Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Possible Perlovga infection - Mountpoints2 reg key returns

  • This topic is locked This topic is locked
2 replies to this topic

#1 geistman


  • Members
  • 3 posts
  • Local time:06:10 PM

Posted 15 January 2009 - 03:13 PM

I have some kind of stubborn malware that I cannot seem to totally clean. From what I have been able to find out, it may be the Perlovga virus/malware. I may have "short-circuited" the virus partially by creating files c:\autorun.inf, c:\copy.exe, and c:\host.exe (all files have attributes SHR and all have just "filler" as the contents), but something is still infecting my system. Symptom: if I open My Computer and double-click on the C: drive, instead of opening the drive, the file c:\copy.exe is run (just a blank Command window is displayed). I have found that I can fix that problem by running Regedit and deleting the key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{89c205ac-7e33-11db-8f0a-806d6172} -- there are four copies of this, but only one has subkeys Shell\AutoRun\Command; the name of command is default, the type is Reg_Sz, and the data is "c:\windows\system32\rundll32.exe shell32.dll,ShellExec_RunDLL copy.exe". When I delete that key, the C: drive icon in My Computer works fine, until I reboot the system and double-click C:, at which time the key is recreated and the icon opens the command window trying to run copy.exe again.

Below is the file created by the DDS script. Also attached is the zipped file attach.zip. Let me know if there is any additional information I can provice. All help would be appreciated. Thanks.

DDS (Ver_09-01-07.01) - NTFSx86
Run by TechSupport at 14:32:45.20 on Thu 01/15/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.490 [GMT -5:00]

AV: Sunbelt VIPRE *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dialogic\bin\ctbbserv.exe
C:\Program Files\Dialogic\bin\IPMedia.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Nuance\license_manager\components\lmgrd.exe
C:\Program Files\Nuance\license_manager\components\lmgrd.exe
C:\Program Files\ScanSoft\RealSpeak 4.0\ttsserver_service.exe
C:\Program Files\Dialogic\bin\RtfServer.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Nuance\license_manager\components\swilmgrd.exe
C:\Program Files\Dialogic\bin\DM3Config.exe
C:\Program Files\Dialogic\bin\dlgimrservice.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Dialogic\bin\OAMEventService.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Dialogic\bin\devmapserver.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Dialogic\bin\dlgsysmonitorserver.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Dialogic\bin\ObserverService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox 3\firefox.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [WScheduler] c:\progra~1\system~1\WScheduler.exe /LOGON
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SBAMTray] c:\program files\sunbelt software\vipre\SBAMTray.exe
mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\post-i~1.lnk - c:\program files\3m\psnlite\PsnLite.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\upswor~1.lnk - c:\ups\wstd\wstdPldReminder.exe
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
TCP: {1D29B06B-BCA8-4096-88D6-A7A849666BD3} =,
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {F552DDE6-2090-4bf4-B924-6141E87789A5} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\techsu~1\applic~1\mozilla\firefox\profiles\z53qkjn1.default\
FF - plugin: c:\documents and settings\techsupport\application data\mozilla\firefox\profiles\z53qkjn1.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox 3\plugins\npFoxitReaderPlugin.dll

============= SERVICES / DRIVERS ===============

R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2009-1-12 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-1-12 202928]
R3 CTBusBroker;CT Bus Broker;c:\program files\dialogic\bin\ctbbserv.exe [2008-8-4 540780]
R3 DM3Config;DM3Config;c:\program files\dialogic\bin\DM3Config.exe [2008-8-4 45165]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2009-1-15 206608]
R4 DlgPnPObserverService;DlgPnPObserverService;c:\program files\dialogic\bin\ObserverService.exe [2008-8-4 69747]
R4 IMRService;Implementation Repository;c:\program files\dialogic\bin\dlgimrservice.exe [2008-8-4 32881]
R4 IPMedia;IPLink Media Service;c:\program files\dialogic\bin\IPMedia.exe [2008-8-4 520192]
R4 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-4-17 12856]
R4 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-8-1 47640]
R4 MCallLinkService;MCallLinkService;c:\medicalllink\mcalllink\MCallLinkService.exe [2009-1-5 11776]
R4 MSSQL$UPSWSDBSERVER;MSSQL$UPSWSDBSERVER;c:\ups\wstd\mssql$upswsdbserver\binn\sqlservr.exe -supswsdbserver --> c:\ups\wstd\mssql$upswsdbserver\binn\sqlservr.exe -sUPSWSDBSERVER [?]
R4 NuanceLicensingService;NuanceLicensingService;c:\program files\nuance\license_manager\components\lmgrd.exe [2007-4-16 1339392]
R4 RealSpeak Host;RealSpeak Host;c:\program files\scansoft\realspeak 4.0\ttsserver_service.exe [2007-1-2 188516]
R4 RtfDispatcher;Dialogic Runtime Tracing Dispatcher;c:\program files\dialogic\bin\RtfServer.exe [2008-8-4 274539]
R4 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\sunbelt software\vipre\SBAMSvc.exe [2008-10-28 886056]
R4 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2009-1-12 69168]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys --> c:\program files\superantispyware\SASKUTIL.sys [?]
S3 Boardserver;Dialogic Boardserver;c:\program files\dialogic\bin\boardserver.exe [2008-8-4 622703]
S3 DebugAngel;Dialogic DebugAngel;c:\program files\dialogic\bin\DebugAngel.exe [2008-8-4 36972]
S3 DetectorsProj;DetectorsProj;c:\program files\dialogic\bin\DetectorsServer.exe [2008-8-4 94323]
S3 DlgcSram;DlgcSram;c:\windows\system32\drivers\dlgcsram.sys [2008-8-4 134016]
S3 GammaFax;GammaLink System Service;c:\program files\dialogic\bin\GfdCp.exe [2008-8-4 241664]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\7.tmp --> c:\windows\system32\7.tmp [?]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2007-4-5 25773]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]
S3 skeysusb;Sentinel Key device driver;c:\windows\system32\drivers\skeysusb.sys --> c:\windows\system32\drivers\skeysusb.sys [?]
S3 SQLAgent$UPSWSDBSERVER;SQLAgent$UPSWSDBSERVER;c:\ups\wstd\mssql$upswsdbserver\binn\sqlagent.exe -i upswsdbserver --> c:\ups\wstd\mssql$upswsdbserver\binn\sqlagent.EXE -i UPSWSDBSERVER [?]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2009-1-15 206608]
S4 Dialogic;Dialogic System Service;c:\program files\dialogic\bin\dlgc_srv.exe [2008-8-4 82028]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2009-1-15 582992]
S4 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2006-11-12 23856]

=============== Created Last 30 ================

2009-01-15 14:11 2,292 a------- C:\autorun.PNF
2009-01-15 14:11 206,608 a------- c:\windows\system32\drivers\TMPassthru.sys
2009-01-15 14:11 <DIR> --d----- c:\program files\Trend Micro
2009-01-14 13:40 6 a--shr-- C:\copy.exe
2009-01-14 13:09 <DIR> --d----- C:\MediCallLink
2009-01-12 15:17 34 a--shr-- C:\autorun.inf
2009-01-12 15:17 6 a--shr-- C:\host.exe
2009-01-12 13:52 69,168 a------- c:\windows\system32\drivers\sbapifs.sys
2009-01-12 13:52 13,360 a------- c:\windows\system32\drivers\sbaphd.sys
2009-01-12 13:50 <DIR> --d----- c:\docume~1\techsu~1\applic~1\Sunbelt
2009-01-12 13:48 202,928 a------- c:\windows\system32\drivers\sbtis.sys
2009-01-12 12:31 6 a------- c:\windows\autorun.inf
2009-01-12 12:28 306,601 a------- C:\bitdefender-011109.html
2009-01-12 07:45 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2009-01-11 11:26 <DIR> --d----- c:\program files\ThreatFire
2009-01-11 09:25 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-01-10 20:17 <DIR> --d----- c:\documents and settings\techsupport\.housecall6.6
2009-01-09 13:52 5,760 -------- c:\windows\system32\2.tmp
2009-01-09 13:52 <DIR> --d----- c:\program files\Sophos
2009-01-09 13:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-01-09 13:07 <DIR> --d----- C:\hjt
2009-01-09 12:55 <DIR> --d----- C:\!KillBox
2009-01-09 12:45 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-01-09 12:24 <DIR> --d----- c:\docume~1\techsu~1\applic~1\Malwarebytes
2009-01-09 12:24 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-09 12:24 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 12:24 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-09 12:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-01-08 14:03 295,424 a------- c:\windows\system32\dllcache\termsrv.dll
2009-01-08 14:01 295,424 a------- c:\windows\system32\termsrv.dll
2009-01-08 12:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-01-08 12:50 <DIR> --d----- c:\docume~1\techsu~1\applic~1\AVS4YOU
2009-01-08 12:50 658,432 a------- c:\windows\system32\cc3270mt.dll
2009-01-08 12:50 <DIR> --d----- c:\program files\common files\AVSMedia
2009-01-08 12:50 24,576 a------- c:\windows\system32\msxml3a.dll
2009-01-08 12:50 <DIR> --d----- c:\program files\AVS4YOU
2009-01-08 12:33 <DIR> --d----- c:\program files\NCH Software
2009-01-08 11:37 <DIR> --d----- c:\program files\Audacity
2009-01-08 11:27 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-01-08 11:27 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-01-08 11:27 <DIR> --d----- c:\program files\iPod
2009-01-08 11:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-08 11:27 <DIR> --d----- c:\program files\iTunes
2009-01-08 11:27 <DIR> --d----- c:\program files\Bonjour
2009-01-06 16:18 <DIR> --d----- c:\program files\ScanSoft
2009-01-06 16:18 <DIR> --d----- c:\program files\common files\SpeechWorks
2009-01-06 16:14 <DIR> --d----- C:\Guy
2009-01-06 15:05 <DIR> --d----- c:\program files\Nuance
2008-12-30 16:25 <DIR> --d----- C:\NRAD
2008-12-24 14:23 <DIR> --d----- C:\New Folder (3)
2008-12-23 16:51 <DIR> --d----- c:\program files\AskBarDis
2008-12-23 16:51 <DIR> --d----- c:\program files\Foxit Software
2008-12-23 16:51 <DIR> --d----- c:\docume~1\techsu~1\applic~1\Foxit
2008-12-18 13:25 <DIR> --d----- C:\New Folder (2)

==================== Find3M ====================

2008-12-13 01:40 3,593,216 a------- c:\windows\system32\dllcache\mshtml.dll
2008-10-29 12:44 62,016 a------- C:\GDIPFONTCACHEV1.DAT
2008-10-28 16:28 65,320 a------- c:\windows\system32\sbbd.exe
2008-10-24 06:10 453,632 -------- c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 08:01 283,648 a------- c:\windows\system32\gdi32.dll
2008-10-23 08:01 283,648 -------- c:\windows\system32\dllcache\gdi32.dll
2008-08-17 09:05 3,902,784 a------- c:\documents and settings\techsupport\gosetup.exe
2008-07-18 15:17 60,744 a------- c:\documents and settings\techsupport\g2mdlhlpx.exe
2007-08-01 15:24 630,784 a------- c:\documents and settings\techsupport\GoToAssist_chat2way__317_en.exe
2007-04-05 12:52 2 a--shrot c:\windows\winstart.bat

============= FINISH: 14:33:26.93 ===============

Attached Files

BC AdBot (Login to Remove)


#2 PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • Gender:Male
  • Local time:07:10 PM

Posted 27 January 2009 - 11:57 AM

Hello. I am PropagandaPanda (Panda or PP for short), and I will be helping you.

Disable Realtime Protection
Antimalware programs can interfere with ComboFix and other tools we need to run. Please temporarily disable all realtime protections you have enabled. Refer to this page, if you are unsure how.

Download and Run ComboFix
If you have already run ComboFix, delete your copy and download a new one. If the computer in question is unable to download ComboFix, transfer it using a removable media (CDs, flash drive).

Download Combofix by sUBs from any of the links below, and save it to your desktop.
Link 1, Link 2, Link 3
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click on ComboFix.exe and follow the prompts. If you are using Windows Vista, right click the icon and select "Run as Administrator". You will not recieve the prompts below if you are not using Windows XP. ComboFix will check to see if you have the Windows Recovery Console installed.
  • If you did not have it installed, you will see the prompt below. Choose YES.
    Posted ImagePosted Image

  • When the Recovery Console has been installed, you will see the prompt below. Choose YES.
    Posted Image
  • When finished, ComboFix will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

In your next reply include:
-the ComboFix log
-a new HijackThis or DDS log

Please also tell me of any changes you have made to your computer since you started your topic.

With Regards,
The Panda

#3 PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • Gender:Male
  • Local time:07:10 PM

Posted 07 February 2009 - 10:38 AM


There had been no reply from the topic starter in 5 days. Due to inactivity, this topic is now closed.
If you are the topic starter and need this topic reopened, send me a message.

Everyone else, please begin a new topic.

With Regards,
The Panda

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users