Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Infected with Conficker, Virtumonde (I think)

  • This topic is locked This topic is locked
2 replies to this topic

#1 shortyb06


  • Members
  • 1 posts
  • Local time:11:07 AM

Posted 30 January 2009 - 06:58 PM

I ran A-squared Malware on my PC and tried to clear the infections it showed (which I think were Conficker and Virtumonde) and it instantly rebooted my computer. When it came back on, I logged on and my start bar and desktop icons were not appearing. It only shows my desktop background and my cursor. I've just been doing Ctrl+Alt+Del to run tasks. This all happened today so I restored my system to yesterday but it doesn't appear to have made any changes. This is my first post, so if you need any additional information just let me know. Help please. Thanks!

DDS (Ver_09-01-19.01) - NTFSx86
Run by Ken at 18:47:16.67 on Fri 01/30/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1982.1459 [GMT -5:00]

AV: avast! antivirus 4.8.1296 [VPS 090130-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ken\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\ljJBronM.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: {84f5cbb2-9647-4c63-949d-3618914f73dc} - c:\windows\system32\mlJCTJAP.dll
BHO: {e43c9ba6-53c0-d75b-4e84-b79e19725fff}: {fff52791-e97b-48e4-b57d-0c356ab9c34e} - c:\windows\system32\uoyxfx.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
uRun: [A00F49D1A3E.exe] c:\docume~1\ken\locals~1\temp\_A00F49D1A3E.exe
uRun: [A00F49D33C1.exe] c:\docume~1\ken\locals~1\temp\_A00F49D33C1.exe
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [MP10_EnsureFileVer] c:\windows\inf\unregmp2.exe /EnsureFileVersions
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [a-squared] "c:\program files\a-squared anti-malware\a2guard.exe"
mRun: [20fdf793] rundll32.exe "c:\windows\system32\esgclraj.dll",b
mRunOnce: [*Restore] c:\windows\system32\restore\rstrui.exe -i
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - file://c:\documents and settings\ken\local settings\application data\oberon media\oberon games host\swflash.cab
Notify: ljJBronM - ljJBronM.dll
Notify: __c006AEFC - c:\windows\system32\__c006AEFC.dat
AppInit_DLLs: uoyxfx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\ljJBronM.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\mlJCTJAP

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ken\applic~1\mozilla\firefox\profiles\re6hb2p0.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\ken\application

FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-3-30 111184]
R4 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2009-1-28 421496]
R4 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-1-26 421496]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-3-30 20560]
R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-3-1 155160]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-3-2 24652]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;"c:\program files\firebird\firebird_2_1\bin\fbserver.exe" -s defaultinstance -->

c:\program files\firebird\firebird_2_1\bin\fbserver.exe [?]
S3 kwkpcusb;Kyocera CDMA Wireless Modem Driver for KPC;c:\windows\system32\drivers\kwusbnt.sys [2007-2-8 101280]
S3 VmbInfce;VmbInfce;c:\windows\system32\drivers\vmbinfce.sys [2007-1-29 95104]

=============== Created Last 30 ================

2009-01-30 17:13 25,088 a------- c:\windows\system32\__c00CE66F.dat
2009-01-30 17:13 25,088 a------- c:\windows\system32\__c006AEFC.dat
2009-01-29 21:54 1,483,063 ---sh--- c:\windows\system32\jarlcgse.ini
2009-01-29 21:54 72,704 a------- c:\windows\system32\esgclraj.dll
2009-01-29 21:51 129,024 a------- c:\windows\system32\uoyxfx.dll
2009-01-29 21:51 129,024 a------- c:\windows\system32\yuqfboch.dll
2009-01-28 22:17 <DIR> --d----- c:\program files\a-squared Anti-Malware
2009-01-28 21:53 1,518,468 ---sh--- c:\windows\system32\ripdtufb.ini
2009-01-28 21:53 72,704 a------- c:\windows\system32\bfutdpir.dll
2009-01-28 21:50 129,024 a------- c:\windows\system32\wkulaz.dll
2009-01-28 21:50 129,024 a------- c:\windows\system32\adovgvxq.dll
2009-01-27 21:50 129,024 a------- c:\windows\system32\wstwkc.dll
2009-01-27 21:50 129,024 a------- c:\windows\system32\kynideho.dll
2009-01-27 21:48 1,518,468 ---sh--- c:\windows\system32\pdgwskxr.ini
2009-01-27 21:47 391,429 a--sh--- c:\windows\system32\PAJTCJlm.ini2
2009-01-27 21:47 391,429 a--sh--- c:\windows\system32\PAJTCJlm.ini
2009-01-27 21:47 315,904 a------- c:\windows\system32\mlJCTJAP.dll
2009-01-27 21:42 36,352 a------- c:\windows\system32\ljJBronM.dll
2009-01-27 21:42 36,352 a------- c:\windows\system32\ljJBqrPf.dll
2009-01-26 18:53 <DIR> --d----- c:\program files\common files\HP
2009-01-26 18:50 <DIR> --d----- c:\program files\common files\Hewlett-Packard
2009-01-26 18:47 16,496 a----r-- c:\windows\system32\drivers\HPZipr12.sys
2009-01-26 18:47 51,120 a----r-- c:\windows\system32\drivers\HPZid412.sys
2009-01-26 18:46 21,744 a----r-- c:\windows\system32\drivers\HPZius12.sys
2009-01-26 18:46 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
2009-01-26 18:46 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2009-01-26 18:41 278,584 a------- c:\windows\system32\HPZidr12.dll
2009-01-26 18:41 204,800 a------- c:\windows\system32\HPZipr12.dll
2009-01-26 18:41 94,208 a------- c:\windows\system32\HPZipt12.dll
2009-01-26 18:41 69,632 a------- c:\windows\system32\HPZipm12.exe
2009-01-26 18:41 61,440 a------- c:\windows\system32\HPZinw12.exe
2009-01-26 18:41 57,344 a------- c:\windows\system32\HPZisn12.dll
2009-01-26 18:36 <DIR> --d----- c:\program files\HP
2009-01-26 18:35 112,923 a------- c:\windows\hpoins07.dat
2009-01-26 18:35 21,124 -------- c:\windows\hpomdl07.dat
2009-01-26 18:20 <DIR> --d----- c:\program files\a-squared Free
2009-01-12 14:04 140,800 a------- c:\windows\system32\tm20dec.ax
2009-01-12 14:04 <DIR> --d----- c:\documents and settings\ken\WINDOWS
2009-01-11 17:53 <DIR> --d----- c:\program files\ACE Mega CoDecS Pack
2009-01-10 15:24 <DIR> --d----- c:\program files\Final Fantasy VII
2009-01-09 21:27 <DIR> --d----- c:\program files\Pcsx2_0.9.4
2009-01-05 23:38 <DIR> --d----- c:\program files\Click-2U
2009-01-04 15:22 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-01-03 13:08 0 a------- c:\windows\system32\drivers\seneka.sys
2009-01-03 13:06 2,461 a------- c:\windows\system32\senekadf.dat
2009-01-03 13:06 59 a------- c:\windows\system32\seneka.dat
2009-01-03 13:01 2,365 a------- c:\windows\system32\senekalog.dat

==================== Find3M ====================

2008-12-02 15:34 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 18:48:49.68 ===============

Attached Files

BC AdBot (Login to Remove)


#2 fenzodahl512


  • Members
  • 6,738 posts
  • Local time:12:07 AM

Posted 01 February 2009 - 09:51 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from HERE or HERE or HERE and save it to your Desktop.

During the download, rename Combofix to Combo-Fix as follows:

Posted Image

Posted Image

It is important you rename Combofix during the download, but not after.

**NOTE: If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

After that, double-click and run Combo-Fix. Let it finish its job and post the log here

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive

#3 fenzodahl512


  • Members
  • 6,738 posts
  • Local time:12:07 AM

Posted 10 February 2009 - 05:45 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users