Virtumonde / Gone, Except For Registry Entry.

Posted 04 March 2008 - 12:47 PM

I have been able to clean (or so I believe) the virtumonde/vundo/ms metajuan problem. I have ran the following scanners and all report clean:

- Symantec Corporate
- Spybot S&D
- Malwarebytes Anti-Malware
- Ad-Aware SE
- VundoFix
- VirtumundoBeGone

I have also used "Free Windos Registry Cleaner" which is not perfect, but helps a bit... and finaly HJT.

After rebooting the pc, the following message pops up:

"Error loading C:\WINDOWS\System32\ubuyjehq.dll. The specified module could not be found"

I found that this and a lot of other similar .dlls (8characters.dll) size about 1218kb rename themselves and come back right in with a new random name (8characters.dll) after being deleted manually. It seems that all .dlls are gone now but this final registry entry behaves the same way. When I delete it manually, it comes back in.

here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:29 AM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\05 software\VundoFix.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.taeit.com/home.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://nic.neoris.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://npmosax.exe/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = TAEit
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = fcinetmty01:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = portal4.femcom.net;*.local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: {898468bf-2873-3278-9344-888b1ad304bd} - {db403da1-b888-4439-8723-3782fb864898} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis1.exe
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\EZSP_PX.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\System32\bcmntray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [04d7eda5] rundll32.exe "C:\WINDOWS\system32\ubuyjehq.dll",b
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://nic.neoris.net
O15 - Trusted Zone: http://forums.neoris.net (HKLM)
O15 - Trusted Zone: http://historydb.neoris.net (HKLM)
O15 - Trusted Zone: http://km.neoris.net (HKLM)
O15 - Trusted Zone: http://myad.neoris.net (HKLM)
O15 - Trusted Zone: http://myresume.neoris.net (HKLM)
O15 - Trusted Zone: http://nic.neoris.net (HKLM)
O15 - Trusted Zone: http://nyp.neoris.net (HKLM)
O15 - Trusted Zone: http://portalconosur.neoris.net (HKLM)
O15 - Trusted Zone: http://sac.neoris.net (HKLM)
O15 - Trusted Zone: http://servicecenter.neoris.net (HKLM)
O15 - Trusted Zone: http://servmonitor.neoris.net (HKLM)
O15 - Trusted Zone: http://siebel.neoris.net (HKLM)
O15 - Trusted Zone: http://sif.neoris.net (HKLM)
O15 - Trusted Zone: http://wecare.neoris.net (HKLM)
O15 - Trusted Zone: http://yellowpages.neoris.net (HKLM)
O15 - Trusted IP range: (HKLM)
O15 - ESC Trusted Zone: http://view.atdmt.com (HKLM)
O15 - ESC Trusted Zone: http://search.live.com (HKLM)
O15 - ESC Trusted Zone: http://*.live.com (HKLM)
O15 - ESC Trusted Zone: http://myinfo.neoris.net (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://cmalanis/qcbin/Spider90.ocx
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator -
O16 - DPF: {B2FC031D-8C74-46AE-8042-BCF4FC03C1EF} (Loader Class v4) - http://fctcmty01:8090/qcbin/Spider91.cab
O16 - DPF: {D6A6A09C-C43C-4BCC-90B0-349B71239328} (AXfco Control) -
O16 - DPF: {E09150AF-9388-450B-8098-0B4F6BBE1419} (Ultimus) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nortam.eaglegl.com,eaglegl.com,egl.corp,gateway.2wire.net,nortam.eaglegl.com,eaglegl.com,egl.corp,nortam.eaglegl.com,eaglegl.com,egl.corp
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nortam.eaglegl.com,eaglegl.com,egl.corp,gateway.2wire.net,nortam.eaglegl.com,eaglegl.com,egl.corp,nortam.eaglegl.com,eaglegl.com,egl.corp
O18 - Protocol: HTLFP - (no CLSID) - (no file)
O18 - Protocol: vfsp - (no CLSID) - (no file)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

End of file - 11043 bytes

thanks for your help.

Edited by mercado, 04 March 2008 - 01:09 PM.

Posted 05 March 2008 - 11:37 AM

I just got it Fixed!

I guess, (and am almost sure), some entries could not be removed from the registry thanks to lavasoft's "Ad-Watch" which was active all the time.

- I decided to uninstall ad-aware and ad-watch
- then ran the registry cleaner again
- was able to remove unwanted entries. Finally!

I think Im 10% HAPPIER today!

Posted 05 March 2008 - 11:47 AM

Good job mercado,

This topic is now closed.
