Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 01-07-2008, 07:16 PM   #1 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Evil Constant popups/slow pc - Virtumonde infection

I am constantly recieving popups. I have tried multiple different methods of trying to clean this system (SpyBot S&D, Lavasoft Adaware, Kespersky, Online virus scanners, both in regular and safemode... And.. I am being defeated.

Multiple vendors show that the PC is infected with VUNDO/Virtumonde and multiple other instances of spyware/malware/downloaders.

It has removed all previous system restore points, also.

I have followed the recommended 5 steps and here is my output.

I have tried running dss.exe but keep getting a failure message near the end of the process.

----------------------\
Panda Active Scan Logs|
----------------------/

Incident Status Location

Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\yxrydtuy.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\mfhvgowg.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\vtuurop.dll
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\smt99n4d.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WHQZW1A3\gamadril20071203[1]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.com.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.overture.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Angela\Cookies\angela@ad.yieldmanager[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Angela\Cookies\angela@atwola[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Angela\Cookies\angela@target[2].txt
Adware:Adware/Adband Not disinfected C:\Program Files\Mozilla Firefox\vvqq.exe[ism.exe]
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\S-1-5-21-440593713-3975872581-4289829859-1006\Dc48.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\wghaycdb.dll


----------------------\
HijackThis Log |
----------------------/

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:10:17 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mfhvgowg.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\gebyv.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\yxrydtuy.dll",b
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv
O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\mfhvgowg.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 7453 bytes

PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-07-2008, 10:30 PM   #2 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

Ok I was able to run VundoFix and remove a few files. I am now able to run DSS. Here is the output.

Deckard's System Scanner v20071014.68
Run by Angela on 2008-01-08 00:23:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------



-- Last 2 Restore Point(s) --
2: 2008-01-08 01:49:30 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-01-06 02:21:34 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as Angela.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:44 AM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mfhvgowg.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Angela\Desktop\dss.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\gebyv.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: {365d642b-3313-b70a-2154-90d4c70dd839} - {938dd07c-4d09-4512-a07b-3133b246d563} - C:\WINDOWS\system32\ytaibnhy.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\vtuurop.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\yxrydtuy.dll",b
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv
O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\mfhvgowg.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 8237 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 VMnetBridge (VMware Bridge Protocol) - c:\windows\system32\drivers\vmnetbridge.sys <Not Verified; VMware, Inc.; VMware bridge driver (32-bit)>
R2 VMnetuserif (VMware Network Application Interface) - c:\windows\system32\drivers\vmnetuserif.sys <Not Verified; VMware, Inc.; VMware network application interface driver (32-bit)>
R2 vmx86 (VMware vmx86) - c:\windows\system32\drivers\vmx86.sys <Not Verified; VMware, Inc.; VMware kernel driver>
R2 vstor2 (Vstor2 Virtual Storage Driver) - c:\program files\common files\vmware\vmware virtual image editing\vstor2.sys <Not Verified; VMware, Inc.; VMware Virtual Machine Importer>

S3 BDFsDrv - c:\program files\softwin\bitdefender10\bdfsdrv.sys (file missing)
S3 BDRsDrv - c:\program files\softwin\bitdefender10\bdrsdrv.sys (file missing)
S3 SDTHOOK - c:\windows\system32\drivers\sdthook.sys <Not Verified; Panda Software; Panda® Antivirus>
S3 sscdbus (SAMSUNG USB Composite Device driver (WDM)) - c:\windows\system32\drivers\sscdbus.sys <Not Verified; MCCI; SAMSUNG USB Composite Device>
S3 sscdmdfl (SAMSUNG CDMA Modem Filter) - c:\windows\system32\drivers\sscdmdfl.sys <Not Verified; MCCI; SAMSUNG CDMA Modem Filter Driver>
S3 sscdmdm (SAMSUNG CDMA Modem Drivers) - c:\windows\system32\drivers\sscdmdm.sys <Not Verified; MCCI; SAMSUNG CDMA Modem>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 DomainService - c:\windows\system32\mfhvgowg.exe /service <Not Verified; ; DDC>
R2 VMAuthdService (VMware Authorization Service) - c:\program files\vmware\vmware server\vmware-authd.exe <Not Verified; VMware, Inc.; VMware Server>
R2 VMnetDHCP (VMware DHCP Service) - c:\windows\system32\vmnetdhcp.exe <Not Verified; VMware, Inc.; VMware Server>
R2 vmount2 (VMware Virtual Mount Manager Extended) - "c:\program files\common files\vmware\vmware virtual image editing\vmount2.exe" <Not Verified; VMware, Inc.; VMware Virtual Machine Importer>
R2 vmserverdWin32 (VMware Registration Service) - c:\program files\vmware\vmware server\vmserverdwin32.exe <Not Verified; VMware, Inc.; VMware Server>
R2 VMware NAT Service - c:\windows\system32\vmnat.exe <Not Verified; VMware, Inc.; VMware Server>

S3 hpqwmi (HP WMI Interface) - c:\program files\hpq\shared\hpqwmi.exe <Not Verified; Hewlett-Packard Development Company, L.P.; hpqwmi Module>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2007-12-08 and 2008-01-08 -----------------------------

2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups
2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster
2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus>
2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro
2008-01-07 16:56:05 74304 -----n--- C:\WINDOWS\system32\mfhvgowg.exe <Not Verified; ; DDC>
2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8
2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com
2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender
2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6
2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-05 14:49:50 0 d-------- C:\WINDOWS\?racle
2008-01-05 11:12:09 40448 -----n--- C:\WINDOWS\system32\vtuurop.dll
2008-01-05 11:12:06 2 --a------ C:\WINDOWS\system32\wnsapisv.exe
2008-01-05 11:11:53 0 d-------- C:\WINDOWS\system32\s?stem32


-- Find3M Report ---------------------------------------------------------------

2008-01-07 20:09:31 0 d-------- C:\Program Files\Google
2008-01-07 20:08:54 0 d-------- C:\Program Files\Common Files\LightScribe
2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime
2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger
2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes
2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files
2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2
2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
C:\WINDOWS\system32\gebyv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{938dd07c-4d09-4512-a07b-3133b246d563}]
C:\WINDOWS\system32\ytaibnhy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}]
01/05/2008 11:12 AM 40448 --------- C:\WINDOWS\system32\vtuurop.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" []
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" []
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" []
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\BDMCON~1.EXE" []
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" []
"75a17511"="C:\WINDOWS\system32\yxrydtuy.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" []
"Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}"= C:\WINDOWS\system32\vtuurop.dll [01/05/2008 11:12 AM 40448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyv


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}]
AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe




-- End of Deckard's System Scanner: finished at 2008-01-08 00:26:12 ------------

Attached Files
File Type: txt extra.txt (15.6 KB, 4 views)

Last edited by PAHUNTER21; 01-07-2008 at 10:57 PM.
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-10-2008, 01:37 PM   #3 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

Bump.
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-15-2008, 03:41 AM   #4 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

Hi, if you still need assistance, please post a fresh main.txt log
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-15-2008, 06:05 PM   #5 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

Deckard's System Scanner v20071014.68
Run by Angela on 2008-01-15 20:01:28
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as Angela.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:32 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Documents and Settings\Angela\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\geeby.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4541DD8B-5D11-478E-B443-DA833D5A8698} - C:\WINDOWS\system32\geeby.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: {b254e7ec-ac62-b17a-6d94-3450cb667d2a} - {a2d766bc-0543-49d6-a71b-26cace7e452b} - C:\WINDOWS\system32\bruhixas.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\vtuurop.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\rrcgvlmw.dll",b
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv
O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\mfhvgowg.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 8459 bytes

-- Files created between 2007-12-15 and 2008-01-15 -----------------------------

2008-01-09 21:47:23 0 d-------- C:\Documents and Settings\Angela\Application Data\Wireshark
2008-01-09 20:43:33 0 d-------- C:\Program Files\WinPcap
2008-01-09 20:43:08 0 d-------- C:\Program Files\Wireshark
2008-01-08 21:11:06 0 d-------- C:\Program Files\Western Digital Technologies
2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups
2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster
2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus>
2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro
2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8
2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com
2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender
2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6
2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-05 14:49:50 0 d-------- C:\WINDOWS\?racle
2008-01-05 11:12:06 2 --a------ C:\WINDOWS\system32\wnsapisv.exe
2008-01-05 11:11:53 0 d-------- C:\WINDOWS\system32\s?stem32


-- Find3M Report ---------------------------------------------------------------

2008-01-08 20:54:22 0 d-------- C:\Program Files\Common Files\LightScribe
2008-01-08 20:53:40 0 d-------- C:\Program Files\Google
2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime
2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger
2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes
2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files
2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2
2007-11-06 15:19:28 53299 --a------ C:\WINDOWS\system32\pthreadVC.dll
2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}]
C:\WINDOWS\system32\geeby.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
C:\WINDOWS\system32\gebyv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}]
C:\WINDOWS\system32\bruhixas.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}]
C:\WINDOWS\system32\vtuurop.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" []
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" []
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" []
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" []
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [01/05/2008 09:02 PM]
"75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" []
"Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}"= C:\WINDOWS\system32\vtuurop.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geeby


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}]
AutoRun\command- E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}]
AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe

*Newly Created Service* - NM
*Newly Created Service* - NPF



-- End of Deckard's System Scanner: finished at 2008-01-15 20:02:06 ------------

PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-16-2008, 03:02 AM   #6 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

Hi,

Download combofix.exe
  • Save it to your desktop.
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply along with a fresh HijackThis log.
Note:
  • In case you already used Combofix previously, please delete the version you are having and redownload it again, because Combofix is being updated everyday.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • Do not post the ComboFix-quarantined-files.txt - unless I ask you to.
  • If your Antivirus software is detecting combofix or a part of it as a virus, please choose to ignore it as Antivirus products cannot determine the good/bad use of some softwares embedded in combofix.
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-20-2008, 07:59 PM   #7 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

Combo Fix Log
ComboFix 08-01-20.1 - Angela 2008-01-20 21:36:51.1 - NTFSx86
Running from: C:\Documents and Settings\Angela\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\WINDOWS\system32\sockspy.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Angela\My Documents\SSTEM~1
C:\WINDOWS\cookies.ini
C:\WINDOWS\racle~1
C:\WINDOWS\racle~1\?racle\
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\wnsapisv.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NTNDIS
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 21:35 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-09 21:47 . 2008-01-09 21:47 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Wireshark
2008-01-09 20:43 . 2008-01-09 20:44 <DIR> d-------- C:\Program Files\Wireshark
2008-01-09 20:43 . 2008-01-09 20:43 <DIR> d-------- C:\Program Files\WinPcap
2008-01-08 21:11 . 2008-01-08 21:11 <DIR> d-------- C:\Program Files\Western Digital Technologies
2008-01-08 19:18 . 2008-01-08 19:18 1,054,902 ---hs---- C:\WINDOWS\system32\wmlvgcrr.ini
2008-01-08 19:12 . 2008-01-08 19:12 1,054,842 ---hs---- C:\WINDOWS\system32\wksrjupn.ini
2008-01-08 00:04 . 2008-01-08 19:46 <DIR> d-------- C:\VundoFix Backups
2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\drivers\wlluc48.sys
2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\dllcache\wlluc48.sys
2008-01-07 20:49 . 2008-01-07 20:49 <DIR> d-------- C:\Deckard
2008-01-07 20:43 . 2008-01-08 20:28 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-07 20:43 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-01-07 20:43 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-07 19:47 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-07 19:46 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys
2008-01-07 19:33 . 2008-01-07 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-07 16:59 . 2008-01-07 19:24 1,043,815 ---hs---- C:\WINDOWS\system32\bdcyahgw.ini
2008-01-07 16:59 . 2008-01-07 23:57 534 ---hs---- C:\WINDOWS\system32\yutdyrxy.ini
2008-01-06 23:47 . 2008-01-05 20:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-06 23:45 . 2008-01-07 08:04 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-01-06 22:53 . 2008-01-08 21:04 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-06 22:53 . 2008-01-08 20:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-06 22:53 . 2008-01-08 20:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-06 22:53 . 2008-01-08 20:47 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-06 20:49 . 2008-01-06 20:49 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-01-05 20:28 . 2008-01-06 23:47 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-05 20:25 . 2005-05-11 23:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-05 20:25 . 2005-05-11 23:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-05 17:48 . 2008-01-05 17:48 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender
2008-01-05 17:22 . 2008-01-20 21:45 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-01-05 17:21 . 2008-01-05 17:27 <DIR> d-------- C:\Documents and Settings\Angela\.housecall6.6
2008-01-05 17:15 . 2008-01-05 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-05 14:47 . 2008-01-05 21:18 311,296 --a------ C:\WINDOWS\system32\hphmon03 .exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 02:47 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware
2008-01-21 02:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware
2008-01-09 01:54 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-01-09 01:53 --------- d-----w C:\Program Files\Google
2008-01-07 05:18 --------- d-----w C:\Program Files\QuickTime
2008-01-07 05:14 --------- d-----w C:\Program Files\iTunes
2007-12-03 02:55 --------- d-----w C:\Documents and Settings\Angela\Application Data\OpenOffice.org2
2007-10-25 15:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
.
Code:
<pre>
----a-w           253,952 2008-01-06 02:18:39  C:\hp\drivers\hplsbwatcher\lsburnwatcher .exe
----a-w           339,968 2008-01-06 02:18:36  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w            49,152 2008-01-06 02:18:35  C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
----a-w           233,534 2008-01-06 02:18:39  C:\Program Files\HPQ\Default Settings\cpqset .exe
----a-w           794,624 2008-01-06 02:18:38  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
----a-w           290,816 2008-01-06 02:18:37  C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe
----a-w           278,528 2008-01-06 02:18:42  C:\Program Files\iTunes\iTunesHelper .exe
----a-w            36,975 2008-01-06 02:18:34  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
----a-w           282,624 2008-01-06 02:02:40  C:\Program Files\QuickTime\qttask   .exe
----a-w           282,624 2008-01-06 02:02:40  C:\Program Files\QuickTime\qttask  .exe
----a-w           282,624 2008-01-06 02:02:40  C:\Program Files\QuickTime\qttask .exe
----a-w            69,632 2008-01-06 02:18:44  C:\Program Files\Softwin\BitDefender10\bdagent .exe
----a-w           290,816 2008-01-06 02:18:42  C:\Program Files\Softwin\BitDefender10\BDMCON~1 .EXE
----a-w           692,316 2008-01-06 02:18:38  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w           102,492 2008-01-06 02:18:35  C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
----a-w           311,296 2008-01-06 02:18:40  C:\WINDOWS\system32\hphmon03 .exe
----a-w           196,608 2008-01-06 02:18:40  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
</pre>

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}]
C:\WINDOWS\system32\geeby.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
C:\WINDOWS\system32\gebyv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}]
C:\WINDOWS\system32\bruhixas.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" [ ]
"Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [ ]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [ ]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [ ]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [ ]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [ ]
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [ ]
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2008-01-05 21:02 290816]
"75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll

R2 vmserverdWin32;VMware Registration Service;C:\Program Files\VMware\VMware Server\vmserverdWin32.exe [2006-08-09 14:40]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 09:39]
S3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2006-01-13 01:46]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 15:22]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}]
\Shell\AutoRun\command - E:\JDSecure\Windows\JDSecure20.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 21:47:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\sockspy.dll

PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\sockspy.dll

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\sockspy.dll
.
Completion time: 2008-01-20 21:50:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 02:49:40
.
2008-01-09 00:22:00 --- E O F ---


HijackThis Log

Deckard's System Scanner v20071014.68
Run by Angela on 2008-01-20 21:55:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as Angela.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:55:19 PM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Angela\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Angela.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4541DD8B-5D11-478E-B443-DA833D5A8698} - C:\WINDOWS\system32\geeby.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {73538613-EF18-4628-8EB6-BD2F5F870216} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: {b254e7ec-ac62-b17a-6d94-3450cb667d2a} - {a2d766bc-0543-49d6-a71b-26cace7e452b} - C:\WINDOWS\system32\bruhixas.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [75a17511] rundll32.exe "C:\WINDOWS\system32\rrcgvlmw.dll",b
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\RACLE~1\regsvr32.exe" -vt ndrv
O4 - HKCU\..\Run: [Puin] "C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 8311 bytes

-- Files created between 2007-12-20 and 2008-01-20 -----------------------------

2008-01-09 21:47:23 0 d-------- C:\Documents and Settings\Angela\Application Data\Wireshark
2008-01-09 20:43:33 0 d-------- C:\Program Files\WinPcap
2008-01-09 20:43:08 0 d-------- C:\Program Files\Wireshark
2008-01-08 21:11:06 0 d-------- C:\Program Files\Western Digital Technologies
2008-01-08 00:04:09 0 d-------- C:\VundoFix Backups
2008-01-07 20:43:15 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-01-07 20:43:14 0 d-------- C:\Program Files\SpywareBlaster
2008-01-07 19:47:44 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus>
2008-01-07 19:46:26 8576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-01-07 19:33:16 0 d-------- C:\Program Files\Trend Micro
2008-01-06 23:45:51 0 d-------- C:\WINDOWS\BDOSCAN8
2008-01-06 22:53:00 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-06 20:49:37 0 d-------- C:\WINDOWS\McAfee.com
2008-01-05 20:28:49 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-01-05 20:28:07 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-05 20:26:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-01-05 20:25:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-01-05 20:25:04 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-05 20:25:04 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-05 20:25:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-05 20:25:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-05 20:25:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-01-05 20:25:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-05 20:25:03 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-01-05 17:48:09 0 d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender
2008-01-05 17:22:00 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-01-05 17:21:07 0 d-------- C:\Documents and Settings\Angela\.housecall6.6
2008-01-05 17:15:29 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender


-- Find3M Report ---------------------------------------------------------------

2008-01-08 20:54:22 0 d-------- C:\Program Files\Common Files\LightScribe
2008-01-08 20:53:40 0 d-------- C:\Program Files\Google
2008-01-07 00:18:42 0 d-------- C:\Program Files\QuickTime
2008-01-07 00:15:20 0 d-------- C:\Program Files\Messenger
2008-01-07 00:14:27 0 d-------- C:\Program Files\iTunes
2008-01-05 17:12:00 0 d-------- C:\Program Files\Common Files
2007-12-02 21:55:12 0 d-------- C:\Documents and Settings\Angela\Application Data\OpenOffice.org2
2007-11-06 15:19:28 53299 --a------ C:\WINDOWS\system32\pthreadVC.dll
2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}]
C:\WINDOWS\system32\geeby.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
C:\WINDOWS\system32\gebyv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}]
C:\WINDOWS\system32\bruhixas.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" []
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" []
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" []
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" []
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" []
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [01/05/2008 09:02 PM]
"75a17511"="C:\WINDOWS\system32\rrcgvlmw.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"="C:\WINDOWS\RACLE~1\regsvr32.exe" []
"Puin"="C:\Documents and Settings\Angela\My Documents\s?stem\?ti2evxx.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}]
AutoRun\command- E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}]
AutoRun\command- E:\JDSecure\Windows\JDSecure20.exe




-- End of Deckard's System Scanner: finished at 2008-01-20 21:55:45 ------------

PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 01:18 AM   #8 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

Hi,

Viewpoint, Viewpoint Manager, Viewpoint Media Player
are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". In 2006, this may change, read Viewpoint to Plunge Into Adware.

If you decide to remove it, please go to start > control panel > add/remove programs then uninstall viewpoint from there.

Delete this folder if you uninstalled viewpoint:

C:\Program Files\Viewpoint
________

Combofix Deletions
  • Open notepad.
  • Copy and paste the text inside the code box below to notepad
Code:
Killall::

File::
C:\WINDOWS\system32\yutdyrxy.ini
C:\WINDOWS\system32\bdcyahgw.ini
C:\WINDOWS\system32\wmlvgcrr.ini
C:\WINDOWS\system32\wksrjupn.ini
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
Folder::
C:\VundoFix Backups

RENV::
----a-w           253,952 2008-01-06 02:18:39  C:\hp\drivers\hplsbwatcher\lsburnwatcher .exe
----a-w           339,968 2008-01-06 02:18:36  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w            49,152 2008-01-06 02:18:35  C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
----a-w           233,534 2008-01-06 02:18:39  C:\Program Files\HPQ\Default Settings\cpqset .exe
----a-w           794,624 2008-01-06 02:18:38  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
----a-w           290,816 2008-01-06 02:18:37  C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe
----a-w           278,528 2008-01-06 02:18:42  C:\Program Files\iTunes\iTunesHelper .exe
----a-w            36,975 2008-01-06 02:18:34  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
----a-w           282,624 2008-01-06 02:02:40  C:\Program Files\QuickTime\qttask   .exe
----a-w            69,632 2008-01-06 02:18:44  C:\Program Files\Softwin\BitDefender10\bdagent .exe
----a-w           290,816 2008-01-06 02:18:42  C:\Program Files\Softwin\BitDefender10\BDMCON~1 .EXE
----a-w           692,316 2008-01-06 02:18:38  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w           102,492 2008-01-06 02:18:35  C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
----a-w           311,296 2008-01-06 02:18:40  C:\WINDOWS\system32\hphmon03 .exe
----a-w           196,608 2008-01-06 02:18:40  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe

Registry::
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mfhvgowg.exe"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4541DD8B-5D11-478E-B443-DA833D5A8698}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73538613-EF18-4628-8EB6-BD2F5F870216}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d766bc-0543-49d6-a71b-26cace7e452b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tbsa"=-
"Puin"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"75a17511"=-
  • Save and Name it as "CFScript"
  • Drag and drop CFScript.txt to your copy of combofix.
  • You can take a look at the image below if you're unsure on how to do it.
  • Combofix wil restart your machine then it will produce a log afterwards.
  • Please post the contents of that log along with a fresh HijackThis log.
______

Please do an online scan with Kaspersky WebScanner

Warning: If you had kaspersky online scanner installed before 10-5-2007, please uninstall it as kaspersky released a new version. Previous version had a serious flaw which could result in a buffer overflow.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
    • Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
__________

Your Java is out of date....
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components.
  • Click Start > Control Panel
  • Click Add/Remove Programs
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download Java Runtime Environment 6u4, and install it to your computer.

On your next reply, please include a
  • Fresh HijackThis log (not main.txt)
  • kaspersky scan log
  • combofix log
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.

Last edited by Angelfire777; 01-21-2008 at 01:20 AM.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 07:02 AM   #9 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

Combofix does not seem to be restarting the computer nor is it producing a log file.

Once I drag the CFScript.txt file to the ComboFix executable, the combofix terminal pops up and states that it will produce a log file, then it dissapears and does nothing else..

Do you have any suggestions? Or would you like the Kaspersky and HijackThis logs?
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 07:20 AM   #10 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

That's odd..

Please disable ALL your active security programs just this time then repeat the CFScript step. See if it will produce a log.

If it still won't, try doing it in safe mode.

To enter Safe Mode..

Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 07:41 PM   #11 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:37:08 PM, on 1/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 8511 bytes


Kaspersky Log

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 9:34:06 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 526188
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 51750
Number of viruses found: 14
Number of infected objects: 36
Number of suspicious objects: 2
Duration of the scan process: 01:06:10

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516 NSIS: infected - 1 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq.exe.bac_a00516 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516 NSIS: infected - 1 skipped
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\zzqq[1].exe.bac_a00516 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\mfhvgowg.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\npujrskw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\rrcgvlmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine\vtuurop.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\0102\0310\values Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\cert8.db Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\history.dat Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\key3.db Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\parent.lock Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Angela\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Angela\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3614 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3793 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3795 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3798 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3851 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3854 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3855 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file3856 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe/file4095 Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Angela\Desktop\UBCD4WinV310.exe Inno: infected - 11 skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Application Data\Mozilla\Firefox\Profiles\xolbgccm.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\History\History.IE5\MSHist012008012120080122\index.dat Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Angela\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Angela\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Angela\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Mozilla Firefox\vvqq.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\Program Files\Mozilla Firefox\vvqq.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\Program Files\Mozilla Firefox\vvqq.exe NSIS: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP1\A0002034.exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP1\A0002035.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP14\change.log Object is locked skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0002063.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.av skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0002063.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0004040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0005040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006046.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP2\A0006048.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP3\A0006079.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP3\A0006080.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{ECED0377-36C2-4003-98D0-59A54FD002C8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bdss.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_90.dat Object is locked skipped
C:\WINDOWS\Temp\tmp00002e68\tmp00000000 Object is locked skipped
C:\WINDOWS\Temp\vmware-serverd.log Object is locked skipped
C:\WINDOWS\Temp\vmware-vmount.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


ComboFix Log

ComboFix 08-01-20.1 - Angela 2008-01-21 19:52:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.213 [GMT -5:00]
Running from: C:\Documents and Settings\Angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Angela\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\WINDOWS\system32\bdcyahgw.ini
C:\WINDOWS\system32\wksrjupn.ini
C:\WINDOWS\system32\wmlvgcrr.ini
C:\WINDOWS\system32\yutdyrxy.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\geeby.dll.bad
C:\VundoFix Backups\vybeg.ini.bad
C:\VundoFix Backups\vybeg.ini2.bad
C:\VundoFix Backups\ybeeg.ini.bad
C:\VundoFix Backups\ybeeg.ini2.bad
C:\WINDOWS\system32\bdcyahgw.ini
C:\WINDOWS\system32\wksrjupn.ini
C:\WINDOWS\system32\wmlvgcrr.ini
C:\WINDOWS\system32\yutdyrxy.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-22 to 2008-01-22 )))))))))))))))))))))))))))))))
.

2008-01-20 21:35 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-09 21:47 . 2008-01-09 21:47 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Wireshark
2008-01-09 20:43 . 2008-01-09 20:44 <DIR> d-------- C:\Program Files\Wireshark
2008-01-09 20:43 . 2008-01-09 20:43 <DIR> d-------- C:\Program Files\WinPcap
2008-01-08 21:11 . 2008-01-08 21:11 <DIR> d-------- C:\Program Files\Western Digital Technologies
2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\drivers\wlluc48.sys
2008-01-07 23:07 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\dllcache\wlluc48.sys
2008-01-07 20:49 . 2008-01-07 20:49 <DIR> d-------- C:\Deckard
2008-01-07 20:43 . 2008-01-08 20:28 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-07 20:43 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-01-07 20:43 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-07 19:47 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-07 19:46 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\mkqlwktpdijl.sys
2008-01-07 19:33 . 2008-01-07 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-06 23:47 . 2008-01-05 20:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-06 23:45 . 2008-01-07 08:04 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-01-06 22:53 . 2008-01-08 21:04 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-06 22:53 . 2008-01-08 20:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-06 22:53 . 2008-01-08 20:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-06 22:53 . 2008-01-08 20:47 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-06 20:49 . 2008-01-06 20:49 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-01-05 20:28 . 2008-01-06 23:47 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-05 20:25 . 2005-05-11 23:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-05 20:25 . 2005-05-11 23:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-05 17:48 . 2008-01-05 17:48 <DIR> d-------- C:\Documents and Settings\Angela\Application Data\Bitdefender
2008-01-05 17:22 . 2008-01-21 19:58 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-01-05 17:21 . 2008-01-05 17:27 <DIR> d-------- C:\Documents and Settings\Angela\.housecall6.6
2008-01-05 17:15 . 2008-01-05 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-05 14:47 . 2008-01-05 21:18 311,296 --a------ C:\WINDOWS\system32\hphmon03.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-22 00:59 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware
2008-01-22 00:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware
2008-01-22 00:57 --------- d-----w C:\Program Files\QuickTime
2008-01-22 00:52 --------- d-----w C:\Program Files\iTunes
2008-01-21 13:07 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\VMware
2008-01-09 01:54 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-01-09 01:53 --------- d-----w C:\Program Files\Google
2007-12-03 02:55 --------- d-----w C:\Documents and Settings\Angela\Application Data\OpenOffice.org2
2007-10-25 15:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
.

((((((((((((((((((((((((((((( snapshot_2008-01-21_19.46.36.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 12:51:21 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-22 00:52:17 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-21 12:51:21 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-22 00:52:17 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-21 12:51:21 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-22 00:52:17 229,376 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-21 12:51:22 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-22 00:52:17 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-21 12:51:22 3,817,472 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-22 00:52:17 3,817,472 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-21 12:51:22 98,304 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-22 00:52:18 98,304 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-21 12:51:22 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000007\UsrClass.dat
+ 2008-01-22 00:52:18 8,192 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\Users\00000007\UsrClass.dat
+ 2006-01-27 01:19:52 73,728 ----a-w C:\WINDOWS\system32\sockspy.dll
+ 2008-01-06 02:18:40 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-01-05 21:18 339968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2008-01-05 21:18 36975]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2008-01-05 21:18 794624]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-01-05 21:18 49152]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2008-01-05 21:18 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-05 21:18 692316]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2008-01-05 21:18 290816]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2008-01-05 21:18 253952]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2008-01-05 21:18 233534]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2008-01-05 21:18 196608]
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [2008-01-05 21:18 311296]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-05 21:18 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2008-01-05 21:18 69632]
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2008-01-05 21:02 290816]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll

R2 vmserverdWin32;VMware Registration Service;C:\Program Files\VMware\VMware Server\vmserverdWin32.exe [2006-08-09 14:40]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-03-22 09:39]
S3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2006-01-13 01:46]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 15:22]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18289c3e-be56-11dc-b741-005056c00008}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61137052-5388-11dc-b728-005056c00008}]
\Shell\AutoRun\command - E:\JDSecure\Windows\JDSecure20.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 19:59:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????7?2?5?8??????? ???B?????????????hLC? ??????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-21 20:03:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-22 01:02:37
ComboFix2.txt 2008-01-22 00:48:05
ComboFix3.txt 2008-01-21 02:50:32
.
2008-01-09 00:22:00 --- E O F ---
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-22-2008, 04:06 AM   #12 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

Hi,

Please delete this file:

C:\Program Files\Mozilla Firefox\vvqq.exe

Delete the contents of these folders:

C:\Documents and Settings\Administrator\.housecall6.6\Quarantine
C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Quarantine
______

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System





Download the file & save it as it's originally named, next to ComboFix.exe.






Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
_______

Your Java is out of date....
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components.
  • Click Start > Control Panel
  • Click Add/Remove Programs
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download Java Runtime Environment 6u4, and install it to your computer.

On your next reply, please include a
  • Fresh HijackThis log.
  • A detailed description on how's your machine running.
  • CF_RC.txt contents
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-22-2008, 04:44 PM   #13 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

User Experience / Machine Status

Well, I am happy to announce that i have not seen a popup for many days now. System speed has returned to normal, and all seems well. I have updated Java as per your suggestion. So all and all, it seems like it is back to my normal and stable system. I am not seeing any anomalous network activity sourcing from or destined to my machine. You deserve a BIG THANK YOU!

I still wish I knew how this thing got infected. Being a comp security professional myself (more on the networking and IDS side) I think I have it pinned down... Two things: My wife & MySpace, specifically a MySpace theme generator. I'm just not sure what app/plugin was exploited. Thanks for helping me on the system side!


CF-RC.txt LOG
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons


HijackThis LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:45 PM, on 1/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142796829733
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...00/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 8415 bytes
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-23-2008, 02:28 AM   #14 (permalink)
Moderator/Analyst, Security Team ; Rangemaster, TSF Academy
 
Angelfire777's Avatar
 
Join Date: Oct 2006
Posts: 4,580
OS: Vista


Re: Constant popups/slow pc - Virtumonde infection

Hi,

Quote:
Well, I am happy to announce that i have not seen a popup for many days now. System speed has returned to normal, and all seems well. I have updated Java as per your suggestion. So all and all, it seems like it is back to my normal and stable system. I am not seeing any anomalous network activity sourcing from or destined to my machine. You deserve a BIG THANK YOU!
You're welcome!
Quote:
I still wish I knew how this thing got infected. Being a comp security professional myself (more on the networking and IDS side) I think I have it pinned down... Two things: My wife & MySpace, specifically a MySpace theme generator. I'm just not sure what app/plugin was exploited. Thanks for helping me on the system side!
MySpace is really dubious when it comes to security...Too many exploits in my opinion..I can't say for sure though..


Open HijackThis > choose Scan Only > Place a checkmark in the boxes beside these entries in bold.

This line is legit but it isn't the right file. A similar O4 entry would be created the next time quicktime starts.

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime

Close your browsers and all open windows except for HijackThis, then click "Fix checked". Exit HijackThis.
______

Congratulations! Your log looks clean!

Click start > run > copy and paste:

combofix /u

That will hide your system files, clear your system restore cache and uninstall combofix.


Here are some free programs I recommend that could help you improve your pc's security.

MVPS Hosts File
~You can download it from here
~I highly recommend this hosts file. You can learn more about this here

Install SpyWare Blaster
~You can download it from here
~You can read the tutorial on how to use Spyware Blaster here

Install WinPatrol
~You can download it from here
~You can get some information about how WinPatrol works here

Note: Make sure you update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"

Happy safe surfing!

Note: Please reply to this thread one last time so I could close it.
__________________
UNITE and ASAP since 2006


If we have helped you, please consider donating.

The past won't be able to hurt you unless you keep on looking back at it.
Angelfire777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-24-2008, 07:39 AM   #15 (permalink)
Registered User
 
Join Date: Jan 2008
Posts: 12
OS: WinXP SP2


Re: Constant popups/slow pc - Virtumonde infection

RESOLVED!!!

Thank You!
PAHUNTER21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:20 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85