I have been hit badly with Virtumonde, and my SpyBot cannot remove it. Can you please help? My Noton Security keeps blocking Matajuan, and all my Desktop keeps going totally blue, so I can only restart through the Windows Task Manager.
I have posted my GBT TXT and HijackThis log. On the desktop it permanently says: ''Windows XP Home Edition'' permanently.
Can you help?
Rog53
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:27:18, on 08/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\pctspk.exe
C:\PNP\AUDIO\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\drivers\RMC.exe
C:\Program Files\Spamihilator\spamihilator.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HJT\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...t...earch&meta=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=127.0.0.1:81;gopher=127.0.0.1:81;http=localhost:2323;https=127.0.0.1:81
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
F2 - REG:system.ini: Shell=explorer.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [Audio] C:\PNP\AUDIO\SOUNDMAN.EXE
O4 - HKLM\..\Run: [SbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor
O4 - HKLM\..\Run: [RMC] C:\WINDOWS\system32\drivers\RMC.exe
O4 - HKLM\..\Run: [Spamihilator] "C:\Program Files\Spamihilator\spamihilator.exe"
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [a435e821] rundll32.exe "C:\WINDOWS\system32\sbmyhbge.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02999FD7-E09B-4E84-8F1D-722A74F19683}: NameServer = 192.168.10.1
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 5946 bytes
VBG TXT:
[02/08/2008, 13:16:30] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Roger Douek\Desktop\VirtumundoBeGone.exe" )
[02/08/2008, 13:16:38] - Detected System Information:
[02/08/2008, 13:16:38] - Windows Version: 5.1.2600, Service Pack 2
[02/08/2008, 13:16:38] - Current Username: Roger Douek (Admin)
[02/08/2008, 13:16:38] - Windows is in NORMAL mode.
[02/08/2008, 13:16:38] - Searching for Browser Helper Objects:
[02/08/2008, 13:16:38] - BHO 1: {07CECA9C-D8FA-43E2-A3BA-1582C42C7717} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:38] - BHO 2: {09FBEEEB-7A59-482B-8F13-284A837BDE5C} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\ddcyv
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\ddcyv, continuing.
[02/08/2008, 13:16:38] - BHO 3: {20f3740b-f949-4c3f-8f16-524ad9f1b287} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\ltotulmk
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\ltotulmk, continuing.
[02/08/2008, 13:16:38] - BHO 4: {2CD8AFCA-891D-4E30-BB57-C43F8B5804E8} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:38] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/08/2008, 13:16:38] - BHO 6: {555DC70A-74F5-4688-B8B2-64234232A4D5} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\fcyax
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\fcyax, continuing.
[02/08/2008, 13:16:38] - BHO 7: {9DB30F1E-538B-4395-9E49-37C1429AB459} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\jkkjige
[02/08/2008, 13:16:38] - Found: HKLM\...\Winlogon\Notify\jkkjige - This is probably Virtumundo.
[02/08/2008, 13:16:38] - Assigning {9DB30F1E-538B-4395-9E49-37C1429AB459} MSEvents Object
[02/08/2008, 13:16:38] - BHO list has been changed! Starting over...
[02/08/2008, 13:16:38] - BHO 1: {07CECA9C-D8FA-43E2-A3BA-1582C42C7717} ()
[02/08/2008, 13:16:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:38] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:38] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:38] - BHO 2: {09FBEEEB-7A59-482B-8F13-284A837BDE5C} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\ddcyv
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\ddcyv, continuing.
[02/08/2008, 13:16:39] - BHO 3: {20f3740b-f949-4c3f-8f16-524ad9f1b287} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\ltotulmk
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\ltotulmk, continuing.
[02/08/2008, 13:16:39] - BHO 4: {2CD8AFCA-891D-4E30-BB57-C43F8B5804E8} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:39] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/08/2008, 13:16:39] - BHO 6: {555DC70A-74F5-4688-B8B2-64234232A4D5} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\fcyax
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\fcyax, continuing.
[02/08/2008, 13:16:39] - BHO 7: {9DB30F1E-538B-4395-9E49-37C1429AB459} (MSEvents Object)
[02/08/2008, 13:16:39] - ALERT: Found MSEvents Object!
[02/08/2008, 13:16:39] - BHO 8: {C42693C2-580E-4B87-8DA8-A13F8024A7B5} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\pmkjg
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\pmkjg, continuing.
[02/08/2008, 13:16:39] - BHO 9: {C9CBB51E-D0E6-44FD-9C66-4040FABE948A} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\sstss
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\sstss, continuing.
[02/08/2008, 13:16:39] - BHO 10: {CBDFA3F0-2DAD-452B-BA1F-57F10E151D8B} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\vtsrr
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\vtsrr, continuing.
[02/08/2008, 13:16:39] - BHO 11: {DC234301-325C-4E6A-8FD1-321C64C92EC2} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\ljjhf
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\ljjhf, continuing.
[02/08/2008, 13:16:39] - BHO 12: {DE0F2322-A9ED-4588-AA0A-538CD18DEA0B} ()
[02/08/2008, 13:16:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:39] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:39] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:39] - Finished Searching Browser Helper Objects
[02/08/2008, 13:16:39] - *** Detected MSEvents Object
[02/08/2008, 13:16:39] - Trying to remove MSEvents Object...
[02/08/2008, 13:16:40] - Terminating Process: IEXPLORE.EXE
[02/08/2008, 13:16:40] - Terminating Process: RUNDLL32.EXE
[02/08/2008, 13:16:40] - Disabling Automatic Shell Restart
[02/08/2008, 13:16:41] - Terminating Process: EXPLORER.EXE
[02/08/2008, 13:16:41] - Suspending the NT Session Manager System Service
[02/08/2008, 13:16:41] - Terminating Windows NT Logon/Logoff Manager
[02/08/2008, 13:16:41] - Re-enabling Automatic Shell Restart
[02/08/2008, 13:16:41] - File to disable: C:\WINDOWS\system32\jkkjige.dll
[02/08/2008, 13:16:41] - Renaming C:\WINDOWS\system32\jkkjige.dll -> C:\WINDOWS\system32\jkkjige.dll.vir
[02/08/2008, 13:16:42] - File successfully renamed!
[02/08/2008, 13:16:42] - Removing HKLM\...\Browser Helper Objects\{9DB30F1E-538B-4395-9E49-37C1429AB459}
[02/08/2008, 13:16:42] - Removing HKCR\CLSID\{9DB30F1E-538B-4395-9E49-37C1429AB459}
[02/08/2008, 13:16:42] - Adding Kill Bit for ActiveX for GUID: {9DB30F1E-538B-4395-9E49-37C1429AB459}
[02/08/2008, 13:16:42] - Deleting ATLEvents/MSEvents Registry entries
[02/08/2008, 13:16:42] - Removing HKLM\...\Winlogon\Notify\jkkjige
[02/08/2008, 13:16:42] - Searching for Browser Helper Objects:
[02/08/2008, 13:16:42] - BHO 1: {07CECA9C-D8FA-43E2-A3BA-1582C42C7717} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:42] - BHO 2: {09FBEEEB-7A59-482B-8F13-284A837BDE5C} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\ddcyv
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\ddcyv, continuing.
[02/08/2008, 13:16:42] - BHO 3: {20f3740b-f949-4c3f-8f16-524ad9f1b287} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\ltotulmk
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\ltotulmk, continuing.
[02/08/2008, 13:16:42] - BHO 4: {2CD8AFCA-891D-4E30-BB57-C43F8B5804E8} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:42] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/08/2008, 13:16:42] - BHO 6: {555DC70A-74F5-4688-B8B2-64234232A4D5} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\fcyax
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\fcyax, continuing.
[02/08/2008, 13:16:42] - BHO 7: {C42693C2-580E-4B87-8DA8-A13F8024A7B5} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\pmkjg
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\pmkjg, continuing.
[02/08/2008, 13:16:42] - BHO 8: {C9CBB51E-D0E6-44FD-9C66-4040FABE948A} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\sstss
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\sstss, continuing.
[02/08/2008, 13:16:42] - BHO 9: {CBDFA3F0-2DAD-452B-BA1F-57F10E151D8B} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\vtsrr
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\vtsrr, continuing.
[02/08/2008, 13:16:42] - BHO 10: {DC234301-325C-4E6A-8FD1-321C64C92EC2} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\ljjhf
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\ljjhf, continuing.
[02/08/2008, 13:16:42] - BHO 11: {DE0F2322-A9ED-4588-AA0A-538CD18DEA0B} ()
[02/08/2008, 13:16:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/08/2008, 13:16:42] - Checking for HKLM\...\Winlogon\Notify\vtsts
[02/08/2008, 13:16:42] - Key not found: HKLM\...\Winlogon\Notify\vtsts, continuing.
[02/08/2008, 13:16:42] - Finished Searching Browser Helper Objects
[02/08/2008, 13:16:42] - Finishing up...
[02/08/2008, 13:16:42] - A restart is needed.
[02/08/2008, 13:16:42] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[02/08/2008, 13:17:12] - Attempting to Restart via STOP error (Blue Screen!)
Edited by Rog53, 08 February 2008 - 08:07 AM.