Vundofix:
VundoFix V6.3.21
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.8
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Scan started at 9:23:54 PM 14/05/2007
Listing files found while scanning....
C:\WINNT\system32\cfiii.bak1
C:\WINNT\system32\cfiii.bak2
C:\WINNT\system32\cfiii.ini
C:\WINNT\system32\efcyxyw.dll
C:\WINNT\system32\iiifc.dll
C:\WINNT\system32\tuvtqnn.dll
Beginning removal...
Attempting to delete C:\WINNT\system32\cfiii.bak1
C:\WINNT\system32\cfiii.bak1 Has been deleted!
Attempting to delete C:\WINNT\system32\cfiii.bak2
C:\WINNT\system32\cfiii.bak2 Has been deleted!
Attempting to delete C:\WINNT\system32\cfiii.ini
C:\WINNT\system32\cfiii.ini Has been deleted!
Attempting to delete C:\WINNT\system32\efcyxyw.dll
C:\WINNT\system32\efcyxyw.dll Has been deleted!
Attempting to delete C:\WINNT\system32\iiifc.dll
C:\WINNT\system32\iiifc.dll Has been deleted!
Performing Repairs to the registry.
Done!
Combofix:
"Administrator" - 14/05/2007 22:06:35 Service Pack 3
ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\Administrator\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\edrxkhom.dll
C:\WINNT\system32\mvrjkwiv.dll
C:\WINNT\system32\vhjlshmt.dll
C:\WINNT\system32\viwkjrvm.ini
C:\WINNT\system32\tmhsljhv.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\1.exe
C:\WINNT\system32\svcp.csv
C:\WINNT\system32\winsub.xml
((((((((((((((((((((((((((((((( Files Created from 14/0-01-07 to 14/05/2007 ))))))))))))))))))))))))))))))))))
No new files created in this timespan
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [03/11/03 03:17p]
{49EB07AA-B31A-48C5-A8E4-3AFD670043D5}=C:\WINNT\system32\iiifc.dll []
{4F964B98-CD12-41EC-B67D-6FA856F04818}=C:\WINNT\system32\edrxkhom.dll []
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [09/11/06 04:21p]
{bf00e119-21a3-4fd1-b178-3b8537e75c92}=C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll [11/12/06 06:46p]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"="mobsync.exe /logon"
"NeroFilterCheck"="C:\\WINNT\\system32\\NeroCheck.exe"
"ezShieldProtector for Px"="C:\\WINNT\\System32\\ezSP_Px.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"AtiPTA"="atiptaxx.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WindowsUpdate"="rundll32.exe \"C:\\WINNT\\system32\\mvrjkwiv.dll\",realset"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [07/12/99 08:00a C:\WINNT\system32\mobsync.exe])
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [09/07/01 11:50a]
"ezShieldProtector for Px"="C:\WINNT\System32\ezSP_Px.exe" [20/08/02 10:29a]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [09/11/06 04:07p]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [30/04/07 11:42a]
"AtiPTA"="atiptaxx.exe" [27/09/01 02:39a C:\WINNT\system32\atiptaxx.exe])
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [23/08/06 07:44p]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [25/02/07 09:32p]
"WindowsUpdate"="C:\WINNT\system32\mvrjkwiv.dll" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [09/03/07 01:02a]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [07/12/99 08:00a C:\WINNT\system32\internat.exe])
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [27/03/07 04:22p]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"internat.exe"="internat.exe"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"="internat.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [28/09/06 10:13a]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtqnn
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\WINNT\system32\syst4m.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0
Security Packages kerberosmsv1_0schannel
Notification Packages scecli
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
rpcss RpcSs
wugroup wuauserv
BITSgroup BITS
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
WmdmPmSN
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-14 22:13:29
Windows 5.0.2195 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 14/05/2007 22:13:48
C:\ComboFix-quarantined-files.txt ... 14/05/07 10:13p
C:\ComboFix2.txt ... 11/11/06 12:20a
C:\ComboFix3.txt ... 10/11/06 10:23p