Infected with Virtumonde, Smitfrud, S Juan

Dear Members,

Begin of december I executed an exe file downloaded from the web which infected my laptop.
It chaged the desktop backgroud to a HTML page, with a flashing message saying that there was an infection. It disabled the task manager and infected explorer. Since then I managed to restore the taskbar and the desktop backround, but other problems persisted.

1) From time to time my computer will start with no icons nor taskbar.
2) After I open Mozilla or IE,
- I get pop ups suggesting to buy Antivirus2009 (which I know is a bogus product),
- my browser oftens opens spontaneously a newwindoe with a page like google, which can't be closed except from the task manager, nor sent to background,
- other popup show up as transparencies saying my computer is infected and I should buy some other bogus antivirus

On my machine I have McAfee antivirus, but it did not help. From time to time it will pop up with a warning message that some trojan has been detected and removed, but it is not remving the problem at throot.

Since then I tried some free and commercial antispyware (Search&Destroy, WindowsMediaDefender, VundoFix, SmitFraudFix, SpySweeper). Windows media defender made things worse, since it completely froze my computer and since then I can no longer use the Hibernate feature. The computer succesfully goes in hibernation, but after a random interval of time (4-10 minutes), it resumes spontaneously. This happens despite the fact that the WOL feature is disabled in the bios, and the network cable is diconnected. Do you have any idea about what could be causing this?

I uninstalled Search&Destroy, MediaDefender and Windows SP3, and restored an old PC configuration. None of these has helped. All problems persist.
The copy of SpySweeper I purchased is not helping much either. Every time I start the PC it detects again Virtumonde (it does not detect Smitraud and SJuan which were instead detected by SearchAndDestroy).

Unfortunatly I deleted the file which infected me, but there are chances I may be able to find d download it again, if that could be of help.

Do you think there is any chance to get the computer up and running, without rebuilding it? Since it is an-ex company laptop, I have lot of nice applications of which I no longer have the installation disks.

Thanks a lot.

Best regards,


DDS (Ver_09-01-07.01) - NTFSx86
Run by Fabio at 19:41:10.26 on 10/01/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1279.442 [GMT 8:00]

FW: Webroot Internet Security Essentials *disabled*

============== Running Processes ===============

C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Documents and Settings\Fabio\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = hxxp://www.google.com.sg
uSearch Bar = hxxp://www.google.com.sg
mDefault_Page_URL = about:blank
uWindows: load=c:\windows\mqtgsvc.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: NoExplorer - No File
BHO: {237D2904-FCF1-4798-BAA9-2B7ABF5CE72F} - No File
BHO: {6E1E75EC-38B2-4C84-A880-5CDF11D7F3B2} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_07\bin\ssv.dll
BHO: {76937bfe-e564-7248-d1a4-01d52c02d8aa}: {aa8d20c2-5d10-4a1d-8427-465eefb73967} - c:\windows\system32\tjlcrc.dll
BHO: {d910ae7b-8bd7-4ec3-8a53-00d77cc77817} - c:\windows\system32\cbXRLday.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /installquiet
mRun: [00THotkey] "c:\windows\system32\00THotkey.exe"
mRun: [000StTHK] "c:\windows\system32\000StTHK.exe"
mRun: [TFNF5] "c:\windows\system32\TFNF5.exe"
mRun: [SigmaTel StacMon] "c:\program files\sigmatel\sigmatel ac97 audio drivers\stacmon.exe"
mRun: [SynTPLpr] "c:\program files\synaptics\syntp\SynTPLpr.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [TouchED] "c:\program files\toshiba\touched\TouchED.Exe"
mRun: [TPSMain] "c:\windows\system32\TPSMain.exe"
mRun: [TFncKy] TFncKy.exe
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UpdaterUI.exe" /StartedFromRunKey
mRun: [Network Associates Error Reporting Service] "c:\program files\common files\network associates\talkback\TBMon.exe"
mRun: [NeroFilterCheck] "c:\windows\system32\NeroCheck.exe"
mRun: [LVCOMSX] "c:\windows\system32\LVCOMSX.EXE"
mRun: [LogitechCameraAssistant] "c:\program files\logitech\video\CameraAssistant.exe"
mRun: [LogitechVideo[inspector]] "c:\program files\logitech\video\InstallHelper.exe" /inspect
mRun: [LogitechCameraService(E)] "c:\windows\system32\ElkCtrl.exe" /automation
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_07\bin\jusched.exe"
mRun: [AGRSMMSG] "c:\windows\AGRSMMSG.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
mRun: [a47c8fb8] rundll32.exe "c:\windows\system32\hocfeyka.dll",b
dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
dRunOnce: [IETI] c:\program files\skype\phone\ieplugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART
uExplorerRun: [ComRepl] c:\docume~1\fabio\locals~1\applic~1\comrepl.exe /waitservice
mExplorerRun: [Spool] c:\windows\system\spoolsv.exe /waitservice
dExplorerRun: [rsvp] c:\docume~1\fabio\applic~1\micros~1\rsvp.exe /waitservice
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {2222EF56-F49E-4d07-A14E-8D2B08766958} - c:\program files\altova\xmlspy2005\spy.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_07\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: barclays.co.uk\ibank
Trusted Zone: chess.net\www
Trusted Zone: gov.uk\esd.dwp
Trusted Zone: iblogin.com\www
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: khfEXrOf - khfEXrOf.dll
AppInit_DLLs: ztpoah.dll mmxuof.dll zfbvsm.dll tjlcrc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\cbXRLday
LSA: Notification Packages = scecli

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\fabio\applic~1\mozilla\firefox\profiles\zvthbpye.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\mozilla firefox\extensions\talkback@mozilla.org\components\qfaservices.dll

============= SERVICES / DRIVERS ===============

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-11-12 29808]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2005-2-9 58016]
R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2005-2-9 108256]
R4 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2005-2-9 102463]
R4 McShield;Network Associates McShield;c:\program files\network associates\virusscan\Mcshield.exe [2004-8-18 221191]
R4 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\VsTskMgr.exe [2004-8-18 28672]
R4 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2008-11-12 3667312]
R4 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2008-12-19 1086840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-9-14 13352]
S3 ProtoWall;ProtoWall Network Service;c:\windows\system32\drivers\protowall.sys --> c:\windows\system32\drivers\ProtoWall.sys [?]
S3 tridxp2;tridxp2;c:\windows\system32\drivers\tridxp2m.sys [2004-10-13 1011584]
S3 zebrbus;Sony Ericsson Composite Device driver;c:\windows\system32\drivers\zebrbus.sys [2008-9-14 83200]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [2008-7-15 110080]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe

[2006-12-2 2805000]
S4 vsdatant;vsdatant; [x]

=============== Created Last 30 ================
2009-01-10 19:04 129,024 a------- c:\windows\system32\tjlcrc.dll
2009-01-10 19:04 129,024 a------- c:\windows\system32\bhqjewaf.dll
2009-01-10 19:04 1,252,696 ---sh--- c:\windows\system32\akyefcoh.ini
2009-01-10 19:04 72,704 a------- c:\windows\system32\hocfeyka.dll
2009-01-08 23:02 129,024 a------- c:\windows\system32\zfbvsm.dll
2009-01-08 23:02 129,024 a------- c:\windows\system32\qalaanyw.dll
2009-01-08 23:02 120 ---sh--- c:\windows\system32\lcgkkmbl.ini
2009-01-08 23:02 72,704 a------- c:\windows\system32\lbmkkgcl.dll
2009-01-06 09:00 <DIR> --d----- C:\VundoFix Backups
2009-01-06 08:52 120 ---sh--- c:\windows\system32\qqrramns.ini
2009-01-06 08:52 72,704 a------- c:\windows\system32\snmarrqq.dll
2009-01-06 08:52 129,024 a------- c:\windows\system32\mmxuof.dll
2009-01-06 08:52 129,024 a------- c:\windows\system32\bpnfstqo.dll
2008-12-19 16:56 775,168 a------- c:\windows\isRS-000.tmp
2008-12-19 15:09 <DIR> --d----- C:\Binaries
2008-12-19 15:08 1,553,272 a------- c:\windows\WRSetup.dll
2008-12-19 15:08 <DIR> --d----- c:\program files\Webroot
2008-12-19 15:08 <DIR> --d----- c:\docume~1\fabio\applic~1\Webroot
2008-12-19 15:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Webroot
2008-12-19 14:17 <DIR> --d----- C:\SmitfraudFix
2008-12-19 13:45 4,450 a------- c:\windows\system32\tmp.reg
2008-12-19 13:24 129,024 a------- c:\windows\system32\ztpoah.dll.vir
2008-12-19 09:58 <DIR> --d----- c:\program files\scilab-5.0.3
2008-12-19 09:56 <DIR> --d----- C:\My Downloads
2008-12-19 09:56 <DIR> --d----- C:\toshbios.upd
2008-12-14 18:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\comodo
2008-12-13 13:49 308,630 a--sh--- c:\windows\system32\LkmprBeg.ini2

==================== Find3M ====================

2009-01-10 19:41 116,681 a--sh--- c:\windows\system32\yadLRXbc.ini2
2009-01-10 18:57 0 a------- c:\windows\system32\drivers\lvuvc.hs
2009-01-08 08:41 86,995 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-09 00:03 302,592 a------- c:\windows\system32\cbXRLday.dll
2008-12-08 23:58 81,920 a------- c:\windows\mqtgsvc.exe
2008-11-12 16:02 170,608 a------- c:\windows\system32\drivers\ssidrv.sys
2008-11-12 16:02 29,808 a------- c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 16:02 23,152 a------- c:\windows\system32\drivers\sshrmd.sys
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-10-16 00:57 332,800 a------- c:\windows\system32\dllcache\netapi32.dll
2008-04-07 02:16 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2005-05-02 06:29 44 a------- c:\documents and settings\fabio\sts.bat

============= FINISH: 19:44:36.80 ===============

Please consider this case closed. I decided to try one more time and downloaded MalwareBytes. It did the magic (I think), and I am back to the old merry way.


Thank you for notify us.. I will now close this topic.. Please pm any Moderator or HJT Team should you need to re-open this topic..


