PDA

View Full Version : Virtumonde Infection



Alan Crisp
2007-10-16, 23:23
Over the past few days I've had a lot of advertising popup windows appearing whilst using my PC. According to Spybot, I'm infected with Virtumonde and can't seem to shift it, like so many others it seems.

I've run Spybot S&D in safe mode, run a full virus scan with Norton AntiVirus and tried the Kaspersky online scanner. Below are my Kaspersky and Hijack This logs.

I'd be very grateful for any advice that anyone could offer.

Kaspersky Log:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 16, 2007 9:59:58 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/10/2007
Kaspersky Anti-Virus database records: 436805
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics:
Total number of scanned objects: 246716
Number of viruses found: 7
Number of infected objects: 18
Number of suspicious objects: 0
Duration of the scan process: 04:03:55

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\cert8.db Object is locked skipped
C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\history.dat Object is locked skipped
C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\key3.db Object is locked skipped
C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\parent.lock Object is locked skipped
C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Alan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\Application Data\Mozilla\Firefox\Profiles\bn3tn5ox.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Alan\Local Settings\History\History.IE5\MSHist012007101620071017\index.dat Object is locked skipped
C:\Documents and Settings\Alan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Alan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-16_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\VundoFix Backups\awtuvus.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\VundoFix Backups\ddcdcyw.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\VundoFix Backups\pmnopqo.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\VundoFix Backups\rqrrrrp.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\VundoFix Backups\ssqommk.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\VundoFix Backups\vtuvvuv.dll.bad Infected: Trojan-Downloader.Win32.Agent.dlu skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\apophvlr.exe Infected: not-a-virus:AdWare.Win32.SecToolBar.g skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd6813.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\Downloads\mIRC 6.2.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
F:\Downloads\mIRC 6.2.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
F:\Downloads\mIRC 6.2.exe NSIS: infected - 2 skipped
F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe/data0000.cab/OBJECT~2.EXE Infected: Backdoor.Win32.Poison.k skipped
F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe/data0000.cab Infected: Backdoor.Win32.Poison.k skipped
F:\Downloads\Torrents\Stardock ObjectDock Plus 1.90\Stardock ObjectDock Plus 1.90 535u\objectdockplus_190.exe Rsrc-Package: infected - 2 skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45BB3D3C Infected: Trojan-Downloader.Win32.Tiny.id skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45C25A12 Infected: Trojan-Downloader.Win32.Tiny.id skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45D22C00.exe Infected: Trojan.Win32.Agent.ye skipped
F:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\45D555FC.tmp Infected: Trojan.Win32.Agent.ye skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\Temp\Perflib_Perfdata_4d8.dat Object is locked skipped
H:\Temp\xpigelmh.exe Infected: Trojan.Win32.Agent.bck skipped
H:\Temp\~DF4BBB.tmp Object is locked skipped
H:\Temp\~DF702.tmp Object is locked skipped
H:\Temporary Internet Files\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
H:\Temporary Internet Files\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

Scan process completed.

Alan Crisp
2007-10-16, 23:24
Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:19:03, on 16/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\taskswitch.exe
F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Comodo\Firewall\CPF.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\Comodo\Firewall\cmdagent.exe
F:\Program Files\Kontiki\KService.exe
F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\CyberLink\Shared files\RichVideo.exe
F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.hull.ac.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "F:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\Program Files\Ares\chatServer.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OLE multi config - Unknown owner - C:\WINDOWS\system32\ole2.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - F:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 9092 bytes

shelf life
2007-10-18, 01:48
hi Alan Crisp,

ive seen you already have run vundofix. do this:

Please download ComboFix (by sUBs) from one of the following links:

http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Save it to the Desktop.
Double-click combofix.exe and follow the prompts.

CAUTION: Do not mouse-click ComboFix's window while it is running.
It may cause it to stall.

When finished, it produces a log.

Please provide the contents of the ComboFix log in your reply--

shelf life

Alan Crisp
2007-10-18, 17:05
Many thanks for your reply shelf life.

I had indeed tried Vundofix but it didn't seem to work. I must have forgotten to mention that in my initial post. I've now run ComboFix and attached the log below.

ComboFix 07-10-17.8@ - Alan 2007-10-18 15:52:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.543 [GMT 1:00]
Running from: G:\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\rqstv.bak1
C:\WINDOWS\system32\rqstv.bak1
C:\WINDOWS\system32\rqstv.bak2
C:\WINDOWS\system32\rqstv.bak2
C:\WINDOWS\system32\rqstv.ini
C:\WINDOWS\system32\rqstv.ini
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\vtsqr.dll

.
((((((((((((((((((((((((( Files Created from 2007-09-18 to 2007-10-18 )))))))))))))))))))))))))))))))
.

2007-10-16 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-16 15:50 <DIR> d-------- C:\VundoFix Backups
2007-10-16 15:48 <DIR> d-------- F:\Program Files\Trend Micro
2007-10-15 18:20 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\Lavasoft
2007-10-15 18:04 <DIR> d-------- F:\Program Files\Lavasoft
2007-10-11 17:40 <DIR> d-------- F:\Program Files\JAMMER Professional 5
2007-10-08 00:27 <DIR> d-------- F:\Program Files\DVD Shrink
2007-10-08 00:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-10-07 19:30 <DIR> d-------- F:\Program Files\RealMedia
2007-10-07 19:30 <DIR> d-------- F:\Program Files\OpenSource Flash Video Splitter
2007-10-07 19:30 <DIR> d-------- F:\Program Files\CD Audio Reader Filter
2007-10-07 19:29 <DIR> d-------- F:\Program Files\SHOUTcast Source
2007-10-07 19:28 <DIR> d-------- F:\Program Files\DirectVobSub
2007-10-07 18:44 <DIR> d-------- F:\Program Files\Mozilla Sunbird
2007-10-07 04:00 <DIR> d-------- F:\Program Files\Flare
2007-10-06 15:59 <DIR> d-------- F:\Program Files\iPod
2007-10-06 12:24 <DIR> d-------- F:\Program Files\SymNetDrv
2007-10-06 12:13 <DIR> d-------- F:\Program Files\Symantec
2007-10-06 12:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-05 20:20 <DIR> d-------- F:\Program Files\Max Payne
2007-10-05 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-05 18:59 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\nView_Wallpaper
2007-10-05 18:25 <DIR> d-------- F:\Program Files\FLVPlayer
2007-10-05 18:15 <DIR> d-------- F:\Program Files\Nvidia
2007-10-03 16:18 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\CyberLink
2007-10-03 16:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-03 16:16 <DIR> d-------- F:\Program Files\CyberLink
2007-09-30 13:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-09-22 16:20 <DIR> d-------- F:\Program Files\LimeWire
2007-09-22 16:20 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\LimeWire
2007-09-21 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2007-09-21 16:22 <DIR> d-------- C:\Documents and Settings\Alan\Application Data\Comodo
2007-09-21 16:19 <DIR> d-------- F:\Program Files\Comodo
2007-09-21 11:17 <DIR> d-------- F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2007-09-20 18:59 <DIR> d-------- F:\Program Files\Unreal Tournament 2004
2007-09-20 18:57 <DIR> d-------- F:\Program Files\DAEMON Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-18 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-10-16 13:30 --------- d-----w C:\Documents and Settings\Alan\Application Data\uTorrent
2007-10-15 16:29 --------- d-----w F:\Program Files\Norton SystemWorks
2007-10-14 18:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-13 11:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-10-10 21:36 --------- d-----w C:\Documents and Settings\Alan\Application Data\mIRC
2007-10-10 21:13 --------- d-----w F:\Program Files\mIRC
2007-10-09 12:46 --------- d-----w F:\Program Files\Kontiki
2007-10-06 14:59 --------- d-----w F:\Program Files\iTunes
2007-10-06 11:14 4,608 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-10-05 19:20 --------- d--h--w F:\Program Files\InstallShield Installation Information
2007-10-01 11:03 --------- d-----w C:\Documents and Settings\Alan\Application Data\Symantec
2007-09-25 18:23 --------- d-----w F:\Program Files\DivX
2007-09-22 15:10 --------- d-----w F:\Program Files\Ares
2007-09-21 15:19 --------- d-----w F:\Program Files\PC Tools Firewall Plus
2007-09-21 10:17 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-09-20 17:57 223,128 ----a-w C:\WINDOWS\system32\drivers\dtscsi.sys
2007-09-15 10:56 --------- d-----w F:\Program Files\AVI Joiner
2007-09-12 15:52 --------- d-----w F:\Program Files\Apple Software Update
2007-09-06 17:31 --------- d-----w F:\Program Files\KC Softwares
2007-09-06 12:12 --------- d-----w F:\Program Files\Sibelius Software
2007-09-06 12:12 --------- d-----w F:\Program Files\Native Instruments
2007-09-06 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sibelius Software
2007-09-06 10:39 --------- d-----w C:\Documents and Settings\Alan\Application Data\Apple Computer
2007-09-05 16:42 --------- d-----w F:\Program Files\Safari
2007-09-05 16:31 --------- d-----w F:\Program Files\Bonjour
2007-09-04 20:53 --------- d-----w F:\Program Files\Microsoft Works
2007-09-04 20:30 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6813.sys
2007-09-04 20:30 642,560 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-09-04 20:27 --------- d-----w F:\Program Files\MagicISO
2007-09-04 00:39 --------- d-----w C:\Documents and Settings\Alan\Application Data\Multi-Remote Shutdown Manager
2007-09-04 00:26 --------- d-----w F:\Program Files\MSXML 4.0
2007-09-04 00:13 --------- d-----w F:\Program Files\Google
2007-09-03 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2007-09-02 23:43 --------- d-----w F:\Program Files\Microsoft Games
2007-09-02 12:30 --------- d-----w F:\Program Files\Monte Cristo
2007-08-31 18:00 --------- d-----w C:\Documents and Settings\Alan\Application Data\Sibelius Software
2007-08-29 23:59 --------- d-----w F:\Program Files\FastStone Capture
2007-08-29 11:33 --------- d-----w F:\Program Files\Opera
2007-08-28 11:09 --------- d-----w F:\Program Files\AceIt
2007-08-28 01:22 --------- d-----w F:\Program Files\FreeDiff
2007-08-28 01:20 249,856 ------w C:\WINDOWS\Setup1.exe
2007-08-28 01:19 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-08-27 20:30 --------- d-----w F:\Program Files\trainsimfiles
2007-08-27 18:15 --------- d-----w F:\Program Files\Route_Riter
2007-08-27 15:39 --------- d-----w F:\Program Files\VirtualDJ
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opustext.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opuss___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSROMC.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opuspc__.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opusp___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSM___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSJAPC.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFBE_.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFB__.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opusc___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Opus____.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Inkpen2_.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2text.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2spec.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2scri.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\INK2METR.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\Ink2chor.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELST___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSS___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSM___.FOT
2007-08-27 14:42 1,409 ----a-w C:\WINDOWS\Fonts\HELSINKI.FOT
2007-08-27 01:56 --------- d-----w F:\Program Files\Train Store
2007-08-26 19:54 --------- d-----w F:\Program Files\Java
2007-08-26 19:53 --------- d-----w C:\Program Files\Common Files\Java
2007-08-26 18:40 --------- d-----w C:\Documents and Settings\Alan\Application Data\DivX
2007-08-26 17:00 --------- d-----w F:\Program Files\SmartFTP Client
2007-08-26 17:00 --------- d-----w C:\Documents and Settings\Alan\Application Data\SmartFTP
2007-08-26 16:42 --------- d-----w C:\Documents and Settings\Alan\Application Data\WaterProof
2007-08-26 16:40 --------- d-----w F:\Program Files\WaterProof
2007-08-26 15:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-08-26 15:09 --------- d-----w F:\Program Files\Windows Live
2007-08-26 15:09 --------- d-----w F:\Program Files\MSN Messenger
2007-08-26 15:09 --------- d-----w F:\Program Files\Messenger Plus! Live
2007-08-25 18:21 --------- d-----w F:\Program Files\AC3Filter
2007-08-24 22:41 --------- d-----w F:\Program Files\uTorrent
2007-08-24 22:22 --------- d-----w C:\Program Files\Common Files\Adobe
2007-08-24 22:00 --------- d-----w F:\Program Files\Shape Viewer
2007-08-24 21:35 --------- d-----w F:\Program Files\ConBuilder
2007-08-24 18:44 --------- d-----w C:\Documents and Settings\Alan\Application Data\AdobeUM
2007-08-24 15:35 --------- d-----w F:\Program Files\MWGraphics
2007-08-24 15:26 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-08-24 14:41 --------- d-----w F:\Program Files\Real
2007-08-24 14:41 --------- d-----w C:\Program Files\Common Files\xing shared
2007-08-24 14:41 --------- d-----w C:\Program Files\Common Files\Real
2007-08-24 14:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-08-24 14:15 --------- d-----w F:\Program Files\MSXML 6.0
2007-08-24 14:12 --------- d-----w F:\Program Files\QuickTime
2007-08-24 14:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-08-24 14:11 --------- d-----w C:\Program Files\Common Files\Apple
2007-08-24 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-08-24 13:36 --------- d-----w C:\Documents and Settings\Alan\Application Data\IsolatedStorage
2007-08-24 13:28 --------- d-----w F:\Program Files\MSBuild
2007-08-24 12:37 --------- d-----w C:\Documents and Settings\Alan\Application Data\Thunderbird
2007-08-24 11:55 --------- d-----w F:\Program Files\Mozilla Thunderbird
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-10-18 15:47 340032 --a------ C:\WINDOWS\system32\nojdzlja.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\nojdzlja.dll [2007-10-18 15:47 340032]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 10:56 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"Jet Detection"="F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
"CTStartup"="C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe" [2001-12-20 01:00]
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-24 15:41]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"COMODO Firewall Pro"="F:\Program Files\Comodo\Firewall\CPF.exe" [2007-09-21 16:19]
"RemoteControl"="F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57]
"LanguageShortcut"="F:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 11:29]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
"Symantec NetDriver Monitor"="F:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-10-06 12:24]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

C:\Documents and Settings\Alan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nojdzlja]
nojdzlja.dll 2007-10-18 15:47 340032 C:\WINDOWS\system32\nojdzlja.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqr.dll

R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
S2 OLE multi config;OLE multi config;C:\WINDOWS\system32\ole2.exe
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys
S3 SDdriver;SDdriver;\??\C:\WINDOWS\system32\Drivers\sddriver.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da04b16b-51e4-11dc-a577-806d6172696f}]
AutoRun\command - D:\ctrun\start.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-09-12 13:21:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- F:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-12 19:01:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Alan.job"
"2007-10-15 16:29:15 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
"2007-10-16 23:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-18 15:57:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???h??????s?????\?w? ?w???????w???w4???????.??w4???????4???TA?s4????????&2???A~??A~????????\???\???????????U?A~??A~\???\?????????`??????C@?\???\??????s????\??????s\????&2?A??s?&2??C@?x???`|?w\?????@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-18 16:00:33 - machine was rebooted
.
--- E O F ---

shelf life
2007-10-18, 23:42
hi Alan Crisp,

thanks for the info. vundofix gets updated sometimes. delete your copy and redownload another:

download and run vundofix.exe:

http://www.atribune.org/ccount/click.php?id=4

* Double-click VundoFix.exe to run it.
* Click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

please post the vundo log and anew hjt log.

shelf life

Alan Crisp
2007-10-19, 02:38
Hi again,

I've downloaded a fresh copy of VundoFix and run it again. It looks as though it may have worked. Hopefully you can confirm that.

As requested, VundoFix and Hijack This logs are pasted below.

Thanks.

VundoFix Log:

VundoFix V6.5.10

Checking Java version...

Sun Java not detected
Scan started at 15:50:10 16/10/2007

Listing files found while scanning....

C:\windows\system32\awtuvus.dll
C:\windows\system32\ddcdcyw.dll
C:\windows\system32\dtuvvggl.ini
C:\WINDOWS\system32\fnvphrun.dll
C:\windows\system32\lggvvutd.dll
C:\WINDOWS\system32\nurhpvnf.ini
C:\windows\system32\pmnopqo.dll
C:\windows\system32\rqrrrrp.dll
C:\WINDOWS\system32\ssqommk.dll
C:\WINDOWS\system32\uvtaxlkk.dll
C:\windows\system32\vtuvvuv.dll

Beginning removal...

Attempting to delete C:\windows\system32\awtuvus.dll
C:\windows\system32\awtuvus.dll Has been deleted!

Attempting to delete C:\windows\system32\ddcdcyw.dll
C:\windows\system32\ddcdcyw.dll Has been deleted!

Attempting to delete C:\windows\system32\dtuvvggl.ini
C:\windows\system32\dtuvvggl.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\fnvphrun.dll
C:\WINDOWS\system32\fnvphrun.dll Has been deleted!

Attempting to delete C:\windows\system32\lggvvutd.dll
C:\windows\system32\lggvvutd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nurhpvnf.ini
C:\WINDOWS\system32\nurhpvnf.ini Has been deleted!

Attempting to delete C:\windows\system32\pmnopqo.dll
C:\windows\system32\pmnopqo.dll Has been deleted!

Attempting to delete C:\windows\system32\rqrrrrp.dll
C:\windows\system32\rqrrrrp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqommk.dll
C:\WINDOWS\system32\ssqommk.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\uvtaxlkk.dll
C:\WINDOWS\system32\uvtaxlkk.dll Could not be deleted.

Attempting to delete C:\windows\system32\vtuvvuv.dll
C:\windows\system32\vtuvvuv.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ssqommk.dll
C:\WINDOWS\system32\ssqommk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvtaxlkk.dll
C:\WINDOWS\system32\uvtaxlkk.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.10

Checking Java version...

Sun Java not detected
Scan started at 00:22:30 19/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\nojdzlja.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\nojdzlja.dll
C:\WINDOWS\system32\nojdzlja.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\nojdzlja.dll
C:\WINDOWS\system32\nojdzlja.dll Has been deleted!

Performing Repairs to the registry.
Done!

New Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:32:24, on 19/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\Comodo\Firewall\cmdagent.exe
F:\Program Files\Kontiki\KService.exe
F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\CyberLink\Shared files\RichVideo.exe
F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\taskswitch.exe
F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
F:\Program Files\Comodo\Firewall\CPF.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
F:\PROGRA~1\MOZILL~1\FIREFOX.EXE
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.hull.ac.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "F:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "F:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = F:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - F:\Program Files\Ares\chatServer.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - F:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OLE multi config - Unknown owner - C:\WINDOWS\system32\ole2.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - F:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - F:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 9696 bytes

shelf life
2007-10-19, 03:28
hi Alan Crisp,

ok good. please run vundofix again for a second pass.and post the log. if all looks ok on your end we will make new restore points.

shelf life

Alan Crisp
2007-10-19, 13:58
Hi,

VundoFix didn't find any infected files this time around. The latest log entry is below.

Thanks.

VundoFix V6.5.10

Checking Java version...

Sun Java not detected
Scan started at 12:49:06 19/10/2007

Listing files found while scanning....

No infected files were found.

shelf life
2007-10-20, 02:06
hi Alan Crisp,

so hows it looking on your end now?

shelf life

Alan Crisp
2007-10-20, 12:15
As far as I can tell, the system seems to be clean now. Haven't had any recent problems, although I'll keep an eye on it for the next few days.

Many thanks for the assistance.

shelf life
2007-10-21, 05:49
hi Alan Crisp,

ok good, if it all looks ok we can make new restore points.

shelf life

tashi
2007-10-29, 19:20
Glad we could help, as the problem appears to be resolved this topic has been archived.

If you need it re-opened, please send me a private message (pm) and provide a link to the thread.