT -7:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) FW: McAfee Personal Firewall *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\Explorer.EXE c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Dave.COOLWHIP\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: {2323ae2f-ecc6-40ac-a3b8-3bebb0de543c} - c:\windows\system32\tevaziva.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Stylus C88 @ dnabook] c:\windows\system32\spool\drivers\w32x86\3\E_FATIABA.EXE /P20 "Stylus C88 @ dnabook" /O44 "http://dnabook.local:631/printers/Stylus_C88" /M "Stylus C88" mRun: [Stylus C88 @ dnabook (2)] c:\windows\system32\spool\drivers\w32x86\3\E_FATIABA.EXE /P24 "Stylus C88 @ dnabook (2)" /O44 "http://dnabook.local:631/printers/Stylus_C88" /M "Stylus C88" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [CinemaNowMediaManagerApp] c:\program files\cinemanow\CinemaNowShell.exe -start mRun: [vahavemaka] Rundll32.exe "c:\windows\system32\batujuko.dll",s mRun: [48311ff3] rundll32.exe "c:\windows\system32\boponero.dll",b mRun: [CPM4b022c6f] Rundll32.exe "c:\windows\system32\nukatojo.dll",a StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: cinemanow.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\windows\system32\woyobizi.dll c:\windows\system32\nukatojo.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nukatojo.dll STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\nukatojo.dll LSA: Notification Packages = scecli c:\windows\system32\woyobizi.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\dave~1.coo\applic~1\mozilla\firefox\profiles\vu5z11y7.default\ FF - plugin: c:\documents and settings\dave.coolwhip\application data\mozilla\firefox\profiles\vu5z11y7.default\extensions\{3112ca9c-de6d-4884-a869-9855de680400}\plugins\npCinemaNowPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-21 201320] R2 CinemaNow Service;CinemaNow Service;c:\program files\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2009-3-11 125304] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-3-21 359248] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-3-21 144704] R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-3-21 695624] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-21 79304] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-21 35240] R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-21 40488] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-21 33832] =============== Created Last 30 ================ 2009-04-26 20:25 383 ---sh--- c:\windows\system32\popujubi.exe 2009-04-26 18:50 <DIR> --d----- c:\program files\Airfoil 2009-04-26 13:54 221,184 a------- c:\windows\system32\wmpns.dll 2009-04-26 13:53 <DIR> --d----- c:\program files\Windows Media Connect 2 2009-04-26 13:47 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\CinemaNow 2009-04-26 13:47 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\My Videos 2009-04-26 13:47 <DIR> --d----- C:\DocumenStart Menu 2009-04-26 13:47 <DIR> --d----- C:\DocumenDesktop 2009-04-26 13:47 <DIR> --d----- c:\program files\CinemaNow 2009-04-23 21:02 410,984 a------- c:\windows\system32\deploytk.dll 2009-04-23 21:02 73,728 a------- c:\windows\system32\javacpl.cpl 2009-04-18 21:12 <DIR> --d----- c:\program files\Klimb 2009-04-16 07:11 <DIR> --d----- c:\program files\MSECache 2009-04-15 14:34 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb 2009-04-15 14:34 2,560 -------- c:\windows\system32\xpsp4res.dll 2009-04-15 14:34 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe 2009-04-15 14:33 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll 2009-04-15 14:33 284,160 -c------ c:\windows\system32\dllcache\pdh.dll 2009-04-15 14:33 110,592 -c------ c:\windows\system32\dllcache\services.exe 2009-04-15 14:33 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 14:33 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll 2009-04-15 14:33 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll 2009-04-15 14:33 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll 2009-04-15 14:33 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 14:33 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe 2009-04-11 18:36 162,512 a------- c:\windows\system32\AirfoilInject3.dll 2009-04-07 16:10 <DIR> --d----- c:\program files\EPSON 2009-04-07 16:10 309,760 a------- c:\windows\system32\EAL32.DLL 2009-04-07 16:10 79,679 a------- c:\windows\system32\E_FLMABA.DLL 2009-04-07 16:10 64,000 a------- c:\windows\system32\E_FBCBABA.DLL 2009-04-07 16:10 34,304 a------- c:\windows\system32\E_FBCHABA.DLL 2009-04-07 16:10 51 a------- c:\windows\system32\EAL32.INI 2009-04-07 16:10 82,944 a------- c:\windows\system32\EAL.EXE 2009-04-07 16:04 <DIR> --d----- c:\program files\Bonjour ==================== Find3M ==================== 2009-04-28 06:32 104,960 a--sh--- c:\windows\system32\nukatojo.dll 2009-04-28 06:32 97,792 a--sh--- c:\windows\system32\boponero.dll 2009-04-27 18:32 98,816 -------- c:\windows\system32\kewuziga.dll 2009-04-27 18:32 105,472 a--sh--- c:\windows\system32\yovorize.dll 2009-04-27 18:32 59,904 a--sh--- c:\windows\system32\dutuhabe.exe 2009-04-26 20:25 98,816 -------- c:\windows\system32\lukopijo.dll 2009-04-26 20:25 104,960 a--sh--- c:\windows\system32\wisebiga.dll 2009-04-26 20:25 60,928 a--sh--- c:\windows\system32\begimepo.exe 2009-03-21 09:53 87,263 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-03-21 08:06 5 a------- c:\windows\system32\drivers\DELL_XPS_MM061 .MRK 2009-03-21 08:06 5 a------- c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK 2009-03-20 23:19 21,640 a------- c:\windows\system32\emptyregdb.dat 2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll 2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll 2009-02-20 11:09 78,336 a------- c:\windows\system32\ieencode.dll 2009-02-09 05:10 729,088 a------- c:\windows\system32\lsasrv.dll 2009-02-09 05:10 714,752 a------- c:\windows\system32\ntdll.dll 2009-02-09 05:10 617,472 a------- c:\windows\system32\advapi32.dll 2009-02-09 05:10 401,408 a------- c:\windows\system32\rpcss.dll 2009-02-09 04:13 1,846,784 a------- c:\windows\system32\win32k.sys 2009-02-06 04:11 110,592 a------- c:\windows\system32\services.exe 2009-02-06 04:06 2,145,280 a------- c:\windows\system32\ntoskrnl.exe 2009-02-06 03:39 35,328 a------- c:\windows\system32\sc.exe 2009-02-06 03:32 2,023,936 a------- c:\windows\system32\ntkrnlpa.exe 2009-02-03 12:59 56,832 a------- c:\windows\system32\secur32.dll 2009-01-26 20:19 67,072 a--sh--- c:\windows\system32\batujuko.dll 2009-01-26 20:19 67,072 a--sh--- c:\windows\system32\tevaziva.dll 2009-01-26 20:19 67,072 a--sh--- c:\windows\system32\woyobizi.dll ============= FINISH: 7:14:21.71 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Help with Vundo!grb
Hello, and welcome to TSF.
I am currently reviewing your log. I will be back with a fix for your problem as soon as possible. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Please be patient with me during this time. |
|
|
|
|
#3 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Help with Vundo!grb
Hi parrishioner,
Please do the following: Download ComboFix from one of these locations: Link 1 Link 2 Link 3 VERY IMPORTANT !!! Save ComboFix.exe to your Desktop * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, (McAfee & System Guard) via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
![]()
![]()
Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: Windows XP Professional SP 3
|
Re: Help with Vundo!grb
Thanks for the reply. I successfully ran ComboFix and everything seems to be back to normal. Here's the log:
ComboFix 09-04-28.02 - Dave 04/28/2009 17:41.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1339 [GMT -7:00] Running from: c:\documents and settings\Dave.COOLWHIP\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) FW: McAfee Personal Firewall *enabled* * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\windows\system32\batujuko.dll c:\windows\system32\boponero.dll c:\windows\system32\kewuziga.dll c:\windows\system32\lukopijo.dll c:\windows\system32\nukatojo.dll c:\windows\system32\orenopob.ini c:\windows\system32\popujubi.exe c:\windows\system32\tevaziva.dll c:\windows\system32\wisebiga.dll c:\windows\system32\woyobizi.dll c:\windows\system32\yovorize.dll ----- BITS: Possible infected sites ----- hxxp://216.12.168.130 . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-29 ))))))))))))))))))))))))))))))) . 2009-04-27 01:51 . 2009-04-27 01:51 -------- d-----w c:\documents and settings\Dave.COOLWHIP\Local Settings\Application Data\Rogue_Amoeba 2009-04-27 01:50 . 2009-04-27 01:50 -------- d-----w c:\program files\Airfoil 2009-04-26 20:54 . 2008-04-14 00:12 221184 ----a-w c:\windows\system32\wmpns.dll 2009-04-26 20:53 . 2009-04-26 20:53 -------- d-----w c:\program files\Windows Media Connect 2 2009-04-26 20:52 . 2009-04-26 20:53 -------- d-----w c:\windows\system32\drivers\UMDF 2009-04-26 20:47 . 2009-04-26 20:48 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\CinemaNow 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\My Videos 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w C:\DocumenStart Menu 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w C:\DocumenDesktop 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w c:\program files\CinemaNow 2009-04-24 04:02 . 2009-04-24 04:02 -------- d-----w c:\windows\Sun 2009-04-24 04:02 . 2009-04-24 04:01 410984 ----a-w c:\windows\system32\deploytk.dll 2009-04-24 04:01 . 2009-04-24 04:01 -------- d-----w c:\program files\Java 2009-04-19 04:12 . 2009-04-19 04:14 -------- d-----w c:\program files\Klimb 2009-04-16 14:11 . 2009-04-16 14:11 -------- d-----w c:\program files\MSECache 2009-04-15 21:34 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll 2009-04-15 21:34 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe 2009-04-15 21:33 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll 2009-04-15 21:33 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll 2009-04-15 21:33 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe 2009-04-15 21:33 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll 2009-04-15 21:33 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 21:33 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 21:33 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 21:33 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll 2009-04-15 21:33 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll 2009-04-12 01:36 . 2009-04-12 01:36 162512 ----a-w c:\windows\system32\AirfoilInject3.dll 2009-04-07 23:10 . 2009-04-07 23:10 -------- d-----w c:\program files\EPSON 2009-04-07 23:10 . 2003-05-21 09:27 64000 ----a-w c:\windows\system32\E_FBCBABA.DLL 2009-04-07 23:10 . 2004-11-25 12:07 79679 ----a-w c:\windows\system32\E_FLMABA.DLL 2009-04-07 23:10 . 2000-06-07 08:01 34304 ----a-w c:\windows\system32\E_FBCHABA.DLL 2009-04-07 23:10 . 2004-06-24 08:20 309760 ----a-w c:\windows\system32\EAL32.DLL 2009-04-07 23:10 . 2004-03-12 08:30 82944 ----a-w c:\windows\system32\EAL.EXE 2009-04-07 23:04 . 2009-04-07 23:04 -------- d-----w c:\program files\Bonjour 2009-04-03 05:39 . 2009-04-03 05:39 -------- d-----w c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Apple . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-28 01:32 . 2009-01-28 01:32 59904 --sha-w c:\windows\system32\dutuhabe.exe 2009-04-27 03:25 . 2009-01-27 03:25 60928 --sha-w c:\windows\system32\begimepo.exe 2009-04-27 01:51 . 2009-03-21 16:32 22904 ----a-w c:\documents and settings\Dave.COOLWHIP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-21 04:41 . 2009-03-21 19:20 -------- d-----w c:\program files\McAfee 2009-04-15 00:50 . 2009-03-21 15:06 -------- d-----w c:\program files\Common Files\InstallShield 2009-03-23 19:26 . 2009-03-23 19:25 -------- d-----w c:\program files\iTunes 2009-03-23 19:25 . 2009-03-23 19:25 -------- d-----w c:\program files\iPod 2009-03-23 19:25 . 2009-03-23 19:23 -------- d-----w c:\program files\Common Files\Apple 2009-03-23 19:25 . 2009-03-23 19:24 -------- d-----w c:\program files\QuickTime 2009-03-23 19:24 . 2009-03-23 19:24 -------- d-----w c:\program files\Apple Software Update 2009-03-22 01:17 . 2009-03-22 01:15 -------- d-----w c:\program files\Common Files\Adobe 2009-03-21 19:40 . 2009-03-21 19:40 -------- d-----w c:\program files\Microsoft.NET 2009-03-21 19:40 . 2009-03-21 19:40 -------- d-----w c:\program files\Microsoft ActiveSync 2009-03-21 19:21 . 2009-03-21 19:20 -------- d-----w c:\program files\Common Files\McAfee 2009-03-21 19:20 . 2009-03-21 19:20 -------- d-----w c:\program files\McAfee.com 2009-03-21 17:10 . 2009-03-21 05:35 -------- d-----w c:\program files\Dell 2009-03-21 17:10 . 2009-03-21 17:10 -------- d-----w c:\program files\CONEXANT 2009-03-21 17:09 . 2009-03-21 17:09 -------- d-----w c:\program files\Digital Line Detect 2009-03-21 17:09 . 2009-03-21 17:00 -------- d--h--w c:\program files\InstallShield Installation Information 2009-03-21 17:06 . 2009-03-21 17:06 0 ----a-w c:\windows\nsreg.dat 2009-03-21 17:03 . 2009-03-21 17:03 -------- d-----w c:\program files\SigmaTel 2009-03-21 16:53 . 2009-03-21 06:21 87263 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-03-21 16:48 . 2009-03-21 16:47 -------- d-----w c:\program files\Broadcom 2009-03-21 16:43 . 2009-03-21 16:43 -------- d-----w c:\program files\WIDCOMM 2009-03-21 16:17 . 2009-03-21 16:17 -------- d-----w c:\program files\Synaptics 2009-03-21 15:12 . 2009-03-21 15:12 -------- d-----w c:\program files\DIFX 2009-03-21 15:11 . 2009-03-21 15:11 -------- d-----w c:\program files\Intel 2009-03-21 15:06 . 2009-03-21 15:06 5 ----a-w c:\windows\system32\drivers\DELL_XPS_MM061 .MRK 2009-03-21 15:06 . 2009-03-21 15:06 5 ----a-w c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK 2009-03-21 06:21 . 2004-08-04 12:00 67 --sha-w c:\windows\Fonts\desktop.ini 2009-03-21 06:19 . 2009-03-21 06:19 21640 ----a-w c:\windows\system32\emptyregdb.dat 2009-03-21 05:27 . 2009-03-21 05:27 34232 ----a-w c:\documents and settings\Dave\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-03-21 04:51 . 2009-03-21 04:51 -------- d-----w c:\program files\microsoft frontpage 2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll 2009-03-03 00:18 . 2004-08-04 12:00 826368 ----a-w c:\windows\system32\wininet.dll 2009-02-20 18:09 . 2004-08-04 12:00 78336 ----a-w c:\windows\system32\ieencode.dll 2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll 2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll 2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys 2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe 2009-02-06 11:06 . 2004-08-04 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe 2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-31 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-31 162584] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-31 138008] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "Stylus C88 @ dnabook"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304] "Stylus C88 @ dnabook (2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888] c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-3-21 24576] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"= "c:\\Program Files\\Airfoil\\Airfoil.exe"= "c:\\Program Files\\Airfoil\\AirfoilSpeakers.exe"= "c:\\Program Files\\iTunes\\iTunesHelper.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015 "1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016 "500:UDP"= 500:UDP:@xpsp2res.dll,-22017 S2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2009-03-11 125304] . Contents of the 'Scheduled Tasks' folder 2009-04-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-03-21 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-21 20:32] 2009-04-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-21 20:32] . - - - - ORPHANS REMOVED - - - - BHO-{2323ae2f-ecc6-40ac-a3b8-3bebb0de543c} - c:\windows\system32\tevaziva.dll HKLM-Run-CinemaNowMediaManagerApp - c:\program files\CinemaNow\CinemaNowShell.exe . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm Trusted Zone: cinemanow.com FF - ProfilePath - c:\documents and settings\Dave.COOLWHIP\Application Data\Mozilla\Firefox\Profiles\vu5z11y7.default\ FF - plugin: c:\documents and settings\Dave.COOLWHIP\Application Data\Mozilla\Firefox\Profiles\vu5z11y7.default\extensions\{3112ca9c-de6d-4884-a869-9855de680400}\plugins\npCinemaNowPlugin.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-28 17:44 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(944) c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(3096) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\btncopy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\WLTRYSVC.EXE c:\windows\system32\BCMWLTRY.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Java\jre6\bin\jqs.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\McAfee\MPF\MpfSrv.exe c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe c:\windows\system32\igfxsrvc.exe c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe c:\program files\iPod\bin\iPodService.exe c:\program files\CinemaNow\CinemaNow Media Manager\CNRpc.exe c:\progra~1\McAfee\MSC\mcuimgr.exe c:\windows\SoftwareDistribution\Download\d78980f289ff5cbd790156e5d1e92d28\update\update.exe . ************************************************************************** . Completion time: 2009-04-29 17:46 - machine was rebooted ComboFix-quarantined-files.txt 2009-04-29 00:46 Pre-Run: 110,326,439,936 bytes free Post-Run: 110,262,120,448 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 239 --- E O F --- 2009-04-16 13:49 |
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Help with Vundo!grb
Hi,
Glad to hear everything appears to be working well but we still have a little more work to do so stay with me, I will let you know when your machine is totally clean. Please do the following:
Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') Code:
<http://www.techsupportforum.com/2107982-post4.html> Collect:: c:\windows\system32\dutuhabe.exe c:\windows\system32\begimepo.exe Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: Windows XP Professional SP 3
|
Re: Help with Vundo!grb
Ok, here's the latest:
ComboFix 09-04-28.02 - Dave 04/29/2009 6:56.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1444 [GMT -7:00] Running from: c:\documents and settings\Dave.COOLWHIP\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Dave.COOLWHIP\Desktop\CFScript.txt AV: McAfee VirusScan *On-access scanning disabled* (Updated) FW: McAfee Personal Firewall *enabled* * Created a new restore point file zipped: c:\windows\system32\begimepo.exe file zipped: c:\windows\system32\dutuhabe.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\begimepo.exe c:\windows\system32\dutuhabe.exe . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-29 ))))))))))))))))))))))))))))))) . 2009-04-27 01:51 . 2009-04-27 01:51 -------- d-----w c:\documents and settings\Dave.COOLWHIP\Local Settings\Application Data\Rogue_Amoeba 2009-04-27 01:50 . 2009-04-27 01:50 -------- d-----w c:\program files\Airfoil 2009-04-26 20:54 . 2008-04-14 00:12 221184 ----a-w c:\windows\system32\wmpns.dll 2009-04-26 20:53 . 2009-04-26 20:53 -------- d-----w c:\program files\Windows Media Connect 2 2009-04-26 20:52 . 2009-04-26 20:53 -------- d-----w c:\windows\system32\drivers\UMDF 2009-04-26 20:47 . 2009-04-26 20:48 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\CinemaNow 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\My Videos 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w C:\DocumenStart Menu 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w C:\DocumenDesktop 2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w c:\program files\CinemaNow 2009-04-24 04:02 . 2009-04-24 04:02 -------- d-----w c:\windows\Sun 2009-04-24 04:02 . 2009-04-24 04:01 410984 ----a-w c:\windows\system32\deploytk.dll 2009-04-24 04:01 . 2009-04-24 04:01 -------- d-----w c:\program files\Java 2009-04-19 04:12 . 2009-04-19 04:14 -------- d-----w c:\program files\Klimb 2009-04-16 14:11 . 2009-04-16 14:11 -------- d-----w c:\program files\MSECache 2009-04-15 21:34 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll 2009-04-15 21:34 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe 2009-04-15 21:33 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll 2009-04-15 21:33 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll 2009-04-15 21:33 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe 2009-04-15 21:33 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll 2009-04-15 21:33 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 21:33 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 21:33 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 21:33 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll 2009-04-15 21:33 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll 2009-04-12 01:36 . 2009-04-12 01:36 162512 ----a-w c:\windows\system32\AirfoilInject3.dll 2009-04-07 23:10 . 2009-04-07 23:10 -------- d-----w c:\program files\EPSON 2009-04-07 23:10 . 2003-05-21 09:27 64000 ----a-w c:\windows\system32\E_FBCBABA.DLL 2009-04-07 23:10 . 2004-11-25 12:07 79679 ----a-w c:\windows\system32\E_FLMABA.DLL 2009-04-07 23:10 . 2000-06-07 08:01 34304 ----a-w c:\windows\system32\E_FBCHABA.DLL 2009-04-07 23:10 . 2004-06-24 08:20 309760 ----a-w c:\windows\system32\EAL32.DLL 2009-04-07 23:10 . 2004-03-12 08:30 82944 ----a-w c:\windows\system32\EAL.EXE 2009-04-07 23:04 . 2009-04-07 23:04 -------- d-----w c:\program files\Bonjour 2009-04-03 05:39 . 2009-04-03 05:39 -------- d-----w c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Apple . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-27 01:51 . 2009-03-21 16:32 22904 ----a-w c:\documents and settings\Dave.COOLWHIP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-04-21 04:41 . 2009-03-21 19:20 -------- d-----w c:\program files\McAfee 2009-04-15 00:50 . 2009-03-21 15:06 -------- d-----w c:\program files\Common Files\InstallShield 2009-03-23 19:26 . 2009-03-23 19:25 -------- d-----w c:\program files\iTunes 2009-03-23 19:25 . 2009-03-23 19:25 -------- d-----w c:\program files\iPod 2009-03-23 19:25 . 2009-03-23 19:23 -------- d-----w c:\program files\Common Files\Apple 2009-03-23 19:25 . 2009-03-23 19:24 -------- d-----w c:\program files\QuickTime 2009-03-23 19:24 . 2009-03-23 19:24 -------- d-----w c:\program files\Apple Software Update 2009-03-22 01:17 . 2009-03-22 01:15 -------- d-----w c:\program files\Common Files\Adobe 2009-03-21 19:40 . 2009-03-21 19:40 -------- d-----w c:\program files\Microsoft.NET 2009-03-21 19:40 . 2009-03-21 19:40 -------- d-----w c:\program files\Microsoft ActiveSync 2009-03-21 19:21 . 2009-03-21 19:20 -------- d-----w c:\program files\Common Files\McAfee 2009-03-21 19:20 . 2009-03-21 19:20 -------- d-----w c:\program files\McAfee.com 2009-03-21 17:10 . 2009-03-21 05:35 -------- d-----w c:\program files\Dell 2009-03-21 17:10 . 2009-03-21 17:10 -------- d-----w c:\program files\CONEXANT 2009-03-21 17:09 . 2009-03-21 17:09 -------- d-----w c:\program files\Digital Line Detect 2009-03-21 17:09 . 2009-03-21 17:00 -------- d--h--w c:\program files\InstallShield Installation Information 2009-03-21 17:06 . 2009-03-21 17:06 0 ----a-w c:\windows\nsreg.dat 2009-03-21 17:03 . 2009-03-21 17:03 -------- d-----w c:\program files\SigmaTel 2009-03-21 16:53 . 2009-03-21 06:21 87263 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-03-21 16:48 . 2009-03-21 16:47 -------- d-----w c:\program files\Broadcom 2009-03-21 16:43 . 2009-03-21 16:43 -------- d-----w c:\program files\WIDCOMM 2009-03-21 16:17 . 2009-03-21 16:17 -------- d-----w c:\program files\Synaptics 2009-03-21 15:12 . 2009-03-21 15:12 -------- d-----w c:\program files\DIFX 2009-03-21 15:11 . 2009-03-21 15:11 -------- d-----w c:\program files\Intel 2009-03-21 15:06 . 2009-03-21 15:06 5 ----a-w c:\windows\system32\drivers\DELL_XPS_MM061 .MRK 2009-03-21 15:06 . 2009-03-21 15:06 5 ----a-w c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK 2009-03-21 06:21 . 2004-08-04 12:00 67 --sha-w c:\windows\Fonts\desktop.ini 2009-03-21 06:19 . 2009-03-21 06:19 21640 ----a-w c:\windows\system32\emptyregdb.dat 2009-03-21 05:27 . 2009-03-21 05:27 34232 ----a-w c:\documents and settings\Dave\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-03-21 04:51 . 2009-03-21 04:51 -------- d-----w c:\program files\microsoft frontpage 2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll 2009-03-03 00:18 . 2004-08-04 12:00 826368 ----a-w c:\windows\system32\wininet.dll 2009-02-20 18:09 . 2004-08-04 12:00 78336 ----a-w c:\windows\system32\ieencode.dll 2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll 2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll 2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll 2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys 2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe 2009-02-06 11:06 . 2004-08-04 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe 2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe 2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll . ((((((((((((((((((((((((((((( SnapShot@2009-04-29_00.44.53 ))))))))))))))))))))))))))))))))))))))))) . + 2009-04-29 01:07 . 2009-04-29 01:07 16384 c:\windows\Temp\Perflib_Perfdata_7a8.dat - 2009-03-21 16:33 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe + 2009-03-21 16:33 . 2007-07-27 16:41 26488 c:\windows\system32\spupdsvc.exe + 2009-04-26 20:54 . 2007-07-27 16:41 16760 c:\windows\system32\spmsg.dll - 2004-08-04 12:00 . 2009-04-28 01:52 58998 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2009-04-29 01:11 58998 c:\windows\system32\perfc009.dat + 2009-03-21 06:26 . 2009-04-29 05:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2009-03-21 06:26 . 2009-04-29 00:32 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2009-03-21 06:26 . 2009-04-29 00:32 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2009-03-21 06:26 . 2009-04-29 05:07 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat - 2006-10-19 04:47 . 2006-10-19 04:47 295936 c:\windows\system32\wmpeffects.dll + 2006-10-19 04:47 . 2008-06-25 01:12 295936 c:\windows\system32\wmpeffects.dll + 2004-08-04 12:00 . 2008-06-18 12:03 938496 c:\windows\system32\WMNetmgr.dll + 2004-08-04 12:00 . 2007-10-28 00:40 222720 c:\windows\system32\wmasf.dll + 2004-08-04 12:00 . 2009-04-29 01:11 392864 c:\windows\system32\perfh009.dat - 2004-08-04 12:00 . 2009-04-28 01:52 392864 c:\windows\system32\perfh009.dat + 2004-08-04 12:00 . 2006-12-04 23:21 414720 c:\windows\system32\msscp.dll - 2004-08-04 12:00 . 2006-10-19 03:03 100864 c:\windows\system32\logagent.exe + 2004-08-04 12:00 . 2008-06-18 08:09 100864 c:\windows\system32\logagent.exe + 2004-08-04 12:00 . 2008-06-18 12:03 938496 c:\windows\system32\dllcache\WMNetmgr.dll + 2004-08-04 12:00 . 2007-10-28 00:40 222720 c:\windows\system32\dllcache\wmasf.dll + 2004-08-04 12:00 . 2007-06-27 05:10 317440 c:\windows\system32\dllcache\unregmp2.exe + 2004-08-04 12:00 . 2006-12-04 23:21 414720 c:\windows\system32\dllcache\msscp.dll + 2004-08-04 12:00 . 2008-06-18 08:09 100864 c:\windows\system32\dllcache\logagent.exe - 2004-08-04 12:00 . 2006-10-19 03:03 100864 c:\windows\system32\dllcache\logagent.exe + 2004-08-04 12:00 . 2007-06-27 05:10 317440 c:\windows\inf\unregmp2.exe + 2004-08-04 12:00 . 2008-06-18 12:03 2458112 c:\windows\system32\WMVCore.dll + 2004-08-04 12:00 . 2008-06-18 12:03 2458112 c:\windows\system32\dllcache\WMVCore.dll + 2004-08-04 12:00 . 2008-11-12 01:34 10838016 c:\windows\system32\wmp.dll + 2004-08-04 12:00 . 2008-11-12 01:34 10838016 c:\windows\system32\dllcache\wmp.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-31 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-31 162584] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-31 138008] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "Stylus C88 @ dnabook"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304] "Stylus C88 @ dnabook (2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888] c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-3-21 24576] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"= "c:\\Program Files\\Airfoil\\Airfoil.exe"= "c:\\Program Files\\Airfoil\\AirfoilSpeakers.exe"= "c:\\Program Files\\iTunes\\iTunesHelper.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015 "1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016 "500:UDP"= 500:UDP:@xpsp2res.dll,-22017 S2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2009-03-11 125304] . Contents of the 'Scheduled Tasks' folder 2009-04-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-03-21 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-21 20:32] 2009-04-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-21 20:32] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm Trusted Zone: cinemanow.com FF - ProfilePath - c:\documents and settings\Dave.COOLWHIP\Application Data\Mozilla\Firefox\Profiles\vu5z11y7.default\ FF - plugin: c:\documents and settings\Dave.COOLWHIP\Application Data\Mozilla\Firefox\Profiles\vu5z11y7.default\extensions\{3112ca9c-de6d-4884-a869-9855de680400}\plugins\npCinemaNowPlugin.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-29 06:57 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(940) c:\windows\System32\BCMLogon.dll c:\windows\system32\igfxdev.dll . Completion time: 2009-04-29 6:58 ComboFix-quarantined-files.txt 2009-04-29 13:58 ComboFix2.txt 2009-04-29 00:46 Pre-Run: 110,258,798,592 bytes free Post-Run: 110,252,531,712 bytes free 226 --- E O F --- 2009-04-29 00:48 Upload was successful |
|
|
|
|
#7 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Help with Vundo!grb
Hi,
Please do the following: Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT Go to Kaspersky website and perform an online antivirus scan.
In your next reply please include
|
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Apr 2009
Posts: 5
OS: Windows XP Professional SP 3
|
Re: Help with Vundo!grb
MBAM log:
Malwarebytes' Anti-Malware 1.36 Database version: 2060 Windows 5.1.2600 Service Pack 3 4/29/2009 2:24:31 PM mbam-log-2009-04-29 (14-24-31).txt Scan type: Quick Scan Objects scanned: 94179 Time elapsed: 2 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Kapersky log: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, April 29, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, April 29, 2009 23:15:23 Records in database: 2101635 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 29283 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 00:35:21 No malware has been detected. The scan area is clean. The selected area was scanned. |
|
|
|
|
#9 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,185
OS: XP sp3
|
Re: Help with Vundo!grb
Hi parrishioner,
Good news, your logs are clean Now we need to do a little housekeeping. Please do the following: You can delete the DDS and GMER folders from your desktop. NEXT Follow these steps to uninstall Combofix
![]() NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. |
|
|
| Thread Tools | |
|
|