Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virtumonde.dll


  • Please log in to reply

#1
Delta Jeff

Delta Jeff

    New Member

  • Member
  • Pip
  • 1 posts
Hello. My infected computer is running XP Media Center. I have the Virtumonde.dll problem and am writing because everyone else who has it seems to have to follow different removal instructions. I have run VundoFix, ComboFix, Spybot, Ad-Aware, HiJack This and am constantly running WinPatrol. Winpatrol shows me when a file tries to insert itself into Internet Explorer add ons. Attempts are made frequently by what I now know is virtumonde and I have always refused to allow installation. They appear as a seemingly random group of letter, both lower and upper case. The two suspicious entries in HiJack This I have tried to remove will not be removed. I tried to run Virtumonde BeGone, but my keyboard is disabled at the safe mode screen and will not allow me to do anything but start windows normally. After I have run the various programs mentioned above it seems another file just starts trying, now with a new name. Now I cannot get Windows Updates to start, either through their security warning icon or through Control Panel. If I try to connect to the Update website, it says one or more Windows services is not running. When I go to services.msc it will not allow me to start automatic updates because there is nothing associated with it. Now my dependable printer isn't even working. Should I allow this thing to install as an IE add on and then attempt to get rid of it? I have four external hard drives hooked into this computer. Can the bug attach itself to something on one or more of them and continue to give me problems? Help, please.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:02:20 PM, on 5/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [d015c798] rundll32.exe "C:\WINDOWS\system32\osgoysox.dll",b
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg...l_v1-0-3-48.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1158362071843
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

--
End of file - 7773 bytes


ComboFix 08-05-19.4 - Owner 2008-05-20 15:34:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1365 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\CeKUvyay.ini
C:\WINDOWS\system32\CeKUvyay.ini2
C:\WINDOWS\system32\hydpmmre.ini
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-04-20 to 2008-05-20 )))))))))))))))))))))))))))))))
.

2008-05-20 14:33 . 2008-05-20 14:33 91,264 --a------ C:\WINDOWS\system32\ermmpdyh.dll
2008-05-20 14:28 . 2008-05-20 14:29 319,360 --a------ C:\WINDOWS\system32\yayvUKeC.dll
2008-05-20 14:07 . 2008-05-20 14:07 91,264 --a------ C:\WINDOWS\system32\tppqfmao.dll
2008-05-20 13:04 . 2008-05-20 13:04 <DIR> d-------- C:\WINDOWS\9URRBA9U6YXA9ONM
2008-05-20 12:49 . 2008-05-20 12:49 <DIR> d-------- C:\VundoFix Backups
2008-05-20 09:48 . 2008-05-20 09:48 319,360 --a------ C:\WINDOWS\system32\nnnmkKaX.dll
2008-05-20 08:41 . 2008-05-20 08:41 15,287 --a------ C:\Documents and Settings\Owner\ComboFixlog.txt
2008-05-20 08:08 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-18 22:28 . 2008-05-18 22:28 90,752 --a------ C:\WINDOWS\system32\qxohgbxb.dll
2008-05-18 16:26 . 2008-05-18 16:26 90,752 --a------ C:\WINDOWS\system32\mngjgfgu.dll
2008-05-18 16:24 . 2008-05-18 16:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-18 16:18 . 2008-05-18 16:18 28,800 --a------ C:\WINDOWS\system32\iifdBtRI.dll
2008-05-18 16:17 . 2008-05-18 16:17 28,800 --a------ C:\WINDOWS\system32\wvUmkheE.dll
2008-05-04 09:34 . 2008-05-04 09:34 <DIR> d-------- C:\Program Files\Mp3tag
2008-05-04 09:34 . 2008-05-04 09:35 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Mp3tag
2008-05-04 09:33 . 2008-05-04 09:33 <DIR> d-------- C:\Program Files\TagScanner
2008-04-30 12:21 . 2007-06-09 13:09 209 --ahs---- C:\BOOT.BKK
2008-04-30 12:19 . 2008-04-30 12:19 <DIR> d-------- C:\Program Files\TGTSoft
2008-04-24 02:00 . 2008-04-24 02:00 <DIR> d-------- C:\Program Files\Arcade Classic Pack
2008-04-21 05:11 . 2008-04-21 05:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Zylom
2008-04-21 05:10 . 2008-04-21 05:12 <DIR> d-------- C:\Program Files\Zylom Games
2008-04-21 05:09 . 2008-04-21 05:09 <DIR> d-------- C:\WINDOWS\Yahtzee Texas Hold Em
2008-04-21 05:09 . 2008-04-21 05:33 <DIR> d-------- C:\Program Files\Yahtzee Texas Hold Em

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 12:28 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd5837.sys
2008-05-20 12:08 --------- d-----w C:\Program Files\Java
2008-05-20 11:11 --------- d-----w C:\Program Files\PowerISO1
2008-05-20 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-05-20 02:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-14 07:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-06 14:17 --------- d-----w C:\Program Files\MediaMonkeyBeta
2008-05-02 13:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-24 05:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\AVG7
2008-04-18 04:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-12 00:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Vso
2008-04-05 03:15 --------- d-----w C:\Documents and Settings\Owner\Application Data\Xingtone
2008-04-05 03:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Xingtone
2008-03-31 04:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\SoundSpectrum
2008-03-31 04:28 --------- d-----w C:\Program Files\SoundSpectrum
2008-03-31 04:15 --------- d-----w C:\Program Files\Common Files\Real
2008-03-31 02:28 --------- d-----w C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-03-29 06:42 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-29 05:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2008-03-29 03:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\RipIt4Me
2008-03-27 10:00 --------- d-----w C:\Program Files\TagRename
2008-03-27 09:52 --------- d-----w C:\Program Files\Bulk Rename Utility
2008-03-27 09:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Tarma Installer
2008-03-23 12:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\SlySoft
2008-03-23 11:38 --------- d-----w C:\Program Files\SlySoft
2008-03-23 11:15 --------- d-----w C:\Program Files\Maryland_Radio
2008-03-23 11:15 --------- d-----w C:\Program Files\Conduit
2008-03-04 15:37 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-11 05:07 47,360 ----a-w C:\Documents and Settings\Owner\Application Data\pcouffin.sys
2008-01-29 13:35 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-05-27 05:44 560 ----a-w C:\Program Files\Global.sw
2001-10-05 16:53 21,866 ----a-w C:\Program Files\Common Files\tppupd2k.dll
2006-05-03 09:06 163,328 --sha-r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sha-r C:\WINDOWS\system32\msfDX.dll
.

((((((((((((((((((((((((((((( [email protected]_14.29.20.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 18:19:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 19:37:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 19:39:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_70c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47551F98-CC7F-4701-A650-D7231EEA60BD}]
2008-05-18 16:17 28800 --a------ C:\WINDOWS\system32\wvUmkheE.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F20CB17D-5809-408A-B8B3-1C84084D40B2}]
2008-05-20 14:29 319360 --a------ C:\WINDOWS\system32\yayvUKeC.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{AC1840CA-F154-4226-96F1-5A732C9A5766}"= C:\Program Files\Maryland_Radio\tbMary.dll [2008-03-04 13:44 1470488]

[HKEY_CLASSES_ROOT\clsid\{ac1840ca-f154-4226-96f1-5a732c9a5766}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 13:30 292152]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-16 02:50 579584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2006-09-06 04:12:50 1093632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
"{47551F98-CC7F-4701-A650-D7231EEA60BD}"= C:\WINDOWS\system32\wvUmkheE.dll [2008-05-18 16:17 28800]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Program Files\\TGTSoft\\StyleXP\\Logon\\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvUmkheE]
wvUmkheE.dll 2008-05-18 16:17 28800 C:\WINDOWS\system32\wvUmkheE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.ZLIB"= avizlib.dll
"VIDC.CSCD"= camcodec.dll
"vidc.yv12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1146181678\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"C:\\Program Files\\Common Files\\AOL\\1146181678\\EE\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1146181678\\EE\\AOLOpenRide.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MediaMonkeyBeta\\VisHelper.exe"=
"C:\\Program Files\\SoundSpectrum\\G-Force\\G-Force V-Bar.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21505:TCP"= 21505:TCP:BitComet 21505 TCP
"21505:UDP"= 21505:UDP:BitComet 21505 UDP
"22480:TCP"= 22480:TCP:BitComet 22480 TCP
"22480:UDP"= 22480:UDP:BitComet 22480 UDP
"8052:TCP"= 8052:TCP:BitComet 8052 TCP
"8052:UDP"= 8052:UDP:BitComet 8052 UDP
"27128:TCP"= 27128:TCP:BitComet 27128 TCP
"27128:UDP"= 27128:UDP:BitComet 27128 UDP
"11515:TCP"= 11515:TCP:BitComet 11515 TCP
"11515:UDP"= 11515:UDP:BitComet 11515 UDP
"10538:TCP"= 10538:TCP:BitComet 10538 TCP
"10538:UDP"= 10538:UDP:BitComet 10538 UDP
"25184:TCP"= 25184:TCP:BitComet 25184 TCP
"25184:UDP"= 25184:UDP:BitComet 25184 UDP
"10672:TCP"= 10672:TCP:BitComet 10672 TCP
"10672:UDP"= 10672:UDP:BitComet 10672 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"39202:UDP"= 39202:UDP:Limewire
"39202:TCP"= 39202:TCP:Limewire
"12032:TCP"= 12032:TCP:BitComet 12032 TCP
"12032:UDP"= 12032:UDP:BitComet 12032 UDP
"12293:TCP"= 12293:TCP:BitComet 12293 TCP
"12293:UDP"= 12293:UDP:BitComet 12293 UDP
"12125:TCP"= 12125:TCP:BitComet 12125 TCP
"12125:UDP"= 12125:UDP:BitComet 12125 UDP

R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Program Files\ASTRA32\ASTRA32.sys [2007-02-22 11:28]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:42]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2007-01-11 19:20]
R3 uscsc108;uscsc108;C:\WINDOWS\system32\DRIVERS\uscsc108.sys [2003-03-09 18:41]
S3 cmudau;C-Media USB Sound Interface;C:\WINDOWS\system32\drivers\cmudau.sys []
S3 MusCDriverV32;MusCDriverV32;C:\WINDOWS\system32\drivers\MusCDriverV32.sys [2007-07-19 14:58]
S3 n558;N558 Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys [2007-08-15 07:27]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys []
S4 OLE multi config;OLE multi config;C:\WINDOWS\system32\ole2.exe []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
\Shell\AutoRun\command - P:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d674bf2-a03b-11dc-8eb1-806d6172696f}]
\Shell\AutoRun\command - XtremeSound.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b4701c0-4cea-11db-9858-806d6172696f}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77e8bf84-ef1a-11dc-8c20-000fb5d3e3e2}]
\Shell\AutoRun\command - L:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77e8bf86-ef1a-11dc-8c20-000fb5d3e3e2}]
\Shell\AutoRun\command - L:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77e8bf87-ef1a-11dc-8c20-000fb5d3e3e2}]
\Shell\AutoRun\command - M:\setupSNK.exe

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-20 15:40:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\system32\hydpmmre.ini 294 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RtlGina2.dll
-> C:\WINDOWS\system32\wvUmkheE.dll

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\ermmpdyh.dll
-> C:\WINDOWS\system32\geBTJYPi.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-05-20 15:47:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-20 19:46:54
ComboFix2.txt 2008-05-20 18:30:11
ComboFix3.txt 2008-05-20 12:40:33

Pre-Run: 110,314,934,272 bytes free
Post-Run: 110,319,435,776 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

259 --- E O F --- 2008-05-17 18:02:18


Thank you for your help and your time.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP