Hello all, I have been doing a lot of work trying to get rid of this virus with no luck, if ne1 can help me I would really appreciate it. I've followed all the instructions required before posting and here are my logs one of which is from Panda and the other HJT.
TIA.
Incident Status Location
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/spywarequake Not disinfected c:\windows\system32\1024\ldA512.tmp
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 1)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\cbxvttq.dll( 2)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 4)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 5)
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\32msztux.default\cookies.txt[.zedo.com/]
Virus:Trj/Mitglieder.BO Not disinfected C:\Documents and Settings\Me\Application Data\Thunderbird\Profiles\default\z7g2h418.slt\Mail\pop.abs.adelphia.net\Inbox[543.rar][dddd.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-173830-567.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-185847-352.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-190226-840.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070301-220054-861.dll
Potentially unwanted tool:Application/Pskill.K Not disinfected C:\Documents and Settings\Me\Desktop\bin\pskill.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Me\Desktop\VundoFix\VundoFix\process.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\acxpefnm.dll
Potentially unwanted tool:Application/Processor Not disinfected D:\Downloads\Scanned\smitRem.exe[smitRem/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected D:\Downloads\VundoFix.exe[process.exe]
Potentially unwanted tool:Application/Pskill.K Not disinfected D:\DVDTools\bin\pskill.exe
Potentially unwanted tool:Application/Pskill.K Not disinfected D:\DVDTools\pgcedit.exe[Tcl/work/PGCEDIT/bin/pskill.exe]
__________________________
Logfile of HijackThis v1.99.1
Scan saved at 1:54:56 PM, on 3/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Documents and Settings\Me\Desktop\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {43149305-FB38-4A1A-AE45-C6B6AF05EC0A} - C:\WINDOWS\system32\yayxx.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - D:\Program Files\FlashCapture\fcbho.dll
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKLM\..\Run: [WinPatrol PLUS] C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: cbxvttq - cbxvttq.dll (file missing)
O20 - Winlogon Notify: yayxx - C:\WINDOWS\system32\yayxx.dll (file missing)
O20 - Winlogon Notify: yayyy - C:\WINDOWS\system32\yayyy.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
TIA.
Incident Status Location
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/spywarequake Not disinfected c:\windows\system32\1024\ldA512.tmp
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 1)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\cbxvttq.dll( 2)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 4)
Spyware:Spyware/Virtumonde Not disinfected C:\!KillBox\CBXVTTQ.DLL( 5)
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\32msztux.default\cookies.txt[.zedo.com/]
Virus:Trj/Mitglieder.BO Not disinfected C:\Documents and Settings\Me\Application Data\Thunderbird\Profiles\default\z7g2h418.slt\Mail\pop.abs.adelphia.net\Inbox[543.rar][dddd.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-173830-567.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-185847-352.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070225-190226-840.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Me\Desktop\backups\backup-20070301-220054-861.dll
Potentially unwanted tool:Application/Pskill.K Not disinfected C:\Documents and Settings\Me\Desktop\bin\pskill.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Me\Desktop\VundoFix\VundoFix\process.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\acxpefnm.dll
Potentially unwanted tool:Application/Processor Not disinfected D:\Downloads\Scanned\smitRem.exe[smitRem/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected D:\Downloads\VundoFix.exe[process.exe]
Potentially unwanted tool:Application/Pskill.K Not disinfected D:\DVDTools\bin\pskill.exe
Potentially unwanted tool:Application/Pskill.K Not disinfected D:\DVDTools\pgcedit.exe[Tcl/work/PGCEDIT/bin/pskill.exe]
__________________________
Logfile of HijackThis v1.99.1
Scan saved at 1:54:56 PM, on 3/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Documents and Settings\Me\Desktop\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {43149305-FB38-4A1A-AE45-C6B6AF05EC0A} - C:\WINDOWS\system32\yayxx.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - D:\Program Files\FlashCapture\fcbho.dll
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
O4 - HKLM\..\Run: [WinPatrol PLUS] C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: cbxvttq - cbxvttq.dll (file missing)
O20 - Winlogon Notify: yayxx - C:\WINDOWS\system32\yayxx.dll (file missing)
O20 - Winlogon Notify: yayyy - C:\WINDOWS\system32\yayyy.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe