Page 2 of 2 FirstFirst 12
Results 11 to 13 of 13

Thread: Virtumonde that will not die

  1. #11
    Junior Member
    Join Date
    Dec 2007
    Posts
    23

    Default info on symantec issues

    Hello again.

    I'm ready to send this computer home as well, but thanks for helping me make sure, she won't just bring it back

    OK here's the Symantec log. It exports it as a .csv, which I took from excel into notepad. The first bunch of lines are the column headings. If you can spread it out on a landscape sheet it may be readable.

    Risk Action Count Filename Risk Type Original Location Computer User Status Current Location Primary Action Secondary Action Logged By Action Description Date
    Trojan.Duntek Cleaned by deletion 2 A0069941.dll File C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP689\ KRISTIE KRISTIE\Kristie Addington Infected C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP689\ Clean security risk Quarantine Auto-Protect scan 12/10/2007 23:12
    Downloader Cleaned by deletion 2 A0069939.exe File C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP689\ KRISTIE KRISTIE\Kristie Addington Infected C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP689\ Clean security risk Quarantine Auto-Protect scan 12/10/2007 23:12
    Trojan.Vundo Cleaned by deletion 134 A0068566.dll File C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP679\ KRISTIE KRISTIE\Kristie Addington Infected C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP679\ Clean security risk Quarantine Auto-Protect scan 12/10/2007 23:12
    GLP Deleted 1 catchme2007-11-27_214746.93.zip File; Macro C:\qoobox\Quarantine\ KRISTIE KRISTIE\Kristie Addington Deleted Deleted Delete Leave alone (log only) Manual scan The file was deleted successfully. 12/9/2007 19:15
    ?????? Left alone 1 catchme2007-11-27_214746.93.zip Compressed file C:\qoobox\Quarantine\ KRISTIE KRISTIE\Kristie Addington No infected items C:\qoobox\Quarantine\ Leave alone (log only) Leave alone (log only) Manual scan The file was left unchanged. 12/9/2007 9:43
    Trojan.Vundo Cleaned by deletion 1 ddccy.dll File; Compressed file C:\qoobox\Quarantine\catchme2007-11-27_214746.93.zip KRISTIE KRISTIE\Kristie Addington Infected C:\qoobox\Quarantine\catchme2007-11-27_214746.93.zip Clean security risk Quarantine Manual scan 12/9/2007 9:43
    Trojan.Duntek Cleaned by deletion 2 wyejpypn.dll.vir File C:\qoobox\Quarantine\C\WINDOWS\system32\ KRISTIE KRISTIE\Kristie Addington Infected C:\qoobox\Quarantine\C\WINDOWS\system32\ Clean security risk Quarantine Manual scan 12/9/2007 9:43
    Downloader Cleaned by deletion 2 mrofinu572.exe.vir File C:\qoobox\Quarantine\C\WINDOWS\ KRISTIE KRISTIE\Kristie Addington Infected C:\qoobox\Quarantine\C\WINDOWS\ Clean security risk Quarantine Manual scan 12/9/2007 9:43

    Symantec caught more vundos in the APTemp folder of Symantec, a file called APQ422C, with reboot required to fix it. The computer just restarted during the scan (laptop overheated?) and after the restart I rescanned with Symantec and it came up clean. I also rescanned with Spybot and AVG, and they came up clean as well (except for a HitBox cookie).

    About the files under the qoobox\quarantine, I typed the files and folders out, then thought about trying to delete them again, and lo and behold the deleted just fine. In case you're interested, the stuff's below. The lines were tabbed so each line is a folder with subfolders and files

    Thanks again


    Under C
    documents and settings
    all users
    Live safety center.ink.vir
    online security guide.ink.vir
    Kristie Addington
    Favorites
    online security guide.ink.vir
    Program Files
    screensavers.com
    sssuninst.exe.vir
    ActiveDesktop
    bin
    activedesktop.exe.vir
    temp
    1cb
    syscheck.log.vir
    avW9
    tPho.log.vir

    windows
    cookies.ini.vir
    system32
    btepkr.dll.vir
    ddccy.dll.vir
    golpvcyl.ini.vir
    lycvplog.dll.vir
    pac.txt.vir
    yccdd.ini2.vir
    yccdd.ini.vir
    zhdxikxx.dllbox.vir
    ASKS~1
    <no files>
    drivers
    core.cache.dsk.vir
    core.sys.vir
    n8
    ensts2dll.exe.vir

  2. #12
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Not being a Symantec user, I am not familiar with their log, but here is what I see:

    C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B
    These are infected System Restore files and no matter what Symantec says it did, they are protected files. This is the only way you can clean those:
    http://www.microsoft.com/windowsxp/u...s/mcgill1.mspx

    C:\qoobox\Quarantine\ <<< this is the folder used by combofix to quarantine infected files removed by the tool and store files in the event sUBs needs to have them moved to him for some reason. This folder should be deleted completely as well as combofix. The program does not update and must be downloaded new if ever needed again.

    Since you read this same information I read: http://www.fileinfo.net/extension/vir
    If you have not deleted those, I would do so.

    A quick look back over this topic tends to make me think the ower does not realize how serious things are now on the internet, see this:
    http://www.theregister.com/2007/05/1...e_malware_map/
    http://redtape.msnbc.com/2007/05/the_next_net_th.html
    http://www.channelregister.co.uk/200...tispyware_ads/

    This information may help if they will read and follow the suggestions that apply to them:
    http://users.telenet.be/bluepatchy/m...wcomputer.html

    Here is some great information from experts in this field that will help you stay clean and safe online.
    http://users.telenet.be/bluepatchy/m...revention.html
    http://forums.spybot.info/showthread.php?t=279
    http://russelltexas.com/malware/allclear.htm
    http://forum.malwareremoval.com/viewtopic.php?t=14
    http://www.bleepingcomputer.com/forums/topict2520.html
    http://cybercoyote.org/security/not-admin.shtml

    Thanks...pskelley
    Safer Networking Forums
    http://www.spybot.info/en/donate/index.html
    If you are reading this information...thank a teacher,
    If you are reading it in English...thank a soldier.

    As a second thought I also suggest, time permitting, a free diagnostic here: http://www.pcpitstop.com/pcpitstop/
    Might shed some light on other issues.
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  3. #13
    Junior Member
    Join Date
    Dec 2007
    Posts
    23

    Thumbs up Baby is going home

    Cleaned the restore
    cleaned the combofix quarantine
    ran a pcpitstop, which said most things are OK, could use more memory (couldn't we all)
    what was I saying?

    Seriously though, thank you so much. As far as educating the owner, I think being without her laptop for two weeks and seeing her nephews infect her sisters and mothers computers (I may be back on the forum..., or may simpy suggest a disk wipe) she's convinced and will maintain the software I put on her computer, BUT I will keep a copy of the thread on her desktop if ever she needs a reminder, particularly your last message. And I will also encourage her to send a donation to SpyBot.

    Hope your helping advice leads on a journey of ever more joy in the killing of these nasties...

    Farewell

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •