Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Virtumonde Infection

  1. #1
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default Virtumonde Infection

    Over the past few days I've had a lot of advertising popup windows appearing whilst using my PC. According to Spybot, I'm infected with Virtumonde and can't seem to shift it, like so many others it seems.

    I've run Spybot S&D in safe mode, run a full virus scan with Norton AntiVirus and tried the Kaspersky online scanner. Below are my Kaspersky and Hijack This logs.

    I'd be very grateful for any advice that anyone could offer.

    Kaspersky Log:

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Tuesday, October 16, 2007 9:59:58 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 16/10/2007
    Kaspersky Anti-Virus database records: 436805
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\

    Scan Statistics:
    Total number of scanned objects: 246716
    Number of viruses found: 7
    Number of infected objects: 18
    Number of suspicious objects: 0
    Duration of the scan process: 04:03:55

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\cert8.db Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\history.dat Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\key3.db Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\parent.lock Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\urlclassifier2.sqlite Object is locked skipped
    C:\Documents and Settings\Alan\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_001_ Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_002_ Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_003_ Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_MAP_ Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\History\History.IE5\MSHist012007101620071017\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Alan\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-16_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\VundoFix Backups\awtuvus.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\VundoFix Backups\ddcdcyw.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\VundoFix Backups\pmnopqo.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\VundoFix Backups\rqrrrrp.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\VundoFix Backups\ssqommk.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\VundoFix Backups\vtuvvuv.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\system32\apophvlr.exe Infected: not-a-virus:AdWare.Win32.SecToolBar.g skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
    C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd6813.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    F:\Downloads\mIRC 6.2.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    F:\Downloads\mIRC 6.2.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    F:\Downloads\mIRC 6.2.exe NSIS: infected - 2 skipped
    F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe/data0000.cab/OBJECT~2.EXE Infected: Backdoor.Win32.Poison.k skipped
    F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe/data0000.cab Infected: Backdoor.Win32.Poison.k skipped
    F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe Rsrc-Package: infected - 2 skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45BB3D3C Infected: Trojan-Downloader.Win32.Tiny.id skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45C25A12 Infected: Trojan-Downloader.Win32.Tiny.id skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45D22C00.exe Infected: Trojan.Win32.Agent.ye skipped
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45D555FC.tmp Infected: Trojan.Win32.Agent.ye skipped
    F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    H:\Temp\Perflib_Perfdata_4d8.dat Object is locked skipped
    H:\Temp\xpigelmh.exe Infected: Trojan.Win32.Agent.bck skipped
    H:\Temp\~DF4BBB.tmp Object is locked skipped
    H:\Temp\~DF702.tmp Object is locked skipped
    H:\Temporary Internet Files\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    H:\Temporary Internet Files\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    Scan process completed.

  2. #2
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default

    Hijack This Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:19:03, on 16/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\taskswitch.exe
    F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    F:\Program Files\Comodo\Firewall\CPF.exe
    F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    F:\Program Files\Bonjour\mDNSResponder.exe
    F:\Program Files\Comodo\Firewall\cmdagent.exe
    F:\Program Files\Kontiki\KService.exe
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    F:\Program Files\CyberLink\Shared files\RichVideo.exe
    F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    F:\Program Files\iPod\bin\iPodService.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.hull.ac.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Program Files\Comodo\Firewall\CPF.exe" /background
    O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "F:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\Program Files\Ares\chatServer.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: OLE multi config - Unknown owner - C:\WINDOWS\system32\ole2.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - F:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 9092 bytes

  3. #3
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi Alan Crisp,

    ive seen you already have run vundofix. do this:

    Please download ComboFix (by sUBs) from one of the following links:

    http://www.techsupportforum.com/sect...s/ComboFix.exe

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Save it to the Desktop.
    Double-click combofix.exe and follow the prompts.

    CAUTION: Do not mouse-click ComboFix's window while it is running.
    It may cause it to stall.

    When finished, it produces a log.

    Please provide the contents of the ComboFix log in your reply--

    shelf life
    How Can I Reduce My Risk?

  4. #4
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default

    Many thanks for your reply shelf life.

    I had indeed tried Vundofix but it didn't seem to work. I must have forgotten to mention that in my initial post. I've now run ComboFix and attached the log below.

    ComboFix 07-10-17.8@ - Alan 2007-10-18 15:52:17.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.543 [GMT 1:00]
    Running from: G:\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\cookies.ini
    C:\WINDOWS\system32\rqstv.bak1
    C:\WINDOWS\system32\rqstv.bak1
    C:\WINDOWS\system32\rqstv.bak2
    C:\WINDOWS\system32\rqstv.bak2
    C:\WINDOWS\system32\rqstv.ini
    C:\WINDOWS\system32\rqstv.ini
    C:\WINDOWS\system32\vtsqr.dll
    C:\WINDOWS\system32\vtsqr.dll

    .
    ((((((((((((((((((((((((( Files Created from 2007-09-18 to 2007-10-18 )))))))))))))))))))))))))))))))
    .

    2007-10-16 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2007-10-16 15:50 <DIR> d-------- C:\VundoFix Backups
    2007-10-16 15:48 <DIR> d-------- F:\Program Files\Trend Micro
    2007-10-15 18:20 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\Lavasoft
    2007-10-15 18:04 <DIR> d-------- F:\Program Files\Lavasoft
    2007-10-11 17:40 <DIR> d-------- F:\Program Files\JAMMER Professional 5
    2007-10-08 00:27 <DIR> d-------- F:\Program Files\DVD Shrink
    2007-10-08 00:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
    2007-10-07 19:30 <DIR> d-------- F:\Program Files\RealMedia
    2007-10-07 19:30 <DIR> d-------- F:\Program Files\OpenSource Flash Video Splitter
    2007-10-07 19:30 <DIR> d-------- F:\Program Files\CD Audio Reader Filter
    2007-10-07 19:29 <DIR> d-------- F:\Program Files\SHOUTcast Source
    2007-10-07 19:28 <DIR> d-------- F:\Program Files\DirectVobSub
    2007-10-07 18:44 <DIR> d-------- F:\Program Files\Mozilla Sunbird
    2007-10-07 04:00 <DIR> d-------- F:\Program Files\Flare
    2007-10-06 15:59 <DIR> d-------- F:\Program Files\iPod
    2007-10-06 12:24 <DIR> d-------- F:\Program Files\SymNetDrv
    2007-10-06 12:13 <DIR> d-------- F:\Program Files\Symantec
    2007-10-06 12:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
    2007-10-05 20:20 <DIR> d-------- F:\Program Files\Max Payne
    2007-10-05 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
    2007-10-05 18:59 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\nView_Wallpaper
    2007-10-05 18:25 <DIR> d-------- F:\Program Files\FLVPlayer
    2007-10-05 18:15 <DIR> d-------- F:\Program Files\Nvidia
    2007-10-03 16:18 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\CyberLink
    2007-10-03 16:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
    2007-10-03 16:16 <DIR> d-------- F:\Program Files\CyberLink
    2007-09-30 13:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
    2007-09-22 16:20 <DIR> d-------- F:\Program Files\LimeWire
    2007-09-22 16:20 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\LimeWire
    2007-09-21 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
    2007-09-21 16:22 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\Comodo
    2007-09-21 16:19 <DIR> d-------- F:\Program Files\Comodo
    2007-09-21 11:17 <DIR> d-------- F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
    2007-09-20 18:59 <DIR> d-------- F:\Program Files\Unreal Tournament 2004
    2007-09-20 18:57 <DIR> d-------- F:\Program Files\DAEMON Tools

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-18 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
    2007-10-16 13:30 --------- d-----w C:\Documents and Settings\Alan\Application Data\uTorrent
    2007-10-15 16:29 --------- d-----w F:\Program Files\Norton SystemWorks
    2007-10-14 18:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2007-10-13 11:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2007-10-10 21:36 --------- d-----w C:\Documents and Settings\Alan\Application Data\mIRC
    2007-10-10 21:13 --------- d-----w F:\Program Files\mIRC
    2007-10-09 12:46 --------- d-----w F:\Program Files\Kontiki
    2007-10-06 14:59 --------- d-----w F:\Program Files\iTunes
    2007-10-06 11:14 4,608 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
    2007-10-05 19:20 --------- d--h--w F:\Program Files\InstallShield Installation Information
    2007-10-01 11:03 --------- d-----w C:\Documents and Settings\Alan\Application Data\Symantec
    2007-09-25 18:23 --------- d-----w F:\Program Files\DivX
    2007-09-22 15:10 --------- d-----w F:\Program Files\Ares
    2007-09-21 15:19 --------- d-----w F:\Program Files\PC Tools Firewall Plus
    2007-09-21 10:17 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-09-20 17:57 223,128 ----a-w C:\WINDOWS\system32\drivers\dtscsi.sys
    2007-09-15 10:56 --------- d-----w F:\Program Files\AVI Joiner
    2007-09-12 15:52 --------- d-----w F:\Program Files\Apple Software Update
    2007-09-06 17:31 --------- d-----w F:\Program Files\KC Softwares
    2007-09-06 12:12 --------- d-----w F:\Program Files\Sibelius Software
    2007-09-06 12:12 --------- d-----w F:\Program Files\Native Instruments
    2007-09-06 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sibelius Software
    2007-09-06 10:39 --------- d-----w C:\Documents and Settings\Alan\Application Data\Apple Computer
    2007-09-05 16:42 --------- d-----w F:\Program Files\Safari
    2007-09-05 16:31 --------- d-----w F:\Program Files\Bonjour
    2007-09-04 20:53 --------- d-----w F:\Program Files\Microsoft Works
    2007-09-04 20:30 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6813.sys
    2007-09-04 20:30 642,560 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
    2007-09-04 20:27 --------- d-----w F:\Program Files\MagicISO
    2007-09-04 00:39 --------- d-----w C:\Documents and Settings\Alan\Application Data\Multi-Remote Shutdown Manager
    2007-09-04 00:26 --------- d-----w F:\Program Files\MSXML 4.0
    2007-09-04 00:13 --------- d-----w F:\Program Files\Google
    2007-09-03 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Age of Empires 3
    2007-09-02 23:43 --------- d-----w F:\Program Files\Microsoft Games
    2007-09-02 12:30 --------- d-----w F:\Program Files\Monte Cristo
    2007-08-31 18:00 --------- d-----w C:\Documents and Settings\Alan\Application Data\Sibelius Software
    2007-08-29 23:59 --------- d-----w F:\Program Files\FastStone Capture
    2007-08-29 11:33 --------- d-----w F:\Program Files\Opera
    2007-08-28 11:09 --------- d-----w F:\Program Files\AceIt
    2007-08-28 01:22 --------- d-----w F:\Program Files\FreeDiff
    2007-08-28 01:20 249,856 ------w C:\WINDOWS\Setup1.exe
    2007-08-28 01:19 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
    2007-08-27 20:30 --------- d-----w F:\Program Files\trainsimfiles
    2007-08-27 18:15 --------- d-----w F:\Program Files\Route_Riter
    2007-08-27 15:39 --------- d-----w F:\Program Files\VirtualDJ
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opustext.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opuss___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSROMC.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opuspc__.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opusp___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSM___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSJAPC.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFBE_.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFB__.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opusc___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opus____.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Inkpen2_.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2text.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2spec.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2scri.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2METR.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2chor.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELST___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSS___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSM___.FOT
    2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSINKI.FOT
    2007-08-27 01:56 --------- d-----w F:\Program Files\Train Store
    2007-08-26 19:54 --------- d-----w F:\Program Files\Java
    2007-08-26 19:53 --------- d-----w C:\Program Files\Common Files\Java
    2007-08-26 18:40 --------- d-----w C:\Documents and Settings\Alan\Application Data\DivX
    2007-08-26 17:00 --------- d-----w F:\Program Files\SmartFTP Client
    2007-08-26 17:00 --------- d-----w C:\Documents and Settings\Alan\Application Data\SmartFTP
    2007-08-26 16:42 --------- d-----w C:\Documents and Settings\Alan\Application Data\WaterProof
    2007-08-26 16:40 --------- d-----w F:\Program Files\WaterProof
    2007-08-26 15:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2007-08-26 15:09 --------- d-----w F:\Program Files\Windows Live
    2007-08-26 15:09 --------- d-----w F:\Program Files\MSN Messenger
    2007-08-26 15:09 --------- d-----w F:\Program Files\Messenger Plus! Live
    2007-08-25 18:21 --------- d-----w F:\Program Files\AC3Filter
    2007-08-24 22:41 --------- d-----w F:\Program Files\uTorrent
    2007-08-24 22:22 --------- d-----w C:\Program Files\Common Files\Adobe
    2007-08-24 22:00 --------- d-----w F:\Program Files\Shape Viewer
    2007-08-24 21:35 --------- d-----w F:\Program Files\ConBuilder
    2007-08-24 18:44 --------- d-----w C:\Documents and Settings\Alan\Application Data\AdobeUM
    2007-08-24 15:35 --------- d-----w F:\Program Files\MWGraphics
    2007-08-24 15:26 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-08-24 14:41 --------- d-----w F:\Program Files\Real
    2007-08-24 14:41 --------- d-----w C:\Program Files\Common Files\xing shared
    2007-08-24 14:41 --------- d-----w C:\Program Files\Common Files\Real
    2007-08-24 14:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-08-24 14:15 --------- d-----w F:\Program Files\MSXML 6.0
    2007-08-24 14:12 --------- d-----w F:\Program Files\QuickTime
    2007-08-24 14:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
    2007-08-24 14:11 --------- d-----w C:\Program Files\Common Files\Apple
    2007-08-24 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
    2007-08-24 13:36 --------- d-----w C:\Documents and Settings\Alan\Application Data\IsolatedStorage
    2007-08-24 13:28 --------- d-----w F:\Program Files\MSBuild
    2007-08-24 12:37 --------- d-----w C:\Documents and Settings\Alan\Application Data\Thunderbird
    2007-08-24 11:55 --------- d-----w F:\Program Files\Mozilla Thunderbird
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
    2007-10-18 15:47 340032 --a------ C:\WINDOWS\system32\nojdzlja.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\nojdzlja.dll [2007-10-18 15:47 340032]

    [HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WINDVDPatch"="CTHELPER.EXE" [2002-07-02 10:56 C:\WINDOWS\system32\CTHELPER.EXE]
    "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
    "Jet Detection"="F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
    "CTStartup"="C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe" [2001-12-20 01:00]
    "QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-24 15:41]
    "CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30]
    "Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
    "SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
    "COMODO Firewall Pro"="F:\Program Files\Comodo\Firewall\CPF.exe" [2007-09-21 16:19]
    "RemoteControl"="F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57]
    "LanguageShortcut"="F:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 11:29]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26]
    "nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
    "Symantec NetDriver Monitor"="F:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-10-06 12:24]
    "iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

    C:\Documents and Settings\Alan\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nojdzlja]
    nojdzlja.dll 2007-10-18 15:47 340032 C:\WINDOWS\system32\nojdzlja.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqr.dll

    R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
    S2 OLE multi config;OLE multi config;C:\WINDOWS\system32\ole2.exe
    S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys
    S3 SDdriver;SDdriver;\??\C:\WINDOWS\system32\Drivers\sddriver.sys

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da04b16b-51e4-11dc-a577-806d6172696f}]
    AutoRun\command - D:\ctrun\start.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-09-12 13:21:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - F:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-10-12 19:01:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Alan.job"
    "2007-10-15 16:29:15 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
    "2007-10-16 23:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
    .
    **************************************************************************

    catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-10-18 15:57:34
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???h??????s?????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&2???A~??A~????????\???\???????????U?A~??A~\???\?????????`??????C@?\???\??????s????\??????s\????&2?A??s?&2??C@?x???`|?w\?????@

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-10-18 16:00:33 - machine was rebooted
    .
    --- E O F ---

  5. #5
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi Alan Crisp,

    thanks for the info. vundofix gets updated sometimes. delete your copy and redownload another:

    download and run vundofix.exe:

    http://www.atribune.org/ccount/click.php?id=4

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

    please post the vundo log and anew hjt log.

    shelf life
    How Can I Reduce My Risk?

  6. #6
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default

    Hi again,

    I've downloaded a fresh copy of VundoFix and run it again. It looks as though it may have worked. Hopefully you can confirm that.

    As requested, VundoFix and Hijack This logs are pasted below.

    Thanks.

    VundoFix Log:

    VundoFix V6.5.10

    Checking Java version...

    Sun Java not detected
    Scan started at 15:50:10 16/10/2007

    Listing files found while scanning....

    C:\windows\system32\awtuvus.dll
    C:\windows\system32\ddcdcyw.dll
    C:\windows\system32\dtuvvggl.ini
    C:\WINDOWS\system32\fnvphrun.dll
    C:\windows\system32\lggvvutd.dll
    C:\WINDOWS\system32\nurhpvnf.ini
    C:\windows\system32\pmnopqo.dll
    C:\windows\system32\rqrrrrp.dll
    C:\WINDOWS\system32\ssqommk.dll
    C:\WINDOWS\system32\uvtaxlkk.dll
    C:\windows\system32\vtuvvuv.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\awtuvus.dll
    C:\windows\system32\awtuvus.dll Has been deleted!

    Attempting to delete C:\windows\system32\ddcdcyw.dll
    C:\windows\system32\ddcdcyw.dll Has been deleted!

    Attempting to delete C:\windows\system32\dtuvvggl.ini
    C:\windows\system32\dtuvvggl.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\fnvphrun.dll
    C:\WINDOWS\system32\fnvphrun.dll Has been deleted!

    Attempting to delete C:\windows\system32\lggvvutd.dll
    C:\windows\system32\lggvvutd.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\nurhpvnf.ini
    C:\WINDOWS\system32\nurhpvnf.ini Has been deleted!

    Attempting to delete C:\windows\system32\pmnopqo.dll
    C:\windows\system32\pmnopqo.dll Has been deleted!

    Attempting to delete C:\windows\system32\rqrrrrp.dll
    C:\windows\system32\rqrrrrp.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ssqommk.dll
    C:\WINDOWS\system32\ssqommk.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\uvtaxlkk.dll
    C:\WINDOWS\system32\uvtaxlkk.dll Could not be deleted.

    Attempting to delete C:\windows\system32\vtuvvuv.dll
    C:\windows\system32\vtuvvuv.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\ssqommk.dll
    C:\WINDOWS\system32\ssqommk.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\uvtaxlkk.dll
    C:\WINDOWS\system32\uvtaxlkk.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.5.10

    Checking Java version...

    Sun Java not detected
    Scan started at 00:22:30 19/10/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\nojdzlja.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\nojdzlja.dll
    C:\WINDOWS\system32\nojdzlja.dll Could not be deleted.

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\nojdzlja.dll
    C:\WINDOWS\system32\nojdzlja.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    New Hijack This Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 01:32:24, on 19/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    F:\Program Files\Bonjour\mDNSResponder.exe
    F:\Program Files\Comodo\Firewall\cmdagent.exe
    F:\Program Files\Kontiki\KService.exe
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    F:\Program Files\CyberLink\Shared files\RichVideo.exe
    F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\taskswitch.exe
    F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    F:\Program Files\Comodo\Firewall\CPF.exe
    F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    F:\Program Files\iPod\bin\iPodService.exe
    F:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
    F:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.hull.ac.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Program Files\Comodo\Firewall\CPF.exe" /background
    O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "F:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\Program Files\Ares\chatServer.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: OLE multi config - Unknown owner - C:\WINDOWS\system32\ole2.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - F:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 9696 bytes

  7. #7
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi Alan Crisp,

    ok good. please run vundofix again for a second pass.and post the log. if all looks ok on your end we will make new restore points.

    shelf life
    How Can I Reduce My Risk?

  8. #8
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default

    Hi,

    VundoFix didn't find any infected files this time around. The latest log entry is below.

    Thanks.

    VundoFix V6.5.10

    Checking Java version...

    Sun Java not detected
    Scan started at 12:49:06 19/10/2007

    Listing files found while scanning....

    No infected files were found.

  9. #9
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi Alan Crisp,

    so hows it looking on your end now?

    shelf life
    How Can I Reduce My Risk?

  10. #10
    Junior Member
    Join Date
    Oct 2007
    Posts
    6

    Default

    As far as I can tell, the system seems to be clean now. Haven't had any recent problems, although I'll keep an eye on it for the next few days.

    Many thanks for the assistance.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •