Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Trojans Vundo and Virtum

  • This topic is locked This topic is locked
3 replies to this topic

#1 BigBas


  • Members
  • 34 posts
  • Local time:10:12 PM

Posted 04 November 2009 - 03:07 PM

I recently began noticing that my computer was running slower than usual, and certain websites weren't working. Additionally, I began getting popus that didn't seem to originate in my internet browser (Opera). I ran a virus scan and noticed 13 infections, 10 Troj_Vundo (with varying extensions) and 3 Troj_Virtum (also with varying extensions). I came across this website while searching for solutions.

I ran the DDS program, and will copy/attach the pertinent information. I tried running RootRepeal, but I got a Decompression Error once I tried running it after saving.

DDS Report

DDS (Ver_09-10-26.01) - NTFSx86
Run by BAstiphan at 14:47:00.75 on Wed 11/04/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.68 [GMT -5:00]

AV: Trend Micro OfficeScan Antivirus *On-access scanning enabled* (Updated) {0F907F8E-C3F1-40EB-B0AD-1384083F7821}

============== Running Processes ===============

C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\UCClientManager\UCClientManager.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\mmalebranche\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
BHO: AutorunsDisabled - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [lewowapak] Rundll32.exe "c:\windows\system32\fuzadule.dll",a
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [RoxioDragToDisc] "c:\program files\roxio\easy media creator 7\drag to disc\DrgToDsc.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [lewowapak] Rundll32.exe "c:\windows\system32\holiditu.dll",a
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ucclie~1.lnk - c:\windows\installer\{9568af25-a927-4de7-8c88-6d994b5a4d5c}\IconAB46368E.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: adp.com
Trusted Zone: adp.com\payex
Trusted Zone: adp.com\payxreports2
Trusted Zone: adp.com\quickview
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187795455929
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://paylocity.webex.com/client/T26L/webex/ieatgpc.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\holiditu.dll c:\windows\system32\fuzadule.dll c:\windows\system32\dopapoke.dll c:\windows\system32\vefabidu.dll c:\windows\system32\jupaluze.dll c:\windows\system32\karesore.dll c:\windows\system32\diyadodi.dll majudohi.dll c:\windows\system32\wabibegi.dll c:\windows\system32\muwobufi.dll c:\windows\system32\kesawoli.dll c:\windows\system32\giwamega.dll
SSODL: bifajolut - {ccbccd50-2429-4ffb-8c4b-5a36387e3a62} - c:\windows\system32\giwamega.dll
STS: gahurihor: {ccbccd50-2429-4ffb-8c4b-5a36387e3a62} - c:\windows\system32\dopapoke.dll
LSA: Notification Packages = scecli a f n . d l l navafono.dll d

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-30 64288]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-3-11 142592]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-11-4 50192]
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\TmXPFlt.sys [2009-9-15 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2009-9-15 36368]
R2 UCFSPSVC;UC Fax Provider;c:\windows\system32\UCFSPService.exe [2008-5-8 32768]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\trend micro\officescan client\TmProxy.exe [2009-9-15 652552]

=============== Created Last 30 ================

2009-11-04 18:03:56 52752 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2009-11-04 18:03:56 50192 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-11-04 18:03:56 151568 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-04 18:03:55 0 d-----w- c:\windows\system32\log
2009-11-04 18:02:18 0 d-----w- c:\program files\Trend Micro
2009-10-30 18:04:30 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-30 18:03:43 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-30 18:00:41 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-30 18:00:20 0 d-----w- c:\program files\Myfile
2009-10-30 17:59:46 0 d-----w- c:\program files\Lavasoft
2009-10-30 17:57:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-30 17:57:31 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-30 17:57:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-30 17:57:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-26 15:40:21 6456 ---ha-w- c:\windows\system32\yavepato

==================== Find3M ====================

2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36:27 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36:24 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36:24 17408 ------w- c:\windows\system32\corpol.dll
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 23:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23:46 215920 ----a-w- c:\windows\system32\muweb.dll
2009-07-31 13:47:42 89600 --sha-w- c:\windows\system32\dopapoke.dll
2009-08-03 01:48:40 38912 --sha-w- c:\windows\system32\duwemifu.dll
2009-07-26 15:40:22 176128 --sha-w- c:\windows\system32\fasagere.dll
2009-07-31 13:47:42 38400 --sha-w- c:\windows\system32\fihanuna.dll
2009-08-01 01:47:54 89088 --sha-w- c:\windows\system32\fuzadule.dll
2009-08-02 13:48:24 38912 --sha-w- c:\windows\system32\gabejama.dll
2009-08-04 13:49:17 89088 --sha-w- c:\windows\system32\giwamega.dll
2009-08-01 13:48:05 90112 --sha-w- c:\windows\system32\holiditu.dll
2009-07-31 01:47:30 61440 --sha-w- c:\windows\system32\homirohu.dll
2009-07-31 01:47:30 90112 --sha-w- c:\windows\system32\jupaluze.dll
2009-07-31 01:47:30 38400 --sha-w- c:\windows\system32\kamileva.dll
2009-08-04 01:49:08 89088 --sha-w- c:\windows\system32\kesawoli.dll
2009-08-04 13:49:18 38400 --sha-w- c:\windows\system32\lonupovi.dll
2009-07-27 13:42:10 51712 --sha-w- c:\windows\system32\mupitera.dll
2009-08-03 13:48:52 89600 --sha-w- c:\windows\system32\muwobufi.dll
2009-07-26 17:41:04 180224 --sha-w- c:\windows\system32\rituvuza.dll
2009-08-01 13:48:05 38912 --sha-w- c:\windows\system32\sapinisa.dll
2009-08-04 01:49:08 37888 --sha-w- c:\windows\system32\seminali.dll
2009-07-30 13:47:19 37888 --sha-w- c:\windows\system32\tozesogu.dll
2009-08-02 01:48:15 89088 --sha-w- c:\windows\system32\vefabidu.dll
2009-08-03 01:48:40 89088 --sha-w- c:\windows\system32\wabibegi.dll
2009-08-02 01:48:15 38912 --sha-w- c:\windows\system32\wemefigu.dll
2009-08-01 01:47:54 38912 --sha-w- c:\windows\system32\yazemiya.dll
2009-08-03 13:48:52 38912 --sha-w- c:\windows\system32\zisomapi.dll
2009-07-26 15:13:18 92160 --sha-w- c:\windows\system32\zurekiho.dll

============= FINISH: 14:49:25.42 ===============

Attached Files

BC AdBot (Login to Remove)


#2 JSntgRvr


    Master Surgeon General

  • Malware Response Team
  • 11,924 posts
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:12 PM

Posted 04 November 2009 - 04:25 PM

Hi, BigBas :(


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.


    • Copy the entire contents of the Quote Box below to Notepad.
    • Name the file as CFScript.txt
    • Change the Save as Type to All Files
    • and Save it on the desktop


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    Posted Image

    Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report
  • If you receive a message that Combofix has detected the presence of rootkit activity and needs to reboot, kindly write down on paper the list of files present in the message before continuing, and post it in your next reply.
  • Install the Recovery Console upon request.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything unless told to do so while we are fixing your problem.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!

#3 BigBas

  • Topic Starter

  • Members
  • 34 posts
  • Local time:10:12 PM

Posted 06 November 2009 - 04:17 PM


Thank you for the time checking my log. I haven't had a chance to attempt the combofix, but I will give it a try on Monday.

Again, thank you.

#4 JSntgRvr


    Master Surgeon General

  • Malware Response Team
  • 11,924 posts
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:12 PM

Posted 23 November 2009 - 04:34 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users