Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Yes, another one with Win32/Virtumonde [CLOSED]


  • This topic is locked This topic is locked

#1
KoolAidGuy

KoolAidGuy

    Member

  • Member
  • PipPip
  • 11 posts
Hey guys,

Yep. Again the annoying Virtumonde.. I just can't manage to kill it :) . I'd sure appreciate some help :).

Here is a HijackThis log. I believe NOD32 killed some of it. But everytime when I reboot it is there again. It also slows down the computer a lot.
Now that I have to do a lot of schoolwork it really annoys the crap out of me to wait 30 seconds for Word to start.

Anyways, the HijackThis log. Thanks for any help in advance :) !!

Edit: Oh yeah, also forgot to mention it keeps disabling Microsoft's auto-update!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:42 AM, on 7/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: (no name) - {38C6F42E-F880-4E49-8538-9E2B8E243E5A} - C:\WINDOWS\system32\tuvTnNHA.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: {580add0f-2c00-9299-e5f4-e5e4065cd0c8} - {8c0dc560-4e5e-4f5e-9929-00c2f0dda085} - C:\WINDOWS\system32\kppmzp.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {B01689DA-3473-430D-B503-07CBB044A33A} - C:\WINDOWS\system32\xxyaaywU.dll
O2 - BHO: (no name) - {D554A583-D4CF-4A6F-B07A-CB25F60FA743} - C:\WINDOWS\system32\ddcCuULd.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [winsock32] C:\WINDOWS\system32:winsock32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [PS Media Tunnel] C:\Program Files\Digital Integration Ltd\PS Media Tunnel\PSMediaTunnel.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [20f5ffce] rundll32.exe "C:\WINDOWS\system32\tibbbtfg.dll",b
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Onderzoekscentrum - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1209812350046
O20 - Winlogon Notify: ddcCuULd - C:\WINDOWS\SYSTEM32\ddcCuULd.dll
O20 - Winlogon Notify: rqRLbyaA - rqRLbyaA.dll (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 7706 bytes

Edited by KoolAidGuy, 01 July 2008 - 05:03 PM.

  • 0

Advertisements


#2
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hello KoolAidGuy,

Welcome to Geeks to Go.

I am analysing your log and will get back to you in a bit.

regards
emeraldnzl
  • 0

#3
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Great, thanks!
  • 0

#4
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hello KoolAidGuy,

You have a number of infections. We will need to take a multi level approach to solving your problems.

Before we do anything we should start from a sound base. :)

-------------------------------------------------------------------


  • Please read this post completely, it may make it easier if you copy and paste this post to a new text document or print it for reference later. This will especially help you when your computer is off line. You may want to do this following each post for each set of instructions.
  • It is important you carry out instructions exactly in the order they appear. If however for some reason you cannot carry out one of them, please move on to the next and let me know in the next post what happened.
Next

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

-----Step 2-----

You have a serious infection. Combofix is a powerful tool which in rare cases can cause complications. To be on the safe side; if you don't already have it, we should install the Microsoft Recovery Console so that we can access your computer in case this becomes necessary.

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System.

Posted Image

SP3 users select the download for SP2

Download the file & save it as it's originally named, next to ComboFix.exe.

Posted Image

Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
  • 0

#5
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hi.

I already have the Recovery Console installed on my machine. I will run ComboFix without dragging the file onto it.
I hope that's okay.
Anyway, I will post the log when it has finished.
  • 0

#6
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Finished. Here's the log. Oh, and I got an error when ComboFix rebooted the machine.
Posted Image

Just out of curiousity.. How serious is this infection? Can I still do online banking? Write private emails to my friends?
And what other infections besides Virtumonde do I have?

Thanks again for helping, it's really appreciated :) !!

Greetings from The Netherlands!

Jeff

ComboFix 08-07-01.5 - Sjef 2008-07-03 0:25:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.517 [GMT 2:00]
Running from: C:\Documents and Settings\Sjef\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM23c6cc52.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bpdswnli.dll
C:\WINDOWS\system32\byXqNHAR.dll
C:\WINDOWS\system32\ddcCuULd.dll
C:\WINDOWS\system32\efcaYppp.dll
C:\WINDOWS\system32\efcBttRI.dll
C:\WINDOWS\system32\ehdspeak.dll
C:\WINDOWS\system32\evucnald.dll
C:\WINDOWS\system32\fcccyyww.dll
C:\WINDOWS\system32\gdfypgqp.dll
C:\WINDOWS\system32\gftbbbit.ini
C:\WINDOWS\system32\hgGaayvT.dll
C:\WINDOWS\system32\iifcDWoo.dll
C:\WINDOWS\system32\IRttBcfe.ini
C:\WINDOWS\system32\IRttBcfe.ini2
C:\WINDOWS\system32\jxwgyr.dll
C:\WINDOWS\system32\kaepsdhe.ini
C:\WINDOWS\system32\kppmzp.dll
C:\WINDOWS\system32\ljJCrRkK.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\toilpy.dll
C:\WINDOWS\system32\Uwyaayxx.ini
C:\WINDOWS\system32\Uwyaayxx.ini2
C:\WINDOWS\system32\vdlanqxp.ini
C:\WINDOWS\system32\vtUlKETm.dll
C:\WINDOWS\system32\xgbodnfm.dll
C:\WINDOWS\system32\yacnirkl.dll
C:\WINDOWS\system32\zpckmk.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.

2008-07-03 00:19 . 2004-08-04 14:00 4,952 -ra------ C:\Bootfont.bin
2008-07-02 10:10 . 2008-07-02 10:10 1,713,713 --ahs---- C:\WINDOWS\system32\gftbbbit.tmp
2008-07-02 00:44 . 2008-07-02 00:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-30 16:54 . 2008-07-02 00:17 110,446 --a------ C:\WINDOWS\BM23c6cc52.xml
2008-06-30 16:36 . 2008-06-30 16:36 <DIR> d-------- C:\Program Files\CCleaner
2008-06-29 16:42 . 2008-06-29 16:42 268 --ah----- C:\sqmdata01.sqm
2008-06-29 16:42 . 2008-06-29 16:42 244 --ah----- C:\sqmnoopt01.sqm
2008-06-27 19:35 . 2008-06-27 19:35 <DIR> d-------- C:\Documents and Settings\Sjef\Application Data\Lavasoft
2008-06-27 19:09 . 2008-07-02 16:21 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-27 19:08 . 2008-06-10 21:22 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-27 19:08 . 2008-06-02 15:19 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-27 19:08 . 2008-06-02 15:19 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-27 19:08 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-27 19:07 . 2008-06-27 19:10 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-27 19:07 . 2008-06-27 19:07 <DIR> d-------- C:\Documents and Settings\Sjef\Application Data\PC Tools
2008-06-27 19:07 . 2008-06-27 19:07 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-06-27 19:06 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-06-27 19:06 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-06-27 19:06 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-06-27 19:06 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2008-06-27 19:05 . 2008-06-27 19:05 164 --a------ C:\install.dat
2008-06-27 19:03 . 2008-06-27 19:05 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-27 19:03 . 2008-06-27 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-27 19:02 . 2008-06-27 19:02 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-27 19:00 . 2008-06-27 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-06-27 18:59 . 2008-06-27 19:01 <DIR> d-------- C:\Temp
2008-06-27 18:44 . 2008-06-27 18:44 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2008-06-27 18:44 . 2008-06-27 20:01 <DIR> d-------- C:\Program Files\Hitman Pro
2008-06-27 15:13 . 2008-06-27 15:13 25,600 --a------ C:\WINDOWS\system32\opnMdApn.dll__DELETE_ON_REBOOT
2008-06-27 14:50 . 2008-07-03 00:31 2,517,024 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-27 14:50 . 2008-07-03 00:30 31,568 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-27 14:47 . 2008-06-27 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-27 14:47 . 2008-04-02 21:07 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-06-27 14:47 . 2004-04-27 05:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-06-27 14:47 . 2008-06-27 14:48 4,212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2008-06-27 14:46 . 2008-06-27 14:46 <DIR> d-------- C:\Program Files\Zone Labs
2008-06-27 10:42 . 2008-06-27 10:42 28,672 --a------ C:\WINDOWS\conf32.exe
2008-06-26 23:15 . 2008-06-26 23:15 80,896 --a------ C:\WINDOWS\system32\exgjevar.dll__DELETE_ON_REBOOT
2008-06-26 23:08 . 2008-06-26 23:08 91,648 --a------ C:\WINDOWS\system32\dltesbgw.dll__DELETE_ON_REBOOT
2008-06-26 11:01 . 2008-06-26 11:01 25,600 --a------ C:\WINDOWS\system32\rqRLbyaA.dll__DELETE_ON_REBOOT
2008-06-20 16:56 . 2008-06-20 16:56 <DIR> d-------- C:\Program Files\G-Mailto
2008-06-19 17:08 . 2008-04-14 05:42 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-06-19 17:08 . 2008-04-14 00:15 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-19 17:08 . 2008-04-14 00:15 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-19 17:08 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-06-17 23:14 . 2008-06-17 23:14 <DIR> d-------- C:\Documents and Settings\Sjef\Downloads
2008-06-17 23:14 . 2008-06-17 23:43 <DIR> d-------- C:\Documents and Settings\Sjef\Application Data\NewsLeecher
2008-06-17 23:11 . 2008-06-30 00:49 <DIR> d-------- C:\Program Files\NewsLeecher
2008-06-17 00:44 . 2008-06-17 00:46 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-06-17 00:44 . 2008-06-30 00:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-17 00:44 . 2008-06-17 00:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-17 00:44 . 2008-06-17 00:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-06-17 00:43 . 2008-06-17 00:44 435 --ah----- C:\IPH.PH
2008-06-17 00:42 . 2008-06-17 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-17 00:41 . 2008-06-30 00:52 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-15 16:51 . 2008-06-15 16:51 <DIR> d-------- C:\Program Files\WinAVI MP4 Converter
2008-06-11 08:18 . 2008-06-13 13:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:18 . 2008-06-13 13:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 12:23 . 2008-06-08 12:23 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-05 00:25 . 2008-06-05 00:25 <DIR> d-------- C:\Documents and Settings\Sjef\Application Data\Nokia Multimedia Player
2008-06-02 21:13 . 2008-06-02 21:13 <DIR> d-------- C:\Program Files\Gabest
2008-06-02 15:55 . 2008-06-02 15:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nokia
2008-06-02 15:49 . 2008-02-01 15:17 138,112 --a------ C:\WINDOWS\system32\drivers\nmwcdnsu.sys
2008-06-02 15:49 . 2008-02-01 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdnsuc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 22:31 757,036 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-06-30 15:09 --------- d-----w C:\Documents and Settings\Sjef\Application Data\LimeWire
2008-06-29 22:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-29 22:56 --------- d-----w C:\Documents and Settings\Sjef\Application Data\Samsung
2008-06-29 22:54 --------- d-----w C:\Program Files\Orb Networks
2008-06-27 17:06 --------- d-----w C:\Program Files\Webroot
2008-06-27 17:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2008-06-27 17:05 --------- d-----w C:\Documents and Settings\Sjef\Application Data\Webroot
2008-06-17 06:27 --------- d-----w C:\Program Files\FlashGet
2008-06-02 14:20 --------- d-----w C:\Documents and Settings\Sjef\Application Data\Nokia
2008-06-02 13:49 --------- d-----w C:\Program Files\Nokia
2008-06-02 13:49 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-02 13:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-05-25 17:08 --------- d-----w C:\Documents and Settings\Sjef\Application Data\PC Suite
2008-05-25 17:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-05-25 17:07 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-25 17:07 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-05-25 17:03 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-05-25 17:03 --------- d-----w C:\Program Files\DIFX
2008-05-25 17:03 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-05-25 16:59 --------- d-----w C:\Program Files\HooTech
2008-05-24 16:20 --------- d-----w C:\Documents and Settings\Sjef\Application Data\VanDale
2008-05-21 21:56 --------- d-----w C:\Documents and Settings\Sjef\Application Data\uTorrent
2008-05-21 13:10 --------- d-----w C:\Program Files\uTorrent
2008-05-15 13:34 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-05-15 13:20 --------- d-----w C:\Program Files\Samsung
2008-05-12 11:01 --------- d-----w C:\Program Files\Microsoft Encarta
2008-05-11 13:36 --------- d-----w C:\Program Files\Extension Changer
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 21:51 --------- d-----w C:\Documents and Settings\Sjef\Application Data\vlc
2008-05-07 20:36 --------- d-----w C:\Program Files\VideoLAN
2008-05-07 20:35 --------- d-----w C:\Program Files\FLV Player
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-03 16:31 --------- d-----w C:\Program Files\Rockstar Games
2008-05-03 16:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-03 14:46 --------- d-----w C:\Program Files\Alcohol Soft
2008-05-03 14:39 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-05-03 11:33 --------- d-----w C:\Documents and Settings\Sjef\Application Data\Vso
2008-05-03 11:32 87,608 ----a-w C:\Documents and Settings\Sjef\Application Data\inst.exe
2008-05-03 11:32 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-05-03 11:32 47,360 ----a-w C:\Documents and Settings\Sjef\Application Data\pcouffin.sys
2008-05-03 11:32 --------- d-----w C:\Program Files\VSO
2008-05-03 11:26 --------- d-----w C:\Documents and Settings\Sjef\Application Data\Nero
2008-05-03 11:25 --------- d-----w C:\Program Files\Common Files\Nero
2008-05-03 11:24 --------- d-----w C:\Program Files\Nero
2008-05-03 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-05-03 02:47 --------- d-----w C:\Program Files\Common Files\Webroot Shared
2008-05-03 02:22 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-03 02:07 --------- d-----w C:\Program Files\Realtek AC97
2008-05-03 01:37 --------- d-----w C:\Program Files\Real Alternative
2008-05-03 01:36 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-03 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-02 22:28 --------- d-----w C:\Program Files\Java
2008-05-02 22:18 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-02 22:12 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-02 22:12 --------- d-----w C:\Program Files\Windows Live
2008-05-02 22:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-02 22:03 --------- d-----w C:\Program Files\MSECache
2008-05-02 22:02 --------- d-----w C:\Program Files\Foxit Software
2008-05-02 22:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-02 22:01 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-05-02 21:55 --------- d-----w C:\Program Files\ESET
2008-05-02 21:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-05-02 21:38 --------- d-----w C:\Program Files\LimeWire
2008-05-02 21:38 --------- d-----w C:\Program Files\Common Files\Java
2008-05-02 21:09 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-23 05:26 10,760 ----a-w C:\WINDOWS\inst.reg
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 09:40 1,296,669 ----a-r C:\WINDOWS\SET3.tmp
2008-04-14 09:34 16,535 ----a-r C:\WINDOWS\SET8.tmp
2008-04-14 09:34 1,088,840 ----a-r C:\WINDOWS\SET4.tmp
2008-04-14 07:55 1,804 ----a-w C:\WINDOWS\system32\Dcache.bin
2008-04-14 07:51 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
2008-04-14 07:51 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
2008-04-14 07:51 483,840 ----a-w C:\WINDOWS\system32\wzcsvc.dll
2008-04-14 07:51 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
2008-04-14 07:51 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
2008-04-14 07:51 35,328 ----a-w C:\WINDOWS\system32\pid.dll
2008-04-14 07:51 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
2008-04-14 07:51 20,992 ----a-w C:\WINDOWS\system32\hid.dll
2008-04-14 07:51 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 07:51 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
2008-04-14 07:51 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
2008-04-14 07:46 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 07:43 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 07:43 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 07:43 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 07:43 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 07:41 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 07:40 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 07:40 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 07:40 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 07:40 102,912 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 05:42 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
2008-04-14 05:42 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
2008-04-14 05:41 21,504 ----a-w C:\WINDOWS\system32\hidserv.dll
2008-04-14 03:42 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
2008-04-14 03:41 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
2008-04-14 03:00 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 02:57 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
.

((((((((((((((((((((((((((((( [email protected]_16.52.41.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-30 14:50:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 22:31:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2001-07-14 15:32:24 69,632 ----a-w C:\WINDOWS\setupupd\temp\wsdueng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-02-22 17:58 217544]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 09:42 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 14:21 2213160]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 09:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-12-13 19:10 1688872 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-03-26 18:41 1232896 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 01:41 8523776 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-04-16 12:53 1079808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemBoot]
--a------ 2008-06-27 10:42 28672 C:\WINDOWS\conf32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\ccrss.exe"=

R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-11-26 14:47]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]

.
- - - - ORPHANS REMOVED - - - -

BHO-{38C6F42E-F880-4E49-8538-9E2B8E243E5A} - C:\WINDOWS\system32\tuvTnNHA.dll
BHO-{B22F0C6B-CAD1-4E5A-96D0-B6BB1C1DB7D4} - C:\WINDOWS\system32\xxyaaywU.dll
HKLM-Run-winsock32 - C:\WINDOWS\system32:winsock32.exe
HKLM-Run-PS Media Tunnel - C:\Program Files\Digital Integration Ltd\PS Media Tunnel\PSMediaTunnel.exe
HKLM-Run-20f5ffce - C:\WINDOWS\system32\ehdspeak.dll
Notify-rqRLbyaA - rqRLbyaA.dll
MSConfigStartUp-20f5ffce - C:\WINDOWS\system32\hfsglobp.dll
MSConfigStartUp-BM23c6cc52 - C:\WINDOWS\system32\twvfldxo.dll
MSConfigStartUp-Orb - C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe
MSConfigStartUp-ttecx_hdd_led_win_xp - C:\DOCUME~1\Sjef\LOCALS~1\Temp\Rar$EX00.594\ttecx_hdd_led_win_xp.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 00:31:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SoftwareDistribution\Download\f4bbe93413da6448b38093eb5244141e\update\update.exe
.
**************************************************************************
.
Completion time: 2008-07-03 0:36:40 - machine was rebooted [Sjef]
ComboFix-quarantined-files.txt 2008-07-02 22:36:29
ComboFix2.txt 2008-06-30 14:54:46

Pre-Run: 39,810,031,616 bytes free
Post-Run: 39,825,629,184 bytes free

305 --- E O F --- 2008-06-25 20:57:31

Edited by KoolAidGuy, 02 July 2008 - 04:50 PM.

  • 0

#7
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hello again KoolAidGuy,

Sorry for the delay. I haven't forgotten you and will be back. Just working on the correct "fix" for your problem.

Meanwhile.

Just out of curiousity.. How serious is this infection? Can I still do online banking? Write private emails to my friends?
And what other infections besides Virtumonde do I have?


Well I saw a Worm infection that is reported by Trend Micro to have the following capabilities:

* Delete Network Shares
* Disable and enable DCOM
* Disconnect and Reconnect to IRC Server
* Download and execute files
* Join to an IRC Channel
* Listen and executes Commands
* Obtain network and System Information
* Perform basic IRC Commands
* Scan ports to determine vulnerable system in the network
* Redirect HTTP, HTTPS, SOCKS and TCP streams
* Remove and update itself
* Perform SYN flood Attack
* Terminate processes

In your place I would stay off the internet as much as possible and use another "clean" computer to do my banking or use credit cards etc. until we have dealt with this. I would also change passwords.

regards,
emeraldnzl
  • 0

#8
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hello again KoolAidGuy,

Well finally here. :) Lets get down to clearing your computers infection.

No problem with running the Combofix.

Next

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    
    C:\WINDOWS\conf32.exe
    C:\WINDOWS\ccrss.exe
    purity
    
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Next

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

-----Step2-----

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

-----Step 3-----

Kaspersky only works if you are using Internet Explorer.

Please do an online scan with Kaspersky WebScanner.

Click on the Kaspersky Online Scanner button. A box will come up, click Accept, this will allow it to install an ActiveX component and download its latest anti-virus database. (Note: It may take a couple of minutes)

  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    * Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    * Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    * Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information in your next post.

So when you come back please post

* OTMoveIt2 log
* MBAM report
* Kaspersky scan results
* a fresh HijackThis log

Note: you will likely not fit these on one post, that's OK just use the number of posts you need.
  • 0

#9
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hey!

First of all, thanks again for helping.
I ran all programs you suggested. However, I believe ATF Cleaner didn't work. The history in Firefox nor IE was deleted and saved passwords were still in Firefox' memory (and I even terminated the processes in the Task Manager)..
Maybe I can use Webroot Window Washer to delete these files? It's a program I myself regularly use..
Meanwhile, here are the logs you requested :) .

Here is the log from MBAM
Malwarebytes' Anti-Malware 1.19
Database version: 927
Windows 5.1.2600 Service Pack 3

12:36:07 PM 7/6/2008
mbam-log-7-6-2008 (12-36-07).txt

Scan type: Quick Scan
Objects scanned: 39495
Time elapsed: 4 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\opnMdApn.dll__DELETE_ON_REBOOT (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRLbyaA.dll__DELETE_ON_REBOOT (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


Here's the OTMoveIt log
Explorer killed successfully
File/Folder not found.
C:\WINDOWS\conf32.exe moved successfully.
C:\WINDOWS\ccrss.exe moved successfully.
< purity >
File/Folder not found.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07062008_122714


And finally, attached you can find the Kaspersky online scanner report.

Edit: It surprised me that none of the programs prompted me to reboot.. Should I still reboot?

Attached Files


Edited by KoolAidGuy, 06 July 2008 - 06:09 AM.

  • 0

#10
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hello again KoolAidGuy,

Thanks for the logs so far.

Can I have that new HijackThis log. :)

Yep go ahead and reboot.

regards
emeraldnzl
  • 0

Advertisements


#11
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hey!

Sorry, completely forgot;)..

Here it is.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:38 PM, on 7/7/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Onderzoekscentrum - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1209812350046
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://62.100.53.122...sCamControl.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 6995 bytes

  • 0

#12
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hi KoolAidGuy,

Looks pretty good to me now.

In this post I would like to make sure a file that Kaspersky picked up as Trojan-Downloader.WMA.Wimad.n is dealt with or is no longer there.

Clear away Combofix and the baddies it has quarantined.

After that and before our final clean up carry out a last scan to make sure you are completely clean. :)
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Documents and Settings\Sjef\My Documents\Shared\Kilie Minogue - Can't get blue monday out of my head.mp3
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Next

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image

Then

Kaspersky only works if you are using Internet Explorer.

Please do another online scan with Kaspersky WebScanner.

Click on the Kaspersky Online Scanner button. A box will come up, click Accept, this will allow it to install an ActiveX component and download its latest anti-virus database. (Note: It may take a couple of minutes)

  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    * Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    * Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    * Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information in your next post.

So when you come back please post
  • the log from OTMoveIt2
  • the scan results from Kaspersky
  • let me know how your computer is running now

  • 0

#13
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hello again.

I had a quick look at the OTMoveIt log, but when I closed it I couldn't find it anymore after the uninstall of ComboFix and the Kaspersky scan..
However, is said the file had been sucessfully moved.. :) .
I have attached the Kaspersky log.
My computer is running much better now, although it's still a bit slower than it used to be..

Attached Files


  • 0

#14
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 19,989 posts
Hi there KoolAidGuy,

Well we still have two bad files left.

In this post lets try and get rid of them.

You say that while your computer is running better it is still slower than before. To make sure there is nothing we have missed that may be causing this we can have a deeper look with a Deckards System Scan.

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\dltesbgw.dll__DELETE_ON_REBOOT
    C:\WINDOWS\system32\exgjevar.dll__DELETE_ON_REBOOT
    purity
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Next

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

So when you come back please post
  • OTMoveIt2 log
  • both Deckards System Scan reports

  • 0

#15
KoolAidGuy

KoolAidGuy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Hello,

Here are the logs as requested. I hope everything is ok now.

Sjef

Attached Files


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP