Welcome Guest ( Log In | Join )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide. Want to reply to a topic, start a new one, or remove the advertising? Join today (always free).
      
 
Closed TopicStart new topic
Trojan Issue - vundo.gen!r
Theonus
post Oct 6 2008, 06:04 PM
Post #1


New Member
*
Posts: 3
OS: Windows XP



Hello,

This is slightly risky of maybe mentioning something already covered by another thread but I am scared to follow instructions you give to others without knowing it is exactly the same steps I need to follow. So sorry in advance if this is the case and please feel free to point me to some pre-written instructions somewhere.

I have ended up in a little pickle today, downloaded a file (a infected copy of iTunes I think gave me it) that ended up not being from the manufacturers website and seems to have contained the vundo.gen!r (or so my Windows Defender says).

Windows Defender and my Antivir occasionally flag up messages but then they say they remove the infections but they come back again and again. I also had some pop-ups at first... they seem to have gone when I completed full defender and AV scans and deleted all files but every so long I still get warnings about files infected like this one for example from defender:


-----------------------------------------
Trojan:Win32/Vundo.gen!R Severe

Resources:
process:
pid:2584

file:
C:\WINDOWS\system32\iifcATlI.dll

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{E528D1A0-7C46-447C-B140-42F5B211900A}

regkey:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E528D1A0-7C46-447C-B140-42F5B211900A}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{E528D1A0-7C46-447C-B140-42F5B211900A}

bho:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E528D1A0-7C46-447C-B140-42F5B211900A}

clsid:
HKLM\Software\Classes\CLSID\{E528D1A0-7C46-447C-B140-42F5B211900A}

regkey:
HKLM\Software\Classes\CLSID\{E528D1A0-7C46-447C-B140-42F5B211900A}

Summary:
Application Execution change occurred.

This agent scans software just before it runs. You are alerted if the software has a high potential for harming your computer.

Checkpoint:
Running Processes

View more information about this item online
-----------------------------------------------------------



So I have installed HijackThis 2.02 and made logs...

-----------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:59:06, on 07/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Lachesis\razerhid.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Razer\Lachesis\OSD.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Razer\Lachesis\razertra.exe
C:\Program Files\Razer\Lachesis\razerofa.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Game Cam\GameCam.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07FAA62B-2F85-4009-ADA2-F2B5D7E74C74} - C:\WINDOWS\system32\yayaYSKb.dll
O2 - BHO: (no name) - {124B3CD8-E1B1-4794-AAD0-A37BF64A6F41} - C:\WINDOWS\system32\byXPHWno.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1216768168671
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd...ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: yayaYSKb - C:\WINDOWS\SYSTEM32\yayaYSKb.dll
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe

--
End of file - 8737 bytes

-----------------------------------------------------------


How bad is it? *cringes*

Any and all help extremely appreciated as I am on the verge of a format C:\ here its so worrying....

Thanks...

Steve...
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 6 2008, 06:48 PM
Post #2


GeekU Teacher
Group Icon
Posts: 19,792
From: Dublin
OS: XP



Hello

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.



Disable resident protections (Antivirus...); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)



Go to the top of the page
 
+Quote Post
Theonus
post Oct 7 2008, 08:08 AM
Post #3


New Member
*
Posts: 3
OS: Windows XP



Thanks Rorschach112 I shall do that once I return home soon. Big fan of the Irish by the way, and harold and kumar (hehe)!

Back to topic I did after reading a similar thread run that VundoFix last night, admitedly just after Windows Defender claimed to have removed infected files, but the vundofix said no files found.

I will run it again today and forget the previous attempt and we shall go from there but out of interest if I draw a blank again should I do something specific or just continue to your second Lop S&D instruction?

Thanks in advance mate!

Steve... wink.gif
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 7 2008, 08:11 AM
Post #4


GeekU Teacher
Group Icon
Posts: 19,792
From: Dublin
OS: XP



If you ran it before then no need to run it again, just go onto the LOP S+D step, will save us some time.
Go to the top of the page
 
+Quote Post
Theonus
post Oct 7 2008, 10:18 AM
Post #5


New Member
*
Posts: 3
OS: Windows XP



Just got some "Trend MicroAV" popup or something opening this page....

Anyhow here is my log as requested (anything in the log in "My Documents\SOFTWARE\" I have had long enough to trust the other stff seemed ok and I believe it was a dodgy version of iTunes that caused it, as on install I had explorer crash and got some abuse from Defender and AntiVir and probelms began immediately. Deleted that now already:



--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 Quad CPU Q6600 @ 2.40GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Theo ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.15 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 465 Go Free : 405 Go
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 07/10/2008|17:06 )

--------------------\\ Listing folders in APPLIC~1

[19/09/2008|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[22/07/2008|01:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[28/09/2008|05:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/09/2008|17:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[22/07/2008|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[23/07/2008|00:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Razer
[25/09/2008|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[02/10/2008|23:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[28/07/2008|23:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[22/07/2008|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[22/07/2008|00:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[07/10/2008|16:59] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[07/10/2008|17:00] C:\DOCUME~1\LOCALS~1\APPLIC~1\AdobeUM
[23/07/2008|00:26] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[31/07/2008|15:54] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[19/09/2008|18:12] C:\DOCUME~1\Theo\APPLIC~1\Adobe
[19/09/2008|18:21] C:\DOCUME~1\Theo\APPLIC~1\AdobeUM
[06/10/2008|20:05] C:\DOCUME~1\Theo\APPLIC~1\Apple Computer
[22/07/2008|01:59] C:\DOCUME~1\Theo\APPLIC~1\Help
[22/07/2008|00:49] C:\DOCUME~1\Theo\APPLIC~1\Identities
[23/07/2008|00:00] C:\DOCUME~1\Theo\APPLIC~1\InstallShield
[15/09/2008|17:01] C:\DOCUME~1\Theo\APPLIC~1\LimeWire
[23/07/2008|23:38] C:\DOCUME~1\Theo\APPLIC~1\Macromedia
[25/09/2008|14:59] C:\DOCUME~1\Theo\APPLIC~1\Microsoft
[15/09/2008|17:10] C:\DOCUME~1\Theo\APPLIC~1\Nero
[06/10/2008|01:58] C:\DOCUME~1\Theo\APPLIC~1\Skype
[05/10/2008|23:13] C:\DOCUME~1\Theo\APPLIC~1\skypePM
[23/07/2008|22:45] C:\DOCUME~1\Theo\APPLIC~1\SPAMfighter
[23/07/2008|00:14] C:\DOCUME~1\Theo\APPLIC~1\Sun
[29/09/2008|19:41] C:\DOCUME~1\Theo\APPLIC~1\teamspeak2
[06/10/2008|20:14] C:\DOCUME~1\Theo\APPLIC~1\uTorrent
[23/07/2008|01:52] C:\DOCUME~1\Theo\APPLIC~1\Ventrilo
[23/07/2008|00:21] C:\DOCUME~1\Theo\APPLIC~1\Windows Desktop Search
[28/09/2008|03:45] C:\DOCUME~1\Theo\APPLIC~1\Windows Search

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[07/10/2008 16:55][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job
[07/10/2008 16:52][--ah-----] C:\WINDOWS\tasks\SA.DAT
[23/08/2001 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[22/07/2008|02:10] C:\Program Files\Adobe
[22/07/2008|01:08] C:\Program Files\Analog Devices
[06/10/2008|20:14] C:\Program Files\Apple Software Update
[22/07/2008|01:50] C:\Program Files\Avira
[06/10/2008|20:15] C:\Program Files\Bonjour
[06/10/2008|19:56] C:\Program Files\Common Files
[22/07/2008|00:42] C:\Program Files\ComPlus Applications
[15/09/2008|16:48] C:\Program Files\[bleep] NFO Viewer
[23/07/2008|00:00] C:\Program Files\DIFX
[28/07/2008|23:32] C:\Program Files\epson
[02/10/2008|23:45] C:\Program Files\Game Cam
[02/10/2008|23:44] C:\Program Files\InstallShield Installation Information
[15/08/2008|00:45] C:\Program Files\Internet Explorer
[23/07/2008|00:14] C:\Program Files\Java
[24/09/2008|15:36] C:\Program Files\K-Lite Codec Pack
[15/09/2008|16:54] C:\Program Files\LimeWire
[15/08/2008|00:46] C:\Program Files\Messenger
[12/09/2008|16:25] C:\Program Files\Microsoft ActiveSync
[22/07/2008|00:46] C:\Program Files\microsoft frontpage
[12/09/2008|16:28] C:\Program Files\Microsoft Office
[19/08/2008|18:01] C:\Program Files\Microsoft Silverlight
[12/09/2008|16:25] C:\Program Files\Microsoft Visual Studio
[22/07/2008|01:57] C:\Program Files\Movie Maker
[22/07/2008|00:42] C:\Program Files\MSN
[22/07/2008|00:42] C:\Program Files\MSN Gaming Zone
[24/07/2008|19:09] C:\Program Files\MSXML 4.0
[15/09/2008|17:08] C:\Program Files\Nero
[15/09/2008|17:11] C:\Program Files\NeroInstall.bak
[22/07/2008|01:55] C:\Program Files\NetMeeting
[22/07/2008|01:04] C:\Program Files\NVIDIA Corporation
[22/07/2008|00:42] C:\Program Files\Online Services
[27/09/2008|16:32] C:\Program Files\Outlook Express
[23/07/2008|01:10] C:\Program Files\PowerQuest
[23/07/2008|00:00] C:\Program Files\Razer
[25/09/2008|17:50] C:\Program Files\Skype
[06/10/2008|20:18] C:\Program Files\SPAMfighter
[29/09/2008|19:41] C:\Program Files\Teamspeak2_RC2
[30/09/2008|18:12] C:\Program Files\Thomson
[07/10/2008|00:48] C:\Program Files\Trend Micro
[22/07/2008|00:49] C:\Program Files\Uninstall Information
[27/09/2008|17:08] C:\Program Files\Unlocker
[15/09/2008|16:42] C:\Program Files\uTorrent
[23/07/2008|00:17] C:\Program Files\Ventrilo
[31/07/2008|15:34] C:\Program Files\Windows Defender
[23/07/2008|00:21] C:\Program Files\Windows Desktop Search
[22/07/2008|19:13] C:\Program Files\Windows Live
[22/07/2008|02:24] C:\Program Files\Windows Media Connect 2
[22/07/2008|02:24] C:\Program Files\Windows Media Player
[22/07/2008|01:55] C:\Program Files\Windows NT
[22/07/2008|01:33] C:\Program Files\WindowsUpdate
[15/09/2008|16:53] C:\Program Files\WinRAR
[25/09/2008|19:48] C:\Program Files\World of Warcraft
[22/07/2008|00:46] C:\Program Files\xerox

--------------------\\ Listing Folders in C:\Program Files\Common Files

[19/09/2008|18:21] C:\Program Files\Common Files\Adobe
[23/07/2008|22:45] C:\Program Files\Common Files\Ankiro
[06/10/2008|19:56] C:\Program Files\Common Files\Apple
[23/07/2008|22:45] C:\Program Files\Common Files\Application
[12/09/2008|01:09] C:\Program Files\Common Files\Blizzard Entertainment
[12/09/2008|16:25] C:\Program Files\Common Files\Designer
[28/07/2008|23:33] C:\Program Files\Common Files\InstallShield
[23/07/2008|00:13] C:\Program Files\Common Files\Java
[12/09/2008|16:24] C:\Program Files\Common Files\L&H
[15/09/2008|16:43] C:\Program Files\Common Files\Microsoft Shared
[22/07/2008|00:43] C:\Program Files\Common Files\MSSoap
[15/09/2008|17:09] C:\Program Files\Common Files\Nero
[22/07/2008|08:36] C:\Program Files\Common Files\ODBC
[22/07/2008|00:43] C:\Program Files\Common Files\Services
[25/09/2008|17:50] C:\Program Files\Common Files\Skype
[22/07/2008|08:36] C:\Program Files\Common Files\SpeechEngines
[12/09/2008|16:24] C:\Program Files\Common Files\System
[22/07/2008|19:13] C:\Program Files\Common Files\WindowsLiveInstaller
[23/07/2008|00:17] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 53 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

C:\DOCUME~1\Theo\Cookies\theo@advertising[1].txt
C:\DOCUME~1\Theo\Cookies\theo@adopt.euroclick[2].txt

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-07 17:09:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections

C:\WINDOWS\system32\AJihPXbc.ini2
C:\WINDOWS\system32\bcJmnnpo.ini
C:\WINDOWS\system32\bcJmnnpo.ini2
C:\WINDOWS\system32\HOWGNqss.ini
C:\WINDOWS\system32\HOWGNqss.ini2
C:\WINDOWS\system32\IlTAcfii.ini
C:\WINDOWS\system32\IlTAcfii.ini2
C:\WINDOWS\system32\onWHPXyb.ini
C:\WINDOWS\system32\onWHPXyb.ini2
C:\WINDOWS\system32\sYxGMUvw.ini
C:\WINDOWS\system32\sYxGMUvw.ini2
==> VUNDO <==

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Theo\Application Data\uTorrent\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS].1.torrent
C:\DOCUME~1\Theo\Application Data\uTorrent\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS].torrent
C:\DOCUME~1\Theo\Application Data\uTorrent\Nero 8 Keygen.exe.torrent
C:\DOCUME~1\Theo\Application Data\uTorrent\NERO 8.3.6.0+KEYGEN.torrent
C:\DOCUME~1\Theo\Local Settings\Temporary Internet Files\Content.IE5\0DCLNDS9\Nero_8_Keygen.exe_[mininova][1].torrent
C:\DOCUME~1\Theo\Local Settings\Temporary Internet Files\Content.IE5\0DCLNDS9\[isoHunt]_Ahead_-_Nero_8.3.6.0_Keygen&Crack_[NEMESIS][1].torrent
C:\DOCUME~1\Theo\Local Settings\Temporary Internet Files\Content.IE5\34IEAWYB\[isoHunt]_NERO_8.3.6.0_KEYGEN[1].torrent
C:\DOCUME~1\Theo\Local Settings\Temporary Internet Files\Content.IE5\EIJ4P76G\nero+8+keygen[1].htm
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]\Ahead - Nero 8.3.6.0 Crack.exe
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]\Ahead - Nero 8.3.6.0 KeyGen.exe
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]\Extra Keys.txt
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]\Nero-8.3.6.0_eng_trial.exe
C:\DOCUME~1\Theo\My Documents\Downloads\Ahead - Nero 8.3.6.0 Keygen&Crack [NEMESIS]\Read Me First!!!.txt
C:\DOCUME~1\Theo\My Documents\SOFTWARE\CD-R - DVD-R SOFTWARE\Clone Cd & Keygen.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\CD-R - DVD-R SOFTWARE\DVD-R\TMPGEnc DVD Author v1.5.11.37 + KeyGen.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\GRAPHICS\Crystal Button & Crack.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\GRAPHICS\SWISH_2___KEYGEN.EXE
C:\DOCUME~1\Theo\My Documents\SOFTWARE\GRAPHICS\XARA3D AND KEYGEN.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack\# Theo says - Readme.txt
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack\1. Keyfinder.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack\2. Windows XP Keygen.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack\3. WGA Fixer.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\HOUSEKEEPING\WGA Crack\4. WGA Verify.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\INTERNET\mIRC+Keygen.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\SOUND PROGS\AlbumWrap v1.0 + Keygen.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\SOUND PROGS\MODEM SPY V3.2 - RECORDS PHONE CALLS + KEYGEN.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\VIDEO EDITING - CONVERTING\Dr Divx 1.0.6 + DivX 5.2.1 with keygens
C:\DOCUME~1\Theo\My Documents\SOFTWARE\VIDEO EDITING - CONVERTING\Dr Divx 1.0.6 + DivX 5.2.1 with keygens\DivX521XP2K.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\VIDEO EDITING - CONVERTING\Dr Divx 1.0.6 + DivX 5.2.1 with keygens\divx_v5.2.1_kg.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\VIDEO EDITING - CONVERTING\Dr Divx 1.0.6 + DivX 5.2.1 with keygens\DrDivX106.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\VIDEO EDITING - CONVERTING\Dr Divx 1.0.6 + DivX 5.2.1 with keygens\DrDivx_v106_Kg.exe
C:\DOCUME~1\Theo\My Documents\SOFTWARE\Z - MISC\Cracksearcher
C:\DOCUME~1\Theo\My Documents\SOFTWARE\Z - MISC\WinRAR Crack for v3.20.zip
C:\DOCUME~1\Theo\My Documents\SOFTWARE\Z - MISC\Cracksearcher\Cracks
C:\DOCUME~1\Theo\My Documents\SOFTWARE\Z - MISC\Cracksearcher\CrackSearcher.exe


[F:6][D:3]-> C:\DOCUME~1\Theo\LOCALS~1\Temp
[F:360][D:0]-> C:\DOCUME~1\Theo\Cookies
[F:19992][D:21]-> C:\DOCUME~1\Theo\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 07/10/2008|17:10 - Option : [1]

--------------------\\ Scan completed at 17:10:47

This post has been edited by Theonus: Oct 7 2008, 10:19 AM
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 7 2008, 10:57 AM
Post #6


GeekU Teacher
Group Icon
Posts: 19,792
From: Dublin
OS: XP



You got infected because you downloaded cracks, not because of iTunes. There is no doubt in my mind.

You are also using a pirated version of Windows, that is against the rules here so we can no longer help you

Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 2nd December 2008 - 06:41 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.