Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan win32.monderc.gen [CLOSED]


  • This topic is locked This topic is locked

#1
june100

june100

    New Member

  • Member
  • Pip
  • 1 posts
ComboFix 08-07-12.1 - HP_Administrator 2008-07-13 16:43:56.1 - NTFSx86
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\awtrQiJB.dll
C:\WINDOWS\system32\BJRAbccf.ini
C:\WINDOWS\system32\BJRAbccf.ini2
C:\WINDOWS\system32\cbXRJYSj.dll
C:\WINDOWS\system32\dpmqbgri.dll
C:\WINDOWS\system32\efcBtqnl.dll
C:\WINDOWS\system32\fccAssrR.dll
C:\WINDOWS\system32\fccbARJB.dll
C:\WINDOWS\system32\gwcrqp.dll
C:\WINDOWS\system32\hgGxUOfC.dll
C:\WINDOWS\system32\hgGyaaYQ.dll
C:\WINDOWS\system32\iifeeBSK.dll
C:\WINDOWS\system32\irgbqmpd.ini
C:\WINDOWS\system32\jkkiHYss.dll
C:\WINDOWS\system32\ljJASlKD.dll
C:\WINDOWS\system32\ljJYOeFW.dll
C:\WINDOWS\system32\mlJBRKdb.dll
C:\WINDOWS\system32\mlJDvTKc.dll
C:\WINDOWS\system32\nnnLEvUl.dll
C:\WINDOWS\system32\nnnmmmLE.dll
C:\WINDOWS\system32\nnnnkKaa.dll
C:\WINDOWS\system32\nnnnkLBT.dll
C:\WINDOWS\system32\nnnnOfff.dll
C:\WINDOWS\system32\oeminfo.ini
C:\WINDOWS\system32\opnkIBuu.dll
C:\WINDOWS\system32\opnlMdCr.dll
C:\WINDOWS\system32\pmnoLfge.dll
C:\WINDOWS\system32\pxrkniod.dll
C:\WINDOWS\system32\qoMdDusp.dll
C:\WINDOWS\system32\spywarewarning.mht
C:\WINDOWS\system32\spywarewarning2.mht
C:\WINDOWS\system32\urqQiJYS.dll
C:\WINDOWS\system32\vtUooNEU.dll
C:\WINDOWS\system32\xrmuaqdg.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.

2008-07-12 12:39 . 2008-07-12 12:40 <DIR> d-------- C:\NSS
2008-07-11 18:23 . 2008-07-11 18:23 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-07-11 18:22 . 2008-07-11 18:30 <DIR> d-------- C:\Program Files\Norton 360
2008-07-11 18:18 . 2008-07-11 18:26 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-11 18:18 . 2008-07-11 18:26 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-11 18:18 . 2008-07-11 18:26 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-11 18:18 . 2008-07-11 18:26 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-11 18:13 . 2008-07-13 17:00 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-10 17:45 . 2008-07-10 17:45 43,520 --a------ C:\WINDOWS\system32\clbdll(2).dll
2008-07-10 17:37 . 2008-07-12 17:36 110,415 --a------ C:\WINDOWS\BM02f6de7e.xml
2008-07-01 18:49 . 2008-07-01 18:49 <DIR> d-------- C:\Program Files\Memeo
2008-07-01 18:49 . 2008-07-01 18:49 <DIR> d-------- C:\Program Files\Common Files\eSellerate
2008-06-29 16:00 . 2008-06-29 18:44 <DIR> d-------- C:\Program Files\Picasa2
2008-06-29 15:57 . 2008-06-29 15:57 <DIR> d-------- C:\Program Files\Western Digital
2008-06-29 14:14 . 2008-06-29 15:50 <DIR> d-------- C:\Program Files\Western Digital Technologies
2008-06-29 13:01 . 2008-06-29 13:01 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-06-29 12:01 . 2008-06-29 12:01 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-06-29 12:01 . 2008-06-29 12:01 <DIR> d-------- C:\WINDOWS\l2schemas
2008-06-29 11:57 . 2008-06-29 12:02 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-29 11:37 . 2004-07-17 11:35 67,866 --a------ C:\WINDOWS\system32\drivers\netwlan5.img
2008-06-29 11:36 . 2006-12-28 15:01 19,569 --a------ C:\WINDOWS\003249_.tmp
2008-06-29 11:35 . 2004-07-17 11:36 64,352 --a------ C:\WINDOWS\system32\drivers\ativmc20.cod
2008-06-26 19:12 . 2008-06-26 19:12 <DIR> d-------- C:\Program Files\Panda Security
2008-06-26 19:05 . 2008-06-26 19:07 <DIR> d-------- C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-06-24 19:42 . 2008-06-24 20:14 <DIR> d-------- C:\Program Files\RegCure
2008-06-22 20:19 . 2008-07-04 16:45 <DIR> d-------- C:\WINDOWS\system32\NtmsData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-11 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-11 23:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-11 22:26 --------- d-----w C:\Program Files\Symantec
2008-07-11 22:00 --------- d-----w C:\Program Files\Eset
2008-07-10 08:05 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\uTorrent
2008-07-10 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-07-01 22:49 --------- d-s---w C:\Documents and Settings\All Users\Application Data\Memeo
2008-07-01 22:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-29 22:42 --------- d-----w C:\Program Files\Google
2008-06-22 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-06-21 23:13 --------- d-----w C:\Program Files\Avery Wizard 3.1
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 14:10 --------- d-----w C:\Program Files\Click'N Design 3D (V5)
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-07 23:39 --------- d-----w C:\Program Files\TomTom HOME
2008-06-02 22:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2008-06-02 22:08 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\InstallShield
2008-05-24 00:18 --------- d-----w C:\Program Files\Trader's Little Helper
2008-05-23 21:34 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-20 01:47 139,943 ----a-w C:\Program Files\8179-utorrent.68b2.dmp
2008-05-11 11:15 168,458 ----a-w C:\Program Files\8179-utorrent.37db.dmp
2008-03-16 19:24 139,524 ----a-w C:\Program Files\8179-utorrent.6486.dmp
2008-03-15 02:07 132,115 ----a-w C:\Program Files\8179-utorrent.67ed.dmp
2008-03-15 00:44 170,698 ----a-w C:\Program Files\8179-utorrent.5dd6.dmp
2008-03-09 05:19 165,615 ----a-w C:\Program Files\8179-utorrent.6fc7.dmp
2008-03-08 19:28 239,367 ----a-w C:\Program Files\8179-utorrent.0bd8.dmp
2008-02-27 05:10 5,193 ----a-w C:\Program Files\8179-utorrent.b4ae.dmp
2008-02-03 00:45 219,952 ----a-w C:\Program Files\utorrent.exe
2008-01-13 19:40 145,613 ----a-w C:\Program Files\4602-utorrent.7eaa.dmp
2007-11-23 22:44 139,163 ----a-w C:\Program Files\4602-utorrent.233d.dmp
2007-11-02 07:32 135,786 ----a-w C:\Program Files\4602-utorrent.074c.dmp
2007-10-16 05:10 157,417 ----a-w C:\Program Files\4602-utorrent.c5d6.dmp
2007-07-31 00:01 162,833 ----a-w C:\Program Files\3458-utorrent.9a8e.dmp
2007-07-29 14:25 136,167 ----a-w C:\Program Files\3458-utorrent.2f96.dmp
2007-07-29 13:36 144,245 ----a-w C:\Program Files\3458-utorrent.7ce4.dmp
2007-07-14 19:05 0 ----a-w C:\Program Files\490-utorrent.374c.dmp
2007-06-30 21:57 98,638 ----a-w C:\Program Files\490-utorrent.52c2.dmp
2007-06-15 21:45 116,719 ----a-w C:\Program Files\490-utorrent.e347.dmp
2007-06-15 08:07 84,166 ----a-w C:\Program Files\490-utorrent.16a6.dmp
2007-04-12 09:39 21,874 ----a-w C:\Program Files\490-utorrent.ecc5.dmp
2007-04-10 07:51 86,379 ----a-w C:\Program Files\490-utorrent.f001.dmp
2007-04-01 11:08 23,724 ----a-w C:\Program Files\490-utorrent.51af.dmp
2007-03-03 20:48 97,386 ----a-w C:\Program Files\490-utorrent.1e35.dmp
2007-02-28 22:32 92,863 ----a-w C:\Program Files\490-utorrent.dd72.dmp
2007-01-01 05:23 81,920 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\ezpinst.exe
2007-01-01 05:23 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
2005-08-21 23:23 68 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2005-09-17 00:17 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-13 20:49 67128]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-04 17:34 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 07:04 59392]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 18:34 245760]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-18 00:05 339968]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 09:54 253952]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 07:42 659456]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 18:22 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-25 15:14 98304]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-03-30 11:42 36904]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 21:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 21:50 1603152]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 17:40 155648]
"Name of App"="C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe" [2008-07-07 13:12 675935]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-05-15 16:34 3975848]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-06-29 15:59 1838592]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 21:18 366400]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:34 213936]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 15:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 10:50 988512]
"WD Button Manager"="WDBtnMgr.exe" [2007-02-14 20:05 339968 C:\WINDOWS\system32\WDBtnMgr.exe]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2003-09-30 18:30:04 57344]

C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
Memeo AutoSync Launcher.lnk - C:\Program Files\Memeo\AutoSync\MemeoLauncher.exe [2007-07-06 17:28:44 125976]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 02:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 22:28:24 258048]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-13 20:49:45 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-04-22 15:40:28 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.XVID"= xvid.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
"vidc.jpeg"= m3jpeg32.dll
"VIDC.HFYU"= huffyuv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\utorrent.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 11:49]
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 15:37]
S4 AutoSyncService;Memeo AutoSync ;C:\Program Files\Memeo\AutoSync\MemeoService.exe [2007-07-06 17:28]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-07-13 21:00:32 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-07-10 08:05:22 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-01c5ede2 - C:\WINDOWS\system32\dpmqbgri.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 16:59:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\ehome\ehRecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\ps2.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-07-13 17:08:12 - machine was rebooted [HP_Administrator]
ComboFix-quarantined-files.txt 2008-07-13 21:08:02

Pre-Run: 90,312,585,216 bytes free
Post-Run: 90,648,899,584 bytes free

266 --- E O F --- 2008-07-08 22:19:40
  • 0

Advertisements


#2
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there sorry for the delay,

If you still need help please do the following,

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Note:These logs may be too large to post in one reply, if so, please post extra.txt in a seperate reply.
  • 0

#3
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP