Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Virtumonde


  • This topic is locked This topic is locked
15 replies to this topic

#1 LindaMS

LindaMS

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 28 November 2010 - 04:53 PM

A scan with Spybot Search and Destroy has found the Virtumonde virus/trojan. I have been unable to remove the infection and am asking for your assistance.


DDS (Ver_10-11-27.01) - NTFSx86
Run by Linda at 14:46:50.85 on 29/11/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.280 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\ipsmsnap3232.exe
C:\WINDOWS\system32\iassvcs32.exe
C:\WINDOWS\system32\evr32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\locator.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\tlntsvr.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Linda\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = www.google.ca
uInternet Settings,ProxyOverride = hxxp://localhost;*.local
BHO: {077DF586-96A1-4338-903C-510563439BA9} - No File
BHO: {07A8EAC4-AC4D-436F-BEFF-D8FFAFD8D3C4} - No File
BHO: {0EFBEB0C-96A1-4338-903C-510563439BA9} - No File
BHO: {0F51D588-AC4D-436F-BEFF-D8FFAFD8D3C4} - No File
BHO: {1DF7D618-96A1-4338-903C-510563439BA9} - No File
BHO: {1EA3AB11-AC4D-436F-BEFF-D8FFAFD8D3C4} - No File
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: 3486f02c: {ae617046-c91b-ce0b-9ddf-3e1f31ccb638} - c:\windows\system32\ipsmsnap32.dll
BHO: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [<NO NAME>]
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
dRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
mExplorerRun: [RTHDBPL] c:\documents and settings\linda\application data\syswin\lsass.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
mPolicies-explorer: <NO NAME> =
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://go.microsoft.com/fwlink/?LinkId=82580
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1260639444046
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258230704218
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6}
DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - hxxp://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
Notify: WRNotifier - WRLogonNTF.dll
AppInit_DLLs: c:\windows\system32\atmlib32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\linda\applic~1\mozilla\firefox\profiles\cvn1cgnn.default\
FF - prefs.js: browser.search.selectedEngine - Creative Commons
FF - prefs.js: browser.startup.homepage - about:blank
FF - plugin: c:\documents and settings\linda\application data\mozilla\firefox\profiles\cvn1cgnn.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\opera\program\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - c:\docume~1\linda\applic~1\mozilla\firefox\profiles\cvn1cgnn.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Extension: IE Tab 2 (FF 3.6+): {1BC9BA34-1EED-42ca-A505-6D2F1A935BBB} - c:\docume~1\linda\applic~1\mozilla\firefox\profiles\cvn1cgnn.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
FF - Extension: XUL Cache: {d628ba1c-0dac-40a4-84d4-2c10007f2fde} - c:\docume~1\linda\applic~1\mozilla\firefox\profiles\cvn1cgnn.default\extensions\{d628ba1c-0dac-40a4-84d4-2c10007f2fde}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

============= SERVICES / DRIVERS ===============

R2 ClipSrv32;ClipBook ;c:\windows\system32\ipsmsnap3232.exe [2010-11-20 1433088]
R2 Creative Service for CDROM Access32;Creative Service for CDROM Access ;c:\windows\system32\iassvcs32.exe [2010-11-13 1433088]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-6-24 92008]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\27.tmp --> c:\windows\system32\27.tmp [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S4 AJXQJEMDPS;AJXQJEMDPS;c:\docume~1\linda\locals~1\temp\ajxqjemdps.exe --> c:\docume~1\linda\locals~1\temp\AJXQJEMDPS.exe [?]
S4 PTJBQCRXLJ;PTJBQCRXLJ;c:\docume~1\linda\locals~1\temp\ptjbqcrxlj.exe --> c:\docume~1\linda\locals~1\temp\PTJBQCRXLJ.exe [?]
S4 RHEAEIGJZZM;RHEAEIGJZZM;c:\docume~1\linda\locals~1\temp\rheaeigjzzm.exe --> c:\docume~1\linda\locals~1\temp\RHEAEIGJZZM.exe [?]

=============== Created Last 30 ================

2010-11-29 19:44:56 50477 ----a-w- c:\temp\Defogger.exe
2010-11-29 19:33:10 181248 ----a-w- c:\windows\system32\ipxmontr32.exe
2010-11-29 19:16:54 26112 -c--a-w- c:\windows\system32\dllcache\EXCH_seos.dll
2010-11-29 19:15:59 9216 -c--a-w- c:\windows\system32\dllcache\iwrps.dll
2010-11-29 19:14:57 45568 -c--a-w- c:\windows\system32\dllcache\browscap.dll
2010-11-29 19:10:38 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-11-29 19:10:38 16384 ----a-w- c:\program files\internet explorer\connection wizard\isignup.exe
2010-11-29 19:02:08 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-11-29 19:02:08 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-11-29 19:02:08 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-11-29 19:02:08 13312 ----a-w- c:\windows\system32\irclass.dll
2010-11-29 19:01:55 14573 ----a-r- c:\windows\SETB5.tmp
2010-11-29 19:01:47 16535 ----a-r- c:\windows\SET7A.tmp
2010-11-29 19:01:44 1088840 ----a-r- c:\windows\SET6E.tmp
2010-11-29 19:01:42 1296669 ----a-r- c:\windows\SET6D.tmp
2010-11-29 16:01:13 0 ----a-w- c:\windows\system32\8.tmp
2010-11-29 16:01:13 0 ----a-w- c:\windows\system32\6.tmp
2010-11-29 16:01:12 0 ----a-w- c:\windows\system32\5.tmp
2010-11-29 16:01:12 0 ----a-w- c:\windows\system32\4.tmp
2010-11-28 18:05:47 252928 ----a-w- c:\windows\system32\atmlib32.dll
2010-11-28 06:27:05 0 ----a-w- c:\windows\system32\9.tmp
2010-11-27 10:27:05 0 ----a-w- c:\windows\system32\7.tmp
2010-11-22 00:35:52 14573 ----a-r- c:\windows\SETC9.tmp
2010-11-22 00:35:42 13753 ----a-r- c:\windows\SET8E.tmp
2010-11-22 00:35:40 1086058 ----a-r- c:\windows\SET82.tmp
2010-11-22 00:35:38 1056254 ----a-r- c:\windows\SET7F.tmp
2010-11-21 04:45:55 6153352 ----a-w- c:\temp\mbam-setup-1.46.exe
2010-11-21 04:45:31 32219592 ----a-w- c:\temp\cfw_installer_x86.exe
2010-11-21 04:44:56 53123856 ----a-w- c:\temp\avira_antivir_personal_en.exe
2010-11-21 04:33:23 500224 --sha-w- c:\windows\iasrecstwow.exe
2010-11-21 04:31:06 -------- d-sh--w- c:\windows\system32\1C61876B3C4F6A8D90974342CBBA77D3
2010-11-21 04:04:41 14573 ----a-r- c:\windows\SETC8.tmp
2010-11-21 04:04:31 13753 ----a-r- c:\windows\SET8D.tmp
2010-11-21 04:04:29 1086058 ----a-r- c:\windows\SET81.tmp
2010-11-21 04:04:27 1056254 ----a-r- c:\windows\SET7E.tmp
2010-11-21 01:34:32 1433088 ----a-w- c:\windows\system32\ipsmsnap3232.exe
2010-11-21 01:23:18 -------- d--h--w- c:\program files\WindowsUpdate
2010-11-21 01:05:48 14573 ----a-r- c:\windows\SET17B.tmp
2010-11-21 01:05:38 13753 ----a-r- c:\windows\SET140.tmp
2010-11-21 01:05:36 1086058 ----a-r- c:\windows\SET134.tmp
2010-11-21 01:05:33 1056254 ----a-r- c:\windows\SET131.tmp
2010-11-18 02:15:42 1433088 ----a-w- c:\windows\system32\atmlib32.exe
2010-11-18 02:15:40 1433088 ----a-w- c:\windows\system32\evr32.exe
2010-11-17 20:44:32 388096 ----a-r- c:\docume~1\linda\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-11-17 20:40:14 532480 ----a-w- c:\temp\cwshredder.exe
2010-11-17 20:40:14 1913056 ----a-w- c:\temp\HousecallLauncher.exe
2010-11-17 20:40:10 6015152 ----a-w- c:\temp\RUBottedSetup.exe
2010-11-17 20:40:10 51515288 ----a-w- c:\temp\setup_av_free.exe
2010-11-17 07:03:14 1122304 --sha-w- c:\windows\system32\251.tmp
2010-11-16 11:03:14 1125888 --sha-w- c:\windows\system32\D6.tmp
2010-11-15 15:03:14 1125888 --sha-w- c:\windows\system32\29.tmp
2010-11-13 23:38:15 0 ---ha-w- c:\documents and settings\linda\nffuadmxjz.tmp
2010-11-13 14:58:38 181248 ----a-w- c:\windows\system32\ipsecsvc32.exe
2010-11-13 13:08:11 -------- d-sh--w- c:\windows\system32\E2FE0C51BF445D0EBCEF35878430061A
2010-11-13 13:07:58 -------- d-sh--w- c:\windows\system32\SysWoW32
2010-11-13 13:07:40 203776 --sha-w- c:\windows\system32\unrar.exe
2010-11-13 13:07:40 -------- d-----w- c:\windows\system32\1992804126
2010-11-13 13:06:54 1125888 --sha-w- c:\windows\system32\299.tmp
2010-11-13 13:06:53 1125888 --sha-w- c:\windows\system32\298.tmp
2010-11-13 13:06:50 1433088 ----a-w- c:\windows\system32\WMVADVE32.exe
2010-11-13 13:06:49 252928 ----a-w- c:\windows\system32\ipsmsnap32.dll
2010-11-13 13:06:47 1433088 ----a-w- c:\windows\system32\iassvcs32.exe
2010-11-13 13:06:46 181248 ----a-w- c:\windows\system32\ipsmsnap32.exe
2010-10-31 16:41:41 -------- d-----w- c:\program files\iPod
2010-10-31 16:41:22 -------- d-----w- c:\program files\iTunes
2010-10-31 16:37:23 -------- d-----w- c:\program files\Bonjour

==================== Find3M ====================

2010-09-15 08:50:37 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-15 06:29:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-08 15:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts

============= FINISH: 14:48:43.07 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 04 December 2010 - 09:33 AM

I understand that there are more problems to be resolved then there are volunteers to solve them, but, is it possible to let me know if my problem is in the que or has it fallen into the great bit bucket in the sky?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 04 December 2010 - 11:13 PM

Hello LindaMS ,

Posted Image

Sorry for the delay. :( No, noone is ever left behind here. :wink: We have software that keeps track of every single unanswered post and keeps it where it can be seen.

After you run ComboFix you need to get an AntiVirus installed immediately. AVG, Avira OR Avast are good FREE antivirus. I use Avira myself.

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

If you have trouble running it the first time, then rename ComboFix.exe to Linda.exe and try again.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#4 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 05 December 2010 - 04:33 PM

Hello Tea

Thank you so much for providing help with my problem.

I have attached the ComboFix.txt log file.

Recovery Console was not installed and as the machine was not in a location where I could connect it to the internet, RC was not downloaded.

Please let me know if I need to install Recovery Console and run the ComboFix again.

Linda

Attached Files



#5 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 05 December 2010 - 05:16 PM

Hello,

You're welcome. :)

We'll probably run ComboFix again a bit later, but right now I'd like one more scan/clean to go through things. :) This is one you might like to keep to help protect your system.

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

How is it running now please? :)

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#6 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 06 December 2010 - 08:51 PM

Hello Tea

After running MalwareBytes (log follows) I reran Spybot Search & Destroy and it did NOT report finding Virtumonde. The PC is again connected to the internet and, so far, it seems to be working as it should (when the machine was infected it seemed to take control of the router -- the lights were constantly flashing and we would not be able to access anything on the internet). Also, the website redirect seems to be gone.

Linda

--------------------------------------------------
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5249

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

07/12/2010 2:31:04 PM
mbam-log-2010-12-07 (14-31-04).txt

Scan type: Quick scan
Objects scanned: 183725
Time elapsed: 3 minute(s), 50 second(s)

Memory Processes Infected: 3
Memory Modules Infected: 2
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 26

Memory Processes Infected:
c:\WINDOWS\SYSTEM32\ipsmsnap3232.exe (Trojan.Tracur.S) -> 1556 -> Unloaded process successfully.
c:\WINDOWS\SYSTEM32\iassvcs32.exe (Trojan.Tracur.S) -> 1580 -> Unloaded process successfully.
c:\WINDOWS\SYSTEM32\evr32.exe (Trojan.Tracur.S) -> 1600 -> Unloaded process successfully.

Memory Modules Infected:
c:\WINDOWS\SYSTEM32\atmlib32.dll (Trojan.Tracur.S) -> Delete on reboot.
c:\WINDOWS\SYSTEM32\299.tmp (Trojan.Tracur.S) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Creative Service for CDROM Access32 (Trojan.Tracur.S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{AE617046-C91B-CE0B-9DDF-3E1F31CCB638} (Trojan.Tracur.S) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE617046-C91B-CE0B-9DDF-3E1F31CCB638} (Trojan.Tracur.S) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE617046-C91B-CE0B-9DDF-3E1F31CCB638} (Trojan.Tracur.S) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur.S) -> Bad: (C:\WINDOWS\SYSTEM32\atmlib32.dll) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\SYSTEM32\ipsmsnap3232.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\atmlib32.dll (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\299.tmp (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\iassvcs32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\evr32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\ipsmsnap32.dll (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\atmlib32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\D6.tmp (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\ipsecsvc32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\ipsmsnap32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\java.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\wmvadve32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\251.tmp (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\29.tmp (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\298.tmp (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\ipxmontr32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\WINDOWS\iasrecstwow.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\020000001f48e1a11073c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\020000001f48e1a11073o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\020000001f48e1a11073p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\020000001f48e1a11073s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\020000001f48e1a11073c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\020000001f48e1a11073o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\020000001f48e1a11073p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\020000001f48e1a11073s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\SYSTEM32\gnuhashes.ini (Trojan.Tracur) -> Quarantined and deleted successfully.

#7 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 06 December 2010 - 09:13 PM

Hi Linda,

Glad it's better. :thumbup2: MBAM took out a lot more than I expected....really good. Getting rid of a LOT of junk here a little at a time. If you would please have another run with ComboFix now, that would be great. Leave it online for the recovery console if it wants to be. It will automatically take you offline when it starts its run, so you'll be safe. :thumbup2: Post the report in your reply, then we'll get rid of any leftovers.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#8 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 07 December 2010 - 11:10 AM

Hi tea

ComboFix log attached.

Linda

Attached Files



#9 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 07 December 2010 - 11:22 AM

Mornin' Linda :)

* Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the quote box below into notepad:

FILE::
c:\windows\SETC8.tmp
c:\windows\SET8D.tmp
c:\windows\SET81.tmp
c:\windows\SET7E.tmp
c:\windows\SET17B.tmp
c:\windows\SET140.tmp
c:\windows\SET134.tmp
c:\windows\SET131.tmp
c:\windows\SETB5.tmp
c:\windows\SET7A.tmp
c:\windows\SET6E.tmp
c:\windows\SET6D.tmp
c:\windows\system32\8.tmp
c:\windows\system32\6.tmp
c:\windows\system32\5.tmp
c:\windows\system32\4.tmp
c:\windows\system32\7.tmp
c:\windows\SETC9.tmp
c:\windows\SET8E.tmp
c:\windows\SET82.tmp
c:\windows\SET7F.tmp
c:\documents and settings\Linda\nffuadmxjz.tmp
c:\documents and settings\Mandy\nffuadmxjz.tmp
c:\documents and settings\Madison\nffuadmxjz.tmp
c:\docume~1\Linda\LOCALS~1\Temp\AJXQJEMDPS.exe
c:\docume~1\Linda\LOCALS~1\Temp\PTJBQCRXLJ.exe
c:\docume~1\Linda\LOCALS~1\Temp\RHEAEIGJZZM.exe


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again.

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

How is it running now?

tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#10 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 07 December 2010 - 04:08 PM

Hi tea

ComboFix.txt attached

PC still seems to be okay.

Linda

Attached Files



#11 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 07 December 2010 - 04:14 PM

Hi Linda,

Uninstall ComboFix by doing the following :

Click Start>Run>Type in, or copy and paste ComboFix /Uninstall > click OK

I see you downloaded Avira. :thumbup2: Install it and let it update, then have a scan with it. If it comes out clean, then I believe we're done here. :) Let me know!

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#12 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 07 December 2010 - 07:26 PM

Hi tea

ComboFix uninstalled as instructed.
Avira installed and updated. The scan found 7 viruses/unwanted programs.
Log attached.

Linda

Attached Files



#13 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 07 December 2010 - 07:34 PM

Excellent....thank you Linda. :thumbup2: You did let Avira clean them, yes? Run the scan again to be sure it's clean this time.

tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#14 LindaMS

LindaMS
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:07:35 AM

Posted 09 December 2010 - 07:23 AM

Good morning tea

Sorry for the delay in getting back to you.

Yes, I did let Avira clean-up on the first run. I ran it again and it looks like the PC is clean (log attached). I also ran MBAM again and that also came up clean.

I am now using the Comodo firewall (instead of Windows) and will run Avira and MBAM on a regular basis. These programs will also be installed on my granddaughter's computer.

Thank you so much for all of your help, it really is appreciated!! :)

Linda

Attached Files



#15 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:35 AM

Posted 09 December 2010 - 12:06 PM

Hi Linda,

Wonderful to know, and you're most welcome. :)

Take care!
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users