Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works

Having trouble with Trojan.Virtumonde please help!

  • Please log in to reply



    New Member

  • Member
  • Pip
  • 1 posts
I got this virus that attached to several of my running proccesses. everything i have downloaded to get rid of it does not seem to do the job. I need help!!!

here is the most recent HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:17:42 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe
C:\Documents and Settings\Andrea\Desktop\HiJackThis.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\ddccy.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8DA6BD4A-A644-4687-9E46-233B4F018575} - C:\WINDOWS\system32\ddccy.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

End of file - 3762 bytes

here is the virumondobrgone log:

[01/05/2008, 15:17:33] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Andrea\Desktop\VirtumundoBeGone.exe" )
[01/05/2008, 15:17:43] - Detected System Information:
[01/05/2008, 15:17:43] - Windows Version: 5.1.2600, Service Pack 2
[01/05/2008, 15:17:43] - Current Username: Andrea (Admin)
[01/05/2008, 15:17:44] - Windows is in NORMAL mode.
[01/05/2008, 15:17:44] - Searching for Browser Helper Objects:
[01/05/2008, 15:17:44] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[01/05/2008, 15:17:44] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[01/05/2008, 15:17:44] - BHO 3: {8DA6BD4A-A644-4687-9E46-233B4F018575} ()
[01/05/2008, 15:17:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/05/2008, 15:17:44] - Checking for HKLM\...\Winlogon\Notify\ddccy
[01/05/2008, 15:17:44] - Key not found: HKLM\...\Winlogon\Notify\ddccy, continuing.
[01/05/2008, 15:17:44] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[01/05/2008, 15:17:44] - Finished Searching Browser Helper Objects
[01/05/2008, 15:17:44] - Finishing up...
[01/05/2008, 15:17:44] - Nothing found! Exiting...

****ActiveScan log*******

Incident Status Location

Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Andrea\Desktop\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Andrea\Desktop\ComboFix.exe[nircmd.cfexe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Andrea\Desktop\VirtumundoBeGone.exe
Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\xxyvwvw.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\xxyvwvw.dll.bad
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\bnfktlyl.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ogqxwqkp.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\pppakqyx.dll

Edited by mommykc05, 05 January 2008 - 05:17 PM.

  • 0


Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP