[SOLVED]Win32/Adware.Virtumonde [RESOLVED], Slow computer, random DLL's, its trojan time D: |
![]() ![]() |
[SOLVED]Win32/Adware.Virtumonde [RESOLVED], Slow computer, random DLL's, its trojan time D: |
Aug 8 2008, 09:35 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 33 From: ny, usa OS: Windows XP Pro |
Anyway this is the message that pops up when you have AV installed (I didn't at the time DOH!) so this isn't my machine, it was someone elses who tested the file for me. ![]() I am operating Windows XP SP3 updated as far as Windows Updates will go. It seems this Virtumonde is one of those viruses that generate random names for the DLLs so they are hard to spot. Symptoms When I open folders it takes longer to load the contents of them than usual and dragging windows leaves trails behind that take a bit to clear. The computer is now just running slow in general. I use to be able to do things while my computer is running intensive processes since I'm on quad core w/ 4 gigs of ram, but now I can't. Here is my HiJack this log file. I can obviously see its still there and I'm not sure how to get rid of this. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:25:03 PM, on 8/8/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\system32\CTXFIHLP.EXE C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {8D2860D3-B472-434F-8CF6-79613BBF2A54} - C:\WINDOWS\system32\juwefisi.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [tanufogezi] Rundll32.exe "C:\WINDOWS\system32\pofolehe.dll",s O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [tanufogezi] Rundll32.exe "C:\WINDOWS\system32\pofolehe.dll",s (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [tanufogezi] Rundll32.exe "C:\WINDOWS\system32\pofolehe.dll",s (User 'NETWORK SERVICE') O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'Default user') O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216155310359 O20 - AppInit_DLLs: C:\WINDOWS\system32\gofivoki.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe -- End of file - 7073 bytes I'm willing to do whatever it takes to get this fixed because this is a new install of XP and I just got done installing and updating all my programs! Let me know if theres more information you need! EDIT: I did some research and found this http://www.symantec.com/security_response/...-120914-4108-99 It appears a VERY recent version of Vundo is out there causing havoc. This may be why Vundofix hasn't found anything for me yet. EDIT2: After a lot more scanning VundoFix found 2 infected files. There is one more that shows up in HijackThis ( O2 - BHO: (no name) - {8D2860D3-B472-434F-8CF6-79613BBF2A54} - C:\WINDOWS\system32\juwefisi.dll) which VundoFix seems to have missed. Will remove the 2 it found for now. EDIT3: Removed those files. Still slow and its obviously not gone. New HiJackThis log http://pastebin.com/m34f696d7 This post has been edited by muffins: Aug 8 2008, 11:34 PM |
|
|
Aug 8 2008, 10:31 PM
Post
#2
|
|
![]() Angel Annihilator of Malware Posts: 1,614 From: Singapore (born in China) OS: Windows XP Professional |
Hey muffins,
Welcome to GeekstoGo! I'm Ltangelic and I'll be helping you fix your computer problem. Please post all your logs on here and nowhere else. Take note that I'm still in training, and my posts will have to be checked by an expert. This may cause delays in between my responses, I ask for your patience. Please stick with me until we get your computer cleaned up or it will be a wasted effort on both sides. I'm looking at your log now, and I'll post back with a fix when I'm ready. Thanks for your patience. PS. If I've not been responding, and you wonder why, feel free to PM me and I'll give an explanation. LT This post has been edited by Ltangelic: Aug 8 2008, 10:32 PM |
|
|
Aug 8 2008, 10:36 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 33 From: ny, usa OS: Windows XP Pro |
Great! Glad to get some help on this issue.
I'll be glad to be your punching bag for training ^_^ |
|
|
Aug 8 2008, 11:08 PM
Post
#4
|
|
|
Member ![]() ![]() Posts: 33 From: ny, usa OS: Windows XP Pro |
Hey, good news!
Heres a full list of what I did to fix it: Ran SuperAntiSpyware(works good) Ran Malware Bytes (works good) Ran VundoFix This post has been edited by Rorschach112: Aug 10 2008, 07:41 AM |
|
|
Aug 10 2008, 08:48 AM
Post
#5
|
|
![]() Angel Annihilator of Malware Posts: 1,614 From: Singapore (born in China) OS: Windows XP Professional |
Hey muffins,
Below I have included a number of recommendations for how to protect your computer against malware infections. * Keep Windows updated by regularly checking their website at : http://windowsupdate.microsoft.com/ This will ensure your computer has always the latest security updates available installed on your computer. * To reduce re-infection for malware in the future, I strongly recommend installing these free programs: SpywareBlaster protects against bad ActiveX IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all Have a look at this tutorial for IE-Spyad here * SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict. * You should also have a good firewall. Here are 3 free ones available for personal use: It is critical to have only ONE firewall and anti virus to protect your system and to keep them updated. Make Internet Explorer more secure
* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future. * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place' Here This post has been edited by Ltangelic: Aug 10 2008, 08:48 AM |
|
|
Aug 12 2008, 01:29 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 20,009 From: Dublin OS: XP |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
3 / 480 | 17th June 2008 - 10:43 AM ashenvale started - last by fenzodahl512 |
|||||
![]() |
11 / 785 | 7th July 2008 - 11:44 PM xtreme__boi started - last by __RiP_ChAiN_ |
|||||
![]() |
10 / 294 | 8th August 2008 - 08:58 AM sun123 started - last by Essexboy |
|||||
![]() |
19 / 778 | 29th August 2008 - 03:12 PM greysileighty started - last by Rorschach112 |
|||||
|
Time is now: 5th December 2008 - 05:50 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |