Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with some kind of worm. Vundo maybe?


  • This topic is locked This topic is locked
2 replies to this topic

#1 leftwngr

leftwngr

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 07 May 2009 - 01:53 PM

I got infected two days ago with some kind of worm. It was the Antivirus XP Pro 2009 fake antivirus software, which MBAM took out, but there are some lingering side effects that I can't shake and it's causing me great difficulties.

My browser is going through that awful google-redirect and I'm getting redirected all over the place.

My automatic updates shows that it is off, but it is actually on.

I put in a flash drive, and it does not appear in the my computer window.

performance is down.

everytime I re-run MBAM, SpyBot and or PCTools Spy Doctor, I get a whole host of new infections even after full scan and reboot.

For the life of me, I can't remove this thing and it keeps reloading itself each time I log on.

Please help.

Thank you.

Here is the DDS log

DDS (Ver_09-03-16.01) - NTFSx86
Run by Peter Kim at 11:41:22.81 on Thu 05/07/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.16.0\gears.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [Aim6]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [eFax 4.4] "c:\program files\efax messenger 4.4\J2GDllCmd.exe" /R
uRun: [A00F38B66E23.exe] c:\docume~1\peterk~1\locals~1\temp\_A00F38B66E23.exe
uRun: [A00F38BC8D56.exe] c:\docume~1\peterk~1\locals~1\temp\_A00F38BC8D56.exe
uRun: [autochk] rundll32.exe c:\docume~1\peterk~1\protect.dll,_IWMPEvents@16
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [Motive SmartBridge] c:\progra~1\sbclig~1\smartb~1\MotiveSB.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [SetDefPrt] c:\program files\brother\brmfl05c\BrStDvPt.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [PDUiP6700DMon] c:\program files\canon\memory card utility\ip6700d\PDUiP6700DMon.exe
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [DU Meter] c:\program files\du meter\DUMeter.exe
mRun: [QuickTime Task] "c:\program files\k-lite codec pack\quicktime\qttask.exe" -atboottime
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [autochk] rundll32.exe c:\windows\system32\autochk.dll,_IWMPEvents@16
dRun: [Diagnostic Manager] c:\windows\temp\3219612540.exe
dRun: [autochk] rundll32.exe c:\windows\system32\config\system~1\protect.dll,_IWMPEvents@16
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Copy to &Lightning Note - c:\program files\wordperfect lightning\programs\WPLightningCopyToNote.hta
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.16.0\gears.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} - hxxp://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
DPF: {1F9079B1-CB38-4DC0-9DAD-080BD2255698} - hxxp://wvw.kongdisk.com/activex/KongdiskControl.CAB
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189716416796
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://www.shockwave.com/content/luxoramunrising/sis/mjolauncher.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://www.shockwave.com/content/feedingfrenzy/sis/SproutLauncher.cab
DPF: {E0F0958B-C5EB-49E3-8567-E018D2407F35} - hxxp://patch.kongdisk.com/install/kongdisk.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Notification Packages = scecli c:\windows\system32\luyasuwo.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\peterk~1\applic~1\mozilla\firefox\profiles\0nyr1hn2.default\
FF - prefs.js: browser.startup.homepage - hxxp://att.yahoo.com/
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\google\google gears\firefox\components\gears.dll
FF - component: c:\program files\mozilla firefox\components\Scriptff.dll
FF - plugin: c:\documents and settings\peter kim\application data\mozilla\firefox\profiles\0nyr1hn2.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071102000005.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\k-lite codec pack\quicktime\plugins\npqtplugin.dll
FF - plugin: c:\program files\k-lite codec pack\quicktime\plugins\npqtplugin2.dll
FF - plugin: c:\program files\k-lite codec pack\quicktime\plugins\npqtplugin3.dll
FF - plugin: c:\program files\k-lite codec pack\quicktime\plugins\npqtplugin4.dll
FF - plugin: c:\program files\k-lite codec pack\quicktime\plugins\npqtplugin5.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-05-07 11:02 24,064 a--sh--- c:\documents and settings\peter kim\protect.dll
2009-05-07 11:02 24,064 a--sh--- c:\windows\system32\autochk.dll
2009-05-07 11:02 27,648 a------- c:\windows\system32\lmn_setup.exe
2009-05-06 21:01 87,040 ac------ c:\windows\system32\dllcache\wiafbdrv.dll
2009-05-06 21:00 765,884 ac------ c:\windows\system32\dllcache\usrti.sys
2009-05-06 20:59 36,736 ac------ c:\windows\system32\dllcache\ultra.sys
2009-05-06 20:58 149,376 ac------ c:\windows\system32\dllcache\tffsport.sys
2009-05-06 20:57 155,648 ac------ c:\windows\system32\dllcache\stlnprop.dll
2009-05-06 20:56 58,368 ac------ c:\windows\system32\dllcache\smiminib.sys
2009-05-06 20:55 252,032 ac------ c:\windows\system32\dllcache\sis300iv.dll
2009-05-06 20:54 23,936 ac------ c:\windows\system32\dllcache\sccmn50m.sys
2009-05-06 20:53 3,840 ac------ c:\windows\system32\dllcache\rpfun.sys
2009-05-06 20:52 159,232 ac------ c:\windows\system32\dllcache\ptpusd.dll
2009-05-06 20:52 <DIR> --d----- c:\program files\McAfee
2009-05-06 20:51 27,296 ac------ c:\windows\system32\dllcache\perc2.sys
2009-05-06 20:50 54,528 ac------ c:\windows\system32\dllcache\opl3sax.sys
2009-05-06 20:49 27,936 ac------ c:\windows\system32\dllcache\n9i3d.sys
2009-05-06 20:48 15,232 ac------ c:\windows\system32\dllcache\mpe.sys
2009-05-06 20:47 20,864 ac------ c:\windows\system32\dllcache\lwadihid.sys
2009-05-06 20:46 90,200 ac------ c:\windows\system32\dllcache\io8ports.dll
2009-05-06 20:45 488,383 ac------ c:\windows\system32\dllcache\hsf_v124.sys
2009-05-06 20:44 48,128 ac------ c:\windows\system32\dllcache\hpgt33tk.dll
2009-05-06 20:43 24,618 ac------ c:\windows\system32\dllcache\fa410nd5.sys
2009-05-06 20:42 153,631 ac------ c:\windows\system32\dllcache\el90xnd5.sys
2009-05-06 20:41 24,649 ac------ c:\windows\system32\dllcache\dfe650d.sys
2009-05-06 20:40 46,108 ac------ c:\windows\system32\dllcache\cben5.sys
2009-05-06 20:39 26,496 ac------ c:\windows\system32\dllcache\asc.sys
2009-05-06 19:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec
2009-05-06 19:42 61,440 a------- c:\windows\system32\drivers\nelxi.sys
2009-05-06 19:14 61,440 a------- c:\windows\system32\drivers\mphhzjvk.sys
2009-05-06 19:08 61,440 a------- c:\windows\system32\drivers\lswhxmbe.sys
2009-05-06 16:58 5,736 a------- c:\windows\system32\tmp.reg
2009-05-06 14:40 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-05-06 14:39 130,936 a------- c:\windows\system32\drivers\PCTCore.sys
2009-05-06 14:39 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-06 14:39 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-05-06 14:39 <DIR> --d----- c:\program files\common files\PC Tools
2009-05-06 14:39 <DIR> --d----- c:\program files\Spyware Doctor
2009-05-06 14:39 <DIR> --d----- c:\docume~1\peterk~1\applic~1\PC Tools
2009-05-06 14:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-05-06 13:56 61,440 a------- c:\windows\system32\drivers\ysyspyl.sys
2009-05-06 11:38 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-06 11:38 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-06 11:38 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-05 15:05 26,112 ac------ c:\windows\system32\dllcache\userinit.exe
2009-05-05 14:48 578,560 a------- c:\windows\system32\gwiwfazq
2009-05-05 14:48 7,168 a------- C:\poedmta.exe
2009-05-05 14:48 57 a------- C:\xcrashdump.dat
2009-05-05 14:47 182,656 -c------ c:\windows\system32\dllcache\ndis.sys
2009-05-05 14:42 0 a------- c:\windows\system32\drivers\604c54e.sys
2009-05-05 14:42 578,560 ac------ c:\windows\system32\dllcache\user32.dll
2009-05-05 14:42 2 a------- C:\417924065
2009-05-05 14:42 7,168 a------- C:\dtmb.exe
2009-04-29 17:04 544,768 a------- c:\windows\system32\msvcr71d.dll
2009-04-29 17:04 765,952 a------- c:\windows\system32\msvcp71d.dll
2009-04-29 17:04 2,183,168 a------- c:\windows\system32\mfc71ud.dll
2009-04-29 17:04 <DIR> --d----- c:\program files\KONGDISK
2009-04-16 19:35 2,560 -------- c:\windows\system32\xpsp4res.dll

==================== Find3M ====================

2009-05-05 14:47 182,656 a------- c:\windows\system32\drivers\ndis.sys
2009-05-05 14:41 51,712 a--sh--- c:\windows\system32\riseteyo.exe
2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-20 11:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-09 05:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 05:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 05:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 05:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 04:13 1,846,784 a------- c:\windows\system32\win32k.sys
2008-05-06 13:15 724,984 a------- c:\documents and settings\peter kim\gotomypc_437.exe
2008-04-23 12:48 87,608 a------- c:\docume~1\peterk~1\applic~1\inst.exe
2008-04-23 12:48 47,360 a------- c:\docume~1\peterk~1\applic~1\pcouffin.sys
2008-04-23 12:35 81,920 a------- c:\docume~1\peterk~1\applic~1\ezpinst.exe
2008-06-23 12:20 8 ---shr-- c:\windows\system32\AD7661E70E.sys
2006-05-03 03:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2009-02-03 16:19 3,350 a--sh--- c:\windows\system32\KGyGaAvL.sys
2007-02-21 04:47 31,232 ---shr-- c:\windows\system32\msfDX.dll
2008-03-16 06:30 216,064 ---shr-- c:\windows\system32\nbDX.dll
2008-09-04 15:21 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090420080905\index.dat

============= FINISH: 11:42:01.57 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 leftwngr

leftwngr
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 12 May 2009 - 01:22 PM

Mods: Please close topic. Resolved. Thank you.

#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,995 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:08:03 AM

Posted 14 May 2009 - 10:08 PM

Thank you for letting us know. This topic shall now be closed. ~ OB
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users