Also, my computer has crashed twice in two days now...The screen turns blue and it says something about dumping physical memory...Please help me, do not know what else to do
I have virtumonde, virtumonde.dll, trojan-downloader and a bunch of others. I will copy and paste a log of combofixer, do I need to run Hijackthis and post a log too? please what steps do you recommend?
Ps: After I ran combofix, I ran spy doctor and it found the trojan-downloader.vb.awj and immediately crashed. So I do not have the log of that scan.
ComboFix 08-06-15.4 - Sindhuri Prakash 2008-06-16 4:49:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.162 [GMT -4:00]
Running from: C:\Documents and Settings\Sindhuri Prakash\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sindhuri Prakash\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\system32\dfNWDcfe.ini
C:\WINDOWS\system32\dfNWDcfe.ini2
C:\WINDOWS\system32\mgi
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\rLM
C:\WINDOWS\system32\stk
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSSECURITY1.209.4
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
2008-06-27 20:11 . 2008-06-16 02:24 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\Yahoo!
2008-06-27 20:11 . 2008-06-27 20:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-27 14:41 . 2008-06-27 14:43 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-06-27 14:41 . 2008-06-27 14:41 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-06-27 14:41 . 2008-06-27 18:53 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Contacts
2008-06-27 14:33 . 2008-06-27 14:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-27 14:30 . 2008-06-27 14:32 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-27 14:22 . 2008-06-27 14:37 <DIR> d-------- C:\Program Files\Windows Live
2008-06-27 14:22 . 2008-06-27 14:35 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-27 14:21 . 2008-06-27 14:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-27 04:34 . 2008-06-27 04:35 <DIR> d-------- C:\Program Files\Zune
2008-06-27 04:34 . 2008-06-27 04:34 <DIR> d-------- C:\Program Files\DIFX
2008-06-27 04:34 . 2008-06-27 04:34 <DIR> d-------- C:\Program Files\Common Files\ComponentOne
2008-06-27 04:07 . 2008-06-27 04:12 <DIR> d-------- C:\089fd98ee99dea1d3f
2008-06-27 02:24 . 2008-06-27 02:24 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\vlc
2008-06-27 02:22 . 2008-06-27 02:22 <DIR> d-------- C:\Program Files\VideoLAN
2008-06-16 02:26 . 2008-06-16 02:35 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-06-16 02:26 . 2008-06-16 02:26 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\Malwarebytes
2008-06-16 02:25 . 2008-06-16 02:25 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-16 02:25 . 2008-06-16 02:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-16 02:25 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-16 02:25 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-15 03:53 . 2008-06-15 04:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-15 03:52 . 2008-06-15 03:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-15 03:33 . 2008-06-15 04:01 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\Lavasoft
2008-06-15 03:32 . 2008-06-15 04:01 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-15 02:55 . 2008-06-15 02:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-15 02:54 . 2008-06-15 02:52 159,880 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-06-15 02:52 . 2008-06-15 02:54 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-06-14 19:31 . 2008-06-14 19:31 <DIR> d-------- C:\VundoFix Backups
2008-06-14 19:16 . 2008-06-16 02:46 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-14 19:16 . 2008-06-14 19:16 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\PC Tools
2008-06-14 19:16 . 2008-06-16 04:57 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-14 19:16 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-14 19:16 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-14 19:16 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-14 19:16 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-14 01:39 . 2008-06-14 01:39 268 --ah----- C:\sqmdata00.sqm
2008-06-14 01:39 . 2008-06-14 01:39 244 --ah----- C:\sqmnoopt00.sqm
2008-06-13 17:04 . 2008-06-13 17:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-13 13:38 . 2008-06-13 13:38 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-06-13 13:36 . 2003-12-02 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-06-13 13:36 . 2003-12-02 19:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\toshiba
2008-06-13 13:36 . 2003-12-02 19:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-06-13 13:36 . 2003-12-02 20:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-06-13 13:36 . 2003-12-02 18:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-06-13 13:36 . 2008-06-13 13:36 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-13 12:04 . 2008-06-15 15:27 <DIR> d-------- C:\WINDOWS\system32\netrax01
2008-06-11 21:31 . 2008-04-14 07:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-28 22:33 . 2008-05-28 22:33 <DIR> d-------- C:\Documents and Settings\Sindhuri Prakash\Application Data\Samsung
2008-05-28 22:23 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-05-28 22:22 . 2008-05-28 22:22 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-05-28 22:22 . 2005-08-30 01:49 94,000 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
2008-05-28 22:22 . 2005-08-30 01:47 58,320 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
2008-05-28 22:22 . 2005-08-30 01:49 8,336 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2008-05-28 22:22 . 2005-08-30 01:49 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2008-05-28 22:22 . 2005-08-30 01:49 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
2008-05-28 22:22 . 2005-08-30 01:47 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
2008-05-28 22:22 . 2005-08-30 01:47 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
2008-05-28 22:21 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-05-28 22:21 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-05-28 22:20 . 2008-05-28 22:20 <DIR> d-------- C:\Program Files\Samsung
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 07:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-29 23:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-29 02:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 09:33 --------- d-----w C:\Documents and Settings\Sindhuri Prakash\Application Data\U3
2008-04-30 07:46 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45FF584E-6554-4EBE-826C-796A2E1159E9}]
C:\WINDOWS\system32\efcDWNfd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-07 16:57 185632]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2006-10-31 14:34 20752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]
C:\Documents and Settings\Sindhuri Prakash\Start Menu\Programs\Startup\
PcHusen.lnk - C:\Documents and Settings\Sindhuri Prakash\Desktop\PcHusen.exe [2007-11-10 03:39:41 100352]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2004-02-20 19:00 88363 C:\WINDOWS\agrsmmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2003-10-30 20:46 192512 C:\Program Files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-04-22 01:10 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CeEKEY]
--a------ 2004-05-06 17:12 638976 C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CeEPOWER]
--a------ 2004-05-20 13:21 135168 C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 03:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-04-21 05:04 118843 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzButton]
--a------ 2004-05-14 14:29 712704 C:\Program Files\EzButton\EzButton.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 04:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 18:42 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2003-09-26 19:43 184320 C:\Program Files\ltmoh\Ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
--a------ 2004-02-03 18:47 1089589 C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
--a------ 2003-10-20 13:39 159744 c:\toshiba\ivp\ism\pinger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 10:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-11-07 16:57 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2003-09-05 07:24 65536 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPNF]
--a------ 2004-03-15 15:17 53248 C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 ECioctl;ECioctl;C:\WINDOWS\system32\Drivers\ECioctl.sys [2004-05-06 16:40]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-06-15 02:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03e357d9-ad35-11dc-a6cc-00023fda00c4}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{675a568a-923d-11dc-a65d-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{709f698f-a2d6-11dc-a6a6-00023fda00c4}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90b52cd4-1c47-11dd-a6f1-00023fda00c4}]
\Shell\AutoRun\command - E:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 16:06:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-28 21:18:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-16 06:54:23 C:\WINDOWS\Tasks\wrSpySweeper_LBD9456FC0B6D469FA1B5EE4CC2675A76.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_LBD9456FC0B6D469FA1B5EE4CC2675A76
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-16 04:56:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
.
**************************************************************************
.
Completion time: 2008-06-16 5:04:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-16 09:03:30
Pre-Run: 42,098,061,312 bytes free
Post-Run: 42,222,116,864 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
234 --- E O F --- 2008-06-15 16:31:34
Edited by hollagabby, 16 June 2008 - 11:55 AM.