![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
I am constantly recieving popups. I have tried multiple different methods of trying to clean this system (SpyBot S&D, Lavasoft Adaware, Kespersky, Online virus scanners, both in regular and safemode... And.. I am being defeated.
Multiple vendors show that the PC is infected with VUNDO/Virtumonde and multiple other instances of spyware/malware/downloaders. It has removed all previous system restore points, also. I have followed the recommended 5 steps and here is my output. I have tried running dss.exe but keep getting a failure message near the end of the process. ----------------------\ Panda Active Scan Logs| ----------------------/ Incident Status Location Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\yxrydtuy.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\mfhvgowg.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\vtuurop.dll Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\smt99n4d.default\cookies.txt[statse.webtrendslive.com/] Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WHQZW1A3\gamadril20071203[1] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.com.com/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.statcounter.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[statse.webtrendslive.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.247realmedia.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.advertising.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.overture.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Angela\Cookies\angela@ad.yieldmanager[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Angela\Cookies\angela@atwola[2].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Angela\Cookies\angela@target[2].txt Adware:Adware/Adband Not disinfected C:\Program Files\Mozilla Firefox\vvqq.exe[ism.exe] Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\S-1-5-21-440593713-3975872581-4289829859-1006\Dc48.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\wghaycdb.dll ----------------------\ HijackThis Log | ----------------------/ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:10:17 PM, on 1/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\mfhvgowg.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F3 - REG:win.ini: load=C:\WINDOWS\system32\gebyv.exe O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\yxrydtuy.dll",b O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: DomainService - - C:\WINDOWS\system32\mfhvgowg.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 7453 bytes |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
Ok I was able to run VundoFix and remove a few files. I am now able to run DSS. Here is the output.
Deckard's System Scanner v20071014.68 Run by Angela on 2008-01-08 00:23:45 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- -- Last 2 Restore Point(s) -- 2: 2008-01-08 01:49:30 UTC - RP2 - Deckard's System Scanner Restore Point 1: 2008-01-06 02:21:34 UTC - RP1 - System Checkpoint Backed up registry hives. Performed disk cleanup. Total Physical Memory: 511 MiB (512 MiB recommended). -- HijackThis (run as Angela.exe) ---------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:24:44 AM, on 1/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\mfhvgowg.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Angela\Desktop\dss.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F3 - REG:win.ini: load=C:\WINDOWS\system32\gebyv.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: {365d642b-3313-b70a-2154-90d4c70dd839} - {938dd07c-4d09-4512-a07b-3133b246d563} - C:\WINDOWS\system32\ytaibnhy.dll (file missing) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\vtuurop.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\yxrydtuy.dll",b O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: DomainService - - C:\WINDOWS\system32\mfhvgowg.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 8237 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R2 VMnetBridge (VMware Bridge Protocol) - c:\windows\system32\drivers\vmnetbridge.sys <Not Verified; VMware, Inc.; VMware bridge driver (32-bit)> R2 VMnetuserif (VMware Network Application Interface) - c:\windows\system32\drivers\vmnetuserif.sys <Not Verified; VMware, Inc.; VMware network application interface driver (32-bit)> R2 vmx86 (VMware vmx86) - c:\windows\system32\drivers\vmx86.sys <Not Verified; VMware, Inc.; VMware kernel driver> R2 vstor2 (Vstor2 Virtual Storage Driver) - c:\program files\common files\vmware\vmware virtual image editing\vstor2.sys <Not Verified; VMware, Inc.; VMware Virtual Machine Importer> S3 BDFsDrv - c:\program files\softwin\bitdefender10\bdfsdrv.sys (file missing) S3 BDRsDrv - c:\program files\softwin\bitdefender10\bdrsdrv.sys (file missing) S3 SDTHOOK - c:\windows\system32\drivers\sdthook.sys <Not Verified; Panda Software; Panda® Antivirus> S3 sscdbus (SAMSUNG USB Composite Device driver (WDM)) - c:\windows\system32\drivers\sscdbus.sys <Not Verified; MCCI; SAMSUNG USB Composite Device> S3 sscdmdfl (SAMSUNG CDMA Modem Filter) - c:\windows\system32\drivers\sscdmdfl.sys <Not Verified; MCCI; SAMSUNG CDMA Modem Filter Driver> S3 sscdmdm (SAMSUNG CDMA Modem Drivers) - c:\windows\system32\drivers\sscdmdm.sys <Not Verified; MCCI; SAMSUNG CDMA Modem> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 DomainService - c:\windows\system32\mfhvgowg.exe /service <Not Verified; ; DDC> R2 VMAuthdService (VMware Authorization Service) - c:\program files\vmware\vmware server\vmware-authd.exe <Not Verified; VMware, Inc.; VMware Server> R2 VMnetDHCP (VMware DHCP Service) - c:\windows\system32\vmnetdhcp.exe <Not Verified; VMware, Inc.; VMware Server> R2 vmount2 (VMware Virtual Mount Manager Extended) - "c:\program files\common files\vmware\vmware virtual image editing\vmount2.exe" <Not Verified; VMware, Inc.; VMware Virtual Machine Importer> R2 vmserverdWin32 (VMware Registration Service) - c:\program files\vmware\vmware server\vmserverdwin32.exe <Not Verified; VMware, Inc.; VMware Server> R2 VMware NAT Service - c:\windows\system32\vmnat.exe <Not Verified; VMware, Inc.; VMware Server> S3 hpqwmi (HP WMI Interface) - c:\program files\hpq\shared\hpqwmi.exe <Not Verified; Hewlett-Packard Development Company, L.P.; hpqwmi Module> -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Files created between 2007-12-08 and 2008-01-08 ----------------------------- 2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups 2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library> 2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster 2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus> 2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver> 2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro 2008-01-07 16:56:05 74304 -----n--- C:\WINDOWS\system32\mfhvgowg.exe <Not Verified; ; DDC> 2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8 2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan 2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com 2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia 2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6 2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun 2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender 2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin 2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6 2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-01-05 14:49:50 0 d-------- C:\WINDOWS\?racle 2008-01-05 11:12:09 40448 -----n--- C:\WINDOWS\system32\vtuurop.dll 2008-01-05 11:12:06 2 --a------ C:\WINDOWS\system32\wnsapisv.exe 2008-01-05 11:11:53 0 d-------- C:\WINDOWS\system32\s?stem32 -- Find3M Report --------------------------------------------------------------- 2008-01-07 20:09:31 0 d-------- C:\Program Files\Google 2008-01-07 20:08:54 0 d-------- C:\Program Files\Common Files\LightScribe 2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime 2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger 2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes 2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files 2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2 2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}] C:\WINDOWS\system32\gebyv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{938dd07c-4d09-4512-a07b-3133b246d563}] C:\WINDOWS\system32\ytaibnhy.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}] 01/05/2008 11:12 AM 40448 --------- C:\WINDOWS\system32\vtuurop.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [] "HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [] "BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE" [] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [] "75a17511"="C:\WINDOWS\system32\yxrydtuy.dll" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" [] "Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}"= C:\WINDOWS\system32\vtuurop.dll [01/05/2008 11:12 AM 40448] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=sockspy.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}] AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe -- End of Deckard's System Scanner: finished at 2008-01-08 00:26:12 ------------ Last edited by PAHUNTER21; 01-07-2008 at 10:57 PM. |
|
|
|
|
#4 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
Hi, if you still need assistance, please post a fresh main.txt log
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
Deckard's System Scanner v20071014.68
Run by Angela on 2008-01-15 20:01:28 Computer is in Normal Mode. -------------------------------------------------------------------------------- Total Physical Memory: 511 MiB (512 MiB recommended). -- HijackThis (run as Angela.exe) ---------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:01:32 PM, on 1/15/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Documents and Settings\Angela\Desktop\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F3 - REG:win.ini: load=C:\WINDOWS\system32\geeby.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {4541DD8B-5D11-478E-B443-DA833D5A8698} - C:\WINDOWS\system32\geeby.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: {b254e7ec-ac62-b17a-6d94-3450cb667d2a} - {a2d766bc-0543-49d6-a71b-26cace7e452b} - C:\WINDOWS\system32\bruhixas.dll (file missing) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\vtuurop.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\rrcgvlmw.dll",b O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\mfhvgowg.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 8459 bytes -- Files created between 2007-12-15 and 2008-01-15 ----------------------------- 2008-01-09 21:47:23 0 d-------- C:\Documents and Settings\Angela\Application Data\Wireshark 2008-01-09 20:43:33 0 d-------- C:\Program Files\WinPcap 2008-01-09 20:43:08 0 d-------- C:\Program Files\Wireshark 2008-01-08 21:11:06 0 d-------- C:\Program Files\Western Digital Technologies 2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups 2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library> 2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster 2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus> 2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver> 2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro 2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8 2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan 2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com 2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia 2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6 2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun 2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender 2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin 2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6 2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-01-05 14:49:50 0 d-------- C:\WINDOWS\?racle 2008-01-05 11:12:06 2 --a------ C:\WINDOWS\system32\wnsapisv.exe 2008-01-05 11:11:53 0 d-------- C:\WINDOWS\system32\s?stem32 -- Find3M Report --------------------------------------------------------------- 2008-01-08 20:54:22 0 d-------- C:\Program Files\Common Files\LightScribe 2008-01-08 20:53:40 0 d-------- C:\Program Files\Google 2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime 2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger 2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes 2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files 2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2 2007-11-06 15:19:28 53299 --a------ C:\WINDOWS\system32\pthreadVC.dll 2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}] C:\WINDOWS\system32\geeby.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}] C:\WINDOWS\system32\gebyv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}] C:\WINDOWS\system32\bruhixas.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}] C:\WINDOWS\system32\vtuurop.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [] "HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [] "BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [01/05/2008 09:02 PM] "75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" [] "Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}"= C:\WINDOWS\system32\vtuurop.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=sockspy.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\WINDOWS\system32\geeby [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}] AutoRun\command- E:\wd_windows_tools\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}] AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe *Newly Created Service* - NM *Newly Created Service* - NPF -- End of Deckard's System Scanner: finished at 2008-01-15 20:02:06 ------------ |
|
|
|
|
#6 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
Hi,
Download combofix.exe
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
Combo Fix Log
ComboFix 08-01-20.1 - Angela 2008-01-20 21:36:51.1 - NTFSx86 Running from: C:\Documents and Settings\Angela\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . The following files were disabled during the run: C:\WINDOWS\system32\sockspy.dll ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Angela\My Documents\SSTEM~1 C:\WINDOWS\cookies.ini C:\WINDOWS\racle~1 C:\WINDOWS\racle~1\?racle\ C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\sstem3~1 C:\WINDOWS\system32\wnsapisv.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_DOMAINSERVICE -------\LEGACY_NTNDIS -------\DomainService ((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 ))))))))))))))))))))))))))))))) . 2008-01-20 21:35 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-09 21:47 . 2008-01-09 21:47 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Wireshark 2008-01-09 20:43 . 2008-01-09 20:44 <DIR> d-------- C:\Program Files\Wireshark 2008-01-09 20:43 . 2008-01-09 20:43 <DIR> d-------- C:\Program Files\WinPcap 2008-01-08 21:11 . 2008-01-08 21:11 <DIR> d-------- C:\Program Files\Western Digital Technologies 2008-01-08 19:18 . 2008-01-08 19:18 1,054,902 ---hs---- C:\WINDOWS\system32\wmlvgcrr.ini 2008-01-08 19:12 . 2008-01-08 19:12 1,054,842 ---hs---- C:\WINDOWS\system32\wksrjupn.ini 2008-01-08 00:04 . 2008-01-08 19:46 <DIR> d-------- C:\VundoFix Backups 2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\drivers\wlluc48.sys 2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\dllcache\wlluc48.sys 2008-01-07 20:49 . 2008-01-07 20:49 <DIR> d-------- C:\Deckard 2008-01-07 20:43 . 2008-01-08 20:28 <DIR> d-------- C:\Program Files\SpywareBlaster 2008-01-07 20:43 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL 2008-01-07 20:43 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX 2008-01-07 19:47 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS 2008-01-07 19:46 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys 2008-01-07 19:33 . 2008-01-07 19:33 <DIR> d-------- C:\Program Files\Trend Micro 2008-01-07 16:59 . 2008-01-07 19:24 1,043,815 ---hs---- C:\WINDOWS\system32\bdcyahgw.ini 2008-01-07 16:59 . 2008-01-07 23:57 534 ---hs---- C:\WINDOWS\system32\yutdyrxy.ini 2008-01-06 23:47 . 2008-01-05 20:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-01-06 23:45 . 2008-01-07 08:04 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-01-06 22:53 . 2008-01-08 21:04 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2008-01-06 22:53 . 2008-01-08 20:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico 2008-01-06 22:53 . 2008-01-08 20:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico 2008-01-06 22:53 . 2008-01-08 20:47 1,406 --a------ C:\WINDOWS\system32\Help.ico 2008-01-06 20:49 . 2008-01-06 20:49 <DIR> d-------- C:\WINDOWS\McAfee.com 2008-01-05 20:28 . 2008-01-06 23:47 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6 2008-01-05 20:25 . 2005-05-11 23:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-05 20:25 . 2005-05-11 23:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-01-05 17:48 . 2008-01-05 17:48 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender 2008-01-05 17:22 . 2008-01-20 21:45 81,984 --a------ C:\WINDOWS\system32\bdod.bin 2008-01-05 17:21 . 2008-01-05 17:27 <DIR> d-------- C:\Documents and Settings\Angela\.housecall6.6 2008-01-05 17:15 . 2008-01-05 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-01-05 14:47 . 2008-01-05 21:18 311,296 --a------ C:\WINDOWS\system32\hphmon03 .exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-21 02:47 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware 2008-01-21 02:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware 2008-01-09 01:54 --------- d-----w C:\Program Files\Common Files\LightScribe 2008-01-09 01:53 --------- d-----w C:\Program Files\Google 2008-01-07 05:18 --------- d-----w C:\Program Files\QuickTime 2008-01-07 05:14 --------- d-----w C:\Program Files\iTunes 2007-12-03 02:55 --------- d-----w C:\Documents and Settings\Angela\Application Data\OpenOffice.org2 2007-10-25 15:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe . Code:
<pre> ----a-w 253,952 2008-01-06 02:18:39 C:\hp\drivers\hplsbwatcher\lsburnwatcher .exe ----a-w 339,968 2008-01-06 02:18:36 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe ----a-w 49,152 2008-01-06 02:18:35 C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe ----a-w 233,534 2008-01-06 02:18:39 C:\Program Files\HPQ\Default Settings\cpqset .exe ----a-w 794,624 2008-01-06 02:18:38 C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe ----a-w 290,816 2008-01-06 02:18:37 C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe ----a-w 278,528 2008-01-06 02:18:42 C:\Program Files\iTunes\iTunesHelper .exe ----a-w 36,975 2008-01-06 02:18:34 C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe ----a-w 282,624 2008-01-06 02:02:40 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-06 02:02:40 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-06 02:02:40 C:\Program Files\QuickTime\qttask .exe ----a-w 69,632 2008-01-06 02:18:44 C:\Program Files\Softwin\BitDefender10\bdagent .exe ----a-w 290,816 2008-01-06 02:18:42 C:\Program Files\Softwin\BitDefender10\BDMCON~1 .EXE ----a-w 692,316 2008-01-06 02:18:38 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe ----a-w 102,492 2008-01-06 02:18:35 C:\Program Files\Synaptics\SynTP\SynTPLpr .exe ----a-w 311,296 2008-01-06 02:18:40 C:\WINDOWS\system32\hphmon03 .exe ----a-w 196,608 2008-01-06 02:18:40 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe </pre> ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}] C:\WINDOWS\system32\geeby.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}] C:\WINDOWS\system32\gebyv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}] C:\WINDOWS\system32\bruhixas.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" [ ] "Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [ ] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [ ] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [ ] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [ ] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [ ] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [ ] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [ ] "HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [ ] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [ ] "BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2008-01-05 21:02 290816] "75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=sockspy.dll R2 vmserverdWin32;VMware Registration Service;C:\Program Files\VMware\VMware Server\vmserverdWin32.exe [2006-08-09 14:40] R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 09:39] S3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2006-01-13 01:46] S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 15:22] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}] \Shell\AutoRun\command - E:\wd_windows_tools\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}] \Shell\AutoRun\command - E:\JDSecure\Windows\JDSecure20.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-20 21:47:20 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\sockspy.dll PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180] -> C:\WINDOWS\system32\sockspy.dll PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\WINDOWS\system32\sockspy.dll . Completion time: 2008-01-20 21:50:30 - machine was rebooted ComboFix-quarantined-files.txt 2008-01-21 02:49:40 . 2008-01-09 00:22:00 --- E O F --- HijackThis Log Deckard's System Scanner v20071014.68 Run by Angela on 2008-01-20 21:55:09 Computer is in Normal Mode. -------------------------------------------------------------------------------- Total Physical Memory: 511 MiB (512 MiB recommended). -- HijackThis (run as Angela.exe) ---------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:55:19 PM, on 1/20/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Angela\Desktop\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {4541DD8B-5D11-478E-B443-DA833D5A8698} - C:\WINDOWS\system32\geeby.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: {b254e7ec-ac62-b17a-6d94-3450cb667d2a} - {a2d766bc-0543-49d6-a71b-26cace7e452b} - C:\WINDOWS\system32\bruhixas.dll (file missing) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\rrcgvlmw.dll",b O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 8311 bytes -- Files created between 2007-12-20 and 2008-01-20 ----------------------------- 2008-01-09 21:47:23 0 d-------- C:\Documents and Settings\Angela\Application Data\Wireshark 2008-01-09 20:43:33 0 d-------- C:\Program Files\WinPcap 2008-01-09 20:43:08 0 d-------- C:\Program Files\Wireshark 2008-01-08 21:11:06 0 d-------- C:\Program Files\Western Digital Technologies 2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups 2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library> 2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster 2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus> 2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver> 2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro 2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8 2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan 2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com 2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia 2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6 2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun 2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents 2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities 2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender 2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin 2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6 2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender -- Find3M Report --------------------------------------------------------------- 2008-01-08 20:54:22 0 d-------- C:\Program Files\Common Files\LightScribe 2008-01-08 20:53:40 0 d-------- C:\Program Files\Google 2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime 2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger 2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes 2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files 2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2 2007-11-06 15:19:28 53299 --a------ C:\WINDOWS\system32\pthreadVC.dll 2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}] C:\WINDOWS\system32\geeby.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}] C:\WINDOWS\system32\gebyv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}] C:\WINDOWS\system32\bruhixas.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [] "HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [] "BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [01/05/2008 09:02 PM] "75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" [] "Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" [] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=sockspy.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}] AutoRun\command- E:\wd_windows_tools\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}] AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe -- End of Deckard's System Scanner: finished at 2008-01-20 21:55:45 ------------ |
|
|
|
|
#8 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
Hi,
Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". In 2006, this may change, read Viewpoint to Plunge Into Adware. If you decide to remove it, please go to start > control panel > add/remove programs then uninstall viewpoint from there. Delete this folder if you uninstalled viewpoint: C:\Program Files\Viewpoint ________ Combofix Deletions
Code:
Killall::
File::
C:\WINDOWS\system32\yutdyrxy.ini
C:\WINDOWS\system32\bdcyahgw.ini
C:\WINDOWS\system32\wmlvgcrr.ini
C:\WINDOWS\system32\wksrjupn.ini
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
Folder::
C:\VundoFix Backups
RENV::
----a-w 253,952 2008-01-06 02:18:39 C:\hp\drivers\hplsbwatcher\lsburnwatcher .exe
----a-w 339,968 2008-01-06 02:18:36 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w 49,152 2008-01-06 02:18:35 C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
----a-w 233,534 2008-01-06 02:18:39 C:\Program Files\HPQ\Default Settings\cpqset .exe
----a-w 794,624 2008-01-06 02:18:38 C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
----a-w 290,816 2008-01-06 02:18:37 C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe
----a-w 278,528 2008-01-06 02:18:42 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 36,975 2008-01-06 02:18:34 C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
----a-w 282,624 2008-01-06 02:02:40 C:\Program Files\QuickTime\qttask .exe
----a-w 69,632 2008-01-06 02:18:44 C:\Program Files\Softwin\BitDefender10\bdagent .exe
----a-w 290,816 2008-01-06 02:18:42 C:\Program Files\Softwin\BitDefender10\BDMCON~1 .EXE
----a-w 692,316 2008-01-06 02:18:38 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w 102,492 2008-01-06 02:18:35 C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
----a-w 311,296 2008-01-06 02:18:40 C:\WINDOWS\system32\hphmon03 .exe
----a-w 196,608 2008-01-06 02:18:40 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
Registry::
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mfhvgowg.exe"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"=-
"Puin"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"75a17511"=-
Please do an online scan with Kaspersky WebScanner Warning: If you had kaspersky online scanner installed before 10-5-2007, please uninstall it as kaspersky released a new version. Previous version had a serious flaw which could result in a buffer overflow. You will be promted to install an ActiveX component from Kaspersky, Click Yes.
__________ Your Java is out of date.... Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components.
On your next reply, please include a
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. Last edited by Angelfire777; 01-21-2008 at 01:20 AM. |
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
Combofix does not seem to be restarting the computer nor is it producing a log file.
Once I drag the CFScript.txt file to the ComboFix executable, the combofix terminal pops up and states that it will produce a log file, then it dissapears and does nothing else.. Do you have any suggestions? Or would you like the Kaspersky and HijackThis logs? |
|
|
|
|
#10 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
That's odd..
Please disable ALL your active security programs just this time then repeat the CFScript step. See if it will produce a log. If it still won't, try doing it in safe mode. To enter Safe Mode.. Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
HijackThis Log
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:37:08 PM, on 1/21/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe C:\WINDOWS\system32\hphmon03.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HPQ\SHARED\HPQWMI.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 8511 bytes Kaspersky Log ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Monday, January 21, 2008 9:34:06 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 21/01/2008 Kaspersky Anti-Virus database records: 526188 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 51750 Number of viruses found: 14 Number of infected objects: 36 Number of suspicious objects: 2 Duration of the scan process: 01:06:10 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516 NSIS: infected - 1 skipped C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516 CryptFF.b: infected - 1 skipped C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516 NSIS: infected - 1 skipped C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516 CryptFF.b: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\mfhvgowg.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\npujrskw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\rrcgvlmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\vtuurop.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\0102\0310\values Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cert8.db Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\formhistory.dat Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\history.dat Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\key3.db Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\parent.lock Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\search.sqlite Object is locked skipped C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Angela\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3614 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3793 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3795 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3798 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3851 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3854 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3855 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3856 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095 Infected: not-a-virus:PSWTool.Win32.RAS.a skipped C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe Inno: infected - 11 skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Angela\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Angela\Local Settings\History\History.IE5\MSHist012008012120080122\index.dat Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Angela\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Angela\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Angela\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Mozilla Firefox\vvqq.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped C:\Program Files\Mozilla Firefox\vvqq.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped C:\Program Files\Mozilla Firefox\vvqq.exe NSIS: infected - 2 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP1\A0002034.exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP1\A0002035.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP14\change.log Object is locked skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0002063.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.av skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0002063.exe CAB: infected - 1 skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0004040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0005040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006046.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006048.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP3\A0006079.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP3\A0006080.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{ECED0377-36C2-4003-98D0-59A54FD002C8}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\bdss.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_90.dat Object is locked skipped C:\WINDOWS\Temp\tmp00002e68\tmp00000000 Object is locked skipped C:\WINDOWS\Temp\vmware-serverd.log Object is locked skipped C:\WINDOWS\Temp\vmware-vmount.log Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. ComboFix Log ComboFix 08-01-20.1 - Angela 2008-01-21 19:52:31.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.213 [GMT -5:00] Running from: C:\Documents and Settings\Angela\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Angela\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE C:\Program Files\QuickTime\qttask .exe C:\Program Files\QuickTime\qttask .exe C:\WINDOWS\system32\bdcyahgw.ini C:\WINDOWS\system32\wksrjupn.ini C:\WINDOWS\system32\wmlvgcrr.ini C:\WINDOWS\system32\yutdyrxy.ini . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\QuickTime\qttask .exe C:\Program Files\QuickTime\qttask .exe C:\VundoFix Backups C:\VundoFix Backups\addmorefiles.txt C:\VundoFix Backups\geeby.dll.bad C:\VundoFix Backups\vybeg.ini.bad C:\VundoFix Backups\vybeg.ini2.bad C:\VundoFix Backups\ybeeg.ini.bad C:\VundoFix Backups\ybeeg.ini2.bad C:\WINDOWS\system32\bdcyahgw.ini C:\WINDOWS\system32\wksrjupn.ini C:\WINDOWS\system32\wmlvgcrr.ini C:\WINDOWS\system32\yutdyrxy.ini . ((((((((((((((((((((((((( Files Created from 2007-12-22 to 2008-01-22 ))))))))))))))))))))))))))))))) . 2008-01-20 21:35 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-09 21:47 . 2008-01-09 21:47 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Wireshark 2008-01-09 20:43 . 2008-01-09 20:44 <DIR> d-------- C:\Program Files\Wireshark 2008-01-09 20:43 . 2008-01-09 20:43 <DIR> d-------- C:\Program Files\WinPcap 2008-01-08 21:11 . 2008-01-08 21:11 <DIR> d-------- C:\Program Files\Western Digital Technologies 2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\drivers\wlluc48.sys 2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\dllcache\wlluc48.sys 2008-01-07 20:49 . 2008-01-07 20:49 <DIR> d-------- C:\Deckard 2008-01-07 20:43 . 2008-01-08 20:28 <DIR> d-------- C:\Program Files\SpywareBlaster 2008-01-07 20:43 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL 2008-01-07 20:43 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX 2008-01-07 19:47 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS 2008-01-07 19:46 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys 2008-01-07 19:33 . 2008-01-07 19:33 <DIR> d-------- C:\Program Files\Trend Micro 2008-01-06 23:47 . 2008-01-05 20:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-01-06 23:45 . 2008-01-07 08:04 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-01-06 22:53 . 2008-01-08 21:04 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2008-01-06 22:53 . 2008-01-08 20:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico 2008-01-06 22:53 . 2008-01-08 20:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico 2008-01-06 22:53 . 2008-01-08 20:47 1,406 --a------ C:\WINDOWS\system32\Help.ico 2008-01-06 20:49 . 2008-01-06 20:49 <DIR> d-------- C:\WINDOWS\McAfee.com 2008-01-05 20:28 . 2008-01-06 23:47 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6 2008-01-05 20:25 . 2005-05-11 23:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-05 20:25 . 2005-05-11 23:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-01-05 17:48 . 2008-01-05 17:48 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender 2008-01-05 17:22 . 2008-01-21 19:58 81,984 --a------ C:\WINDOWS\system32\bdod.bin 2008-01-05 17:21 . 2008-01-05 17:27 <DIR> d-------- C:\Documents and Settings\Angela\.housecall6.6 2008-01-05 17:15 . 2008-01-05 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-01-05 14:47 . 2008-01-05 21:18 311,296 --a------ C:\WINDOWS\system32\hphmon03.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-22 00:59 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware 2008-01-22 00:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware 2008-01-22 00:57 --------- d-----w C:\Program Files\QuickTime 2008-01-22 00:52 --------- d-----w C:\Program Files\iTunes 2008-01-21 13:07 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\VMware 2008-01-09 01:54 --------- d-----w C:\Program Files\Common Files\LightScribe 2008-01-09 01:53 --------- d-----w C:\Program Files\Google 2007-12-03 02:55 --------- d-----w C:\Documents and Settings\Angela\Application Data\OpenOffice.org2 2007-10-25 15:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe . ((((((((((((((((((((((((((((( snapshot_2008-01-21_19.46.36.10 ))))))))))))))))))))))))))))))))))))))))) . - 2008-01-21 12:51:21 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001\NTUSER.DAT + 2008-01-22 00:52:17 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001\NTUSER.DAT - 2008-01-21 12:51:21 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002\UsrClass.dat + 2008-01-22 00:52:17 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002\UsrClass.dat - 2008-01-21 12:51:21 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003\NTUSER.DAT + 2008-01-22 00:52:17 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003\NTUSER.DAT - 2008-01-21 12:51:22 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004\UsrClass.dat + 2008-01-22 00:52:17 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004\UsrClass.dat - 2008-01-21 12:51:22 3,817,472 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005\NTUSER.DAT + 2008-01-22 00:52:17 3,817,472 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005\NTUSER.DAT - 2008-01-21 12:51:22 98,304 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006\UsrClass.dat + 2008-01-22 00:52:18 98,304 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006\UsrClass.dat - 2008-01-21 12:51:22 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000007\UsrClass.dat + 2008-01-22 00:52:18 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000007\UsrClass.dat + 2006-01-27 01:19:52 73,728 ----a-w C:\WINDOWS\system32\sockspy.dll + 2008-01-06 02:18:40 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-01-05 21:18 339968] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2008-01-05 21:18 36975] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2008-01-05 21:18 794624] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-01-05 21:18 49152] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2008-01-05 21:18 102492] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-05 21:18 692316] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2008-01-05 21:18 290816] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2008-01-05 21:18 253952] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2008-01-05 21:18 233534] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2008-01-05 21:18 196608] "HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [2008-01-05 21:18 311296] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-05 21:18 278528] "QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2008-01-05 21:18 69632] "BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2008-01-05 21:02 290816] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=sockspy.dll R2 vmserverdWin32;VMware Registration Service;C:\Program Files\VMware\VMware Server\vmserverdWin32.exe [2006-08-09 14:40] R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 09:39] S3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2006-01-13 01:46] S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 15:22] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}] \Shell\AutoRun\command - E:\wd_windows_tools\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}] \Shell\AutoRun\command - E:\JDSecure\Windows\JDSecure20.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-21 19:59:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????7?2?5?8??????? ???B?????????????hLC? ?????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-21 20:03:28 - machine was rebooted ComboFix-quarantined-files.txt 2008-01-22 01:02:37 ComboFix2.txt 2008-01-22 00:48:05 ComboFix3.txt 2008-01-21 02:50:32 . 2008-01-09 00:22:00 --- E O F --- |
|
|
|
|
#12 (permalink) |
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
Hi,
Please delete this file: C:\Program Files\Mozilla Firefox\vvqq.exe Delete the contents of these folders: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine ______ Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System ![]() Download the file & save it as it's originally named, next to ComboFix.exe. ![]() Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log. Please do not reboot your machine until we have reviewed the log. _______ Your Java is out of date.... Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components.
On your next reply, please include a
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2
|
Re: Constant popups/slow pc - Virtumonde infection
User Experience / Machine Status
Well, I am happy to announce that i have not seen a popup for many days now. System speed has returned to normal, and all seems well. I have updated Java as per your suggestion. So all and all, it seems like it is back to my normal and stable system. I am not seeing any anomalous network activity sourcing from or destined to my machine. You deserve a BIG THANK YOU! I still wish I knew how this thing got infected. Being a comp security professional myself (more on the networking and IDS side) I think I have it pinned down... Two things: My wife & MySpace, specifically a MySpace theme generator. I'm just not sure what app/plugin was exploited. Thanks for helping me on the system side! CF-RC.txt LOG WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons HijackThis LOG Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:26:45 PM, on 1/22/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe C:\WINDOWS\system32\hphmon03.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\VMware\VMware Server\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\VMware\VMware Server\vmserverdWin32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HPQ\SHARED\HPQWMI.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 8415 bytes |
|
|
|
|
#14 (permalink) | ||
|
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Oct 2006
Posts: 4,580
OS: Vista
|
Re: Constant popups/slow pc - Virtumonde infection
Hi,
Quote:
Quote:
Open HijackThis > choose Scan Only > Place a checkmark in the boxes beside these entries in bold. This line is legit but it isn't the right file. A similar O4 entry would be created the next time quicktime starts. O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime Close your browsers and all open windows except for HijackThis, then click "Fix checked". Exit HijackThis. ______ Congratulations! Your log looks clean! Click start > run > copy and paste: combofix /u That will hide your system files, clear your system restore cache and uninstall combofix. Here are some free programs I recommend that could help you improve your pc's security. MVPS Hosts File ~You can download it from here ~I highly recommend this hosts file. You can learn more about this here Install SpyWare Blaster ~You can download it from here ~You can read the tutorial on how to use Spyware Blaster here Install WinPatrol ~You can download it from here ~You can get some information about how WinPatrol works here Note: Make sure you update your Antivirus programs and other security products regularly to avoid new threats that could infect your system. Please check out Tony Klein's article "How did I get infected in the first place?" Happy safe surfing! Note: Please reply to this thread one last time so I could close it.
__________________
UNITE and ASAP since 2006 ![]() If we have helped you, please consider donating. The past won't be able to hurt you unless you keep on looking back at it. |
||
|
|
| Thread Tools | |
|
|