Wardo
2007-10-25, 17:15
Hello, some time ago my IE6.0 started being redirected to advertisement websites. I remember running SpyBot, Avast and I think Adaware back then. It solved the problem for a while, but then it returned and started getting increasingly worse untill I could no longer use IE at all and had to install FireFox. However, besides from redirecting, apparently a bunch of trash started being downloaded, eventually rendering the PC unusable and forcing me to exclude a bunch of system files with Avast, which in turn forced me to repair my installation of Windows XP. After repairing I booted in safe-mode and ran SpyBot. It found:
Smitfraud-C.
Win32.Agent.bid
Xorpix.a
Virtumonde
I rebooted a few times in safe-mode and ran SpyBot and VundoFix each time. Smitfraud-C. and Virtumonde persisted, Virtu more than Smit, while the other two seem to have disappeared since the first SpyBot scan. I have now booted normally and ran SpyBot twice, finding Virtumonde both times, despite SpyBot attempting to remove it (no sign of Smit). ESET Online Scanner found and removed 45 threats, mostly TryMedia installers (they're adware?) and Trainers among real menacing stuff like:
Win32/Nuwar worm (csrss.exe on a temp folder)
Win32/SpamTool.Agent.NAJtrojan (a temp file on c:\)
Two unknown NewHeur_PE virus (temp files on the Doc and Settings`s temp folder)
Win32/Hoax.Renos application (doc and settings\me\app data\microsoft\IE\Desktop.htt)
a variant of Win32/Nulprot trojan (deskcfg.tmp on c:\windows)
Win32/Nuwar.Gen worm (spooldr.exe on c:\Windows)
Win32/PSW.LdPinch.NEL trojan (msdnc0.exe on c:\windows\system32)
a variant of Win32/TrojanDownloader.Nurech.NBG (msdnc1.exe on windows\system32)
Win32/Nuwar.AO worm (spooldr.sys)
Win32/Agent.QT trojan (winrvc32.dll on windows\system32)
Win32/SpamTool.Agent.NAJ (protect.sys on windows\system32\drivers)
a variant of Win32/Nulprot trojan (hdF.tmp on windows\temp)
Now for the required logs. Kaspersky`s log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, October 25, 2007 3:02:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/10/2007
Kaspersky Anti-Virus database records: 446163
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - Folders:
C:\
Scan Statistics:
Total number of scanned objects: 117348
Number of viruses found: 20
Number of infected objects: 77
Number of suspicious objects: 0
Duration of the scan process: 00:46:31
Infected Object Name / Virus Name / Last Action
C:\Arquivos de programas\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SearchCentrix.zip/spoolsvv.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SearchCentrix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/v6xdt4.game Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/v5xd2.g3ame Infected: Trojan-Downloader.Win32.Agent.coq skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip/vedxga3me2.exe Infected: Trojan-Downloader.Win32.Agent.coq skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/v4xd3.ga2me Infected: Trojan-Downloader.Win32.Small.fox skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip/vedxga4me1.exe Infected: Trojan-Proxy.Win32.Xorpix.bo skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip/v3xd1.g22me Infected: Trojan-Proxy.Win32.Xorpix.bo skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/v5xd4.ga2me Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip/dllh8jkd1q7.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip/dllh8jkd1q6.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip/dllh8jkd1q5.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip/dllh8jkd1q2.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/v4xd6.gam5e Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip/dllh8jkd1q1.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip/kernelwind32.exe Infected: Email-Worm.Win32.Zhelatin.in skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip/vedxg6ame4.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip/desktop.html Infected: not-virus:Hoax.Win32.Renos.cy skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/7.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/6.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/5.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/1.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/ma1x1dd1v.game Infected: not-a-virus:Porn-Dialer.Win32.GBDialer.i skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip/vedxg4am1et2.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/vedxga4m1et4.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff.zip/vx3dt2.game Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff1.zip/vx1dt3.game Infected: Email-Worm.Win32.Zhelatin.id skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff2.zip/vx1dt1.game Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/home.exe.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid3.zip/DefLib.sys Infected: Trojan.Win32.Agent.asu skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid6.zip/winlogon.exe Infected: Trojan-Proxy.Win32.Small.fz skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu27.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinSmallls.zip/svshost.dll Infected: Backdoor.Win32.Small.ta skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinSmallls.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa.zip/bot.dll~ Infected: Trojan-Proxy.Win32.Xorpix.bk skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa2.zip/bot.dll Infected: Trojan-Proxy.Win32.Xorpix.bk skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Histórico\History.IE5\MSHist012007102520071026\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temp\1806.tmp Infected: Trojan.Win32.Inject.er skipped
C:\Documents and Settings\Arede\Configurações locais\Temp\2.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\EFYHI12L\microsoft_forefront_piratas_468x300[1].swf Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\YDWJ234N\xc60[1].exe Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\Arede\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Arede\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Arede\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\fwdrv.sys Infected: SpamTool.Win32.Agent.bd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1640B4F5-E673-48CC-B15F-51E9D834993E}\RP0\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\87354753411123211122534452667798.data Object is locked skipped
C:\WINDOWS\system32\87354753411123211122534452667798.log Object is locked skipped
C:\WINDOWS\system32\Bcxnstb.dll Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\ccccbeaffddfca.dll Object is locked skipped
C:\WINDOWS\system32\config\47781774.Evt Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dfcabcdf.dll Object is locked skipped
C:\WINDOWS\system32\dfcdbaffbcadba.dll Object is locked skipped
C:\WINDOWS\system32\gln.dll Infected: Trojan.Win32.BHO.dm skipped
C:\WINDOWS\system32\gln.exe Infected: Trojan-Downloader.Win32.Delf.byk skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat Object is locked skipped
C:\WINDOWS\Temp\win1026.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\Temp\win119F.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\Temp\win1820.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000003-00000000-00000003-00001102-00000004-00511102}.CDF Object is locked skipped
Scan process completed.
HijackThis (exe renamed to helpme.exe) log on the following post.
Smitfraud-C.
Win32.Agent.bid
Xorpix.a
Virtumonde
I rebooted a few times in safe-mode and ran SpyBot and VundoFix each time. Smitfraud-C. and Virtumonde persisted, Virtu more than Smit, while the other two seem to have disappeared since the first SpyBot scan. I have now booted normally and ran SpyBot twice, finding Virtumonde both times, despite SpyBot attempting to remove it (no sign of Smit). ESET Online Scanner found and removed 45 threats, mostly TryMedia installers (they're adware?) and Trainers among real menacing stuff like:
Win32/Nuwar worm (csrss.exe on a temp folder)
Win32/SpamTool.Agent.NAJtrojan (a temp file on c:\)
Two unknown NewHeur_PE virus (temp files on the Doc and Settings`s temp folder)
Win32/Hoax.Renos application (doc and settings\me\app data\microsoft\IE\Desktop.htt)
a variant of Win32/Nulprot trojan (deskcfg.tmp on c:\windows)
Win32/Nuwar.Gen worm (spooldr.exe on c:\Windows)
Win32/PSW.LdPinch.NEL trojan (msdnc0.exe on c:\windows\system32)
a variant of Win32/TrojanDownloader.Nurech.NBG (msdnc1.exe on windows\system32)
Win32/Nuwar.AO worm (spooldr.sys)
Win32/Agent.QT trojan (winrvc32.dll on windows\system32)
Win32/SpamTool.Agent.NAJ (protect.sys on windows\system32\drivers)
a variant of Win32/Nulprot trojan (hdF.tmp on windows\temp)
Now for the required logs. Kaspersky`s log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, October 25, 2007 3:02:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/10/2007
Kaspersky Anti-Virus database records: 446163
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - Folders:
C:\
Scan Statistics:
Total number of scanned objects: 117348
Number of viruses found: 20
Number of infected objects: 77
Number of suspicious objects: 0
Duration of the scan process: 00:46:31
Infected Object Name / Virus Name / Last Action
C:\Arquivos de programas\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SearchCentrix.zip/spoolsvv.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SearchCentrix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/v6xdt4.game Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/v5xd2.g3ame Infected: Trojan-Downloader.Win32.Agent.coq skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip/vedxga3me2.exe Infected: Trojan-Downloader.Win32.Agent.coq skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/v4xd3.ga2me Infected: Trojan-Downloader.Win32.Small.fox skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip/vedxga4me1.exe Infected: Trojan-Proxy.Win32.Xorpix.bo skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip/v3xd1.g22me Infected: Trojan-Proxy.Win32.Xorpix.bo skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/v5xd4.ga2me Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip/dllh8jkd1q7.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip/dllh8jkd1q6.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip/dllh8jkd1q5.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip/dllh8jkd1q2.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/v4xd6.gam5e Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip/dllh8jkd1q1.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip/kernelwind32.exe Infected: Email-Worm.Win32.Zhelatin.in skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip/vedxg6ame4.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip/desktop.html Infected: not-virus:Hoax.Win32.Renos.cy skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/7.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/6.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/5.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/1.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/ma1x1dd1v.game Infected: not-a-virus:Porn-Dialer.Win32.GBDialer.i skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip/vedxg4am1et2.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/vedxga4m1et4.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff.zip/vx3dt2.game Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff1.zip/vx1dt3.game Infected: Email-Worm.Win32.Zhelatin.id skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff2.zip/vx1dt1.game Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\SpySheriff2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/home.exe.exe Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid3.zip/DefLib.sys Infected: Trojan.Win32.Agent.asu skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid6.zip/winlogon.exe Infected: Trojan-Proxy.Win32.Small.fz skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentbid6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu27.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinSmallls.zip/svshost.dll Infected: Backdoor.Win32.Small.ta skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\WinSmallls.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa.zip/bot.dll~ Infected: Trojan-Proxy.Win32.Xorpix.bk skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa2.zip/bot.dll Infected: Trojan-Proxy.Win32.Xorpix.bk skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Xorpixa2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Histórico\History.IE5\MSHist012007102520071026\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temp\1806.tmp Infected: Trojan.Win32.Inject.er skipped
C:\Documents and Settings\Arede\Configurações locais\Temp\2.dllb Infected: Packed.Win32.Tibs.bs skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\EFYHI12L\microsoft_forefront_piratas_468x300[1].swf Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Arede\Configurações locais\Temporary Internet Files\Content.IE5\YDWJ234N\xc60[1].exe Infected: Trojan.Win32.Dialer.qn skipped
C:\Documents and Settings\Arede\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Arede\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Arede\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\fwdrv.sys Infected: SpamTool.Win32.Agent.bd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1640B4F5-E673-48CC-B15F-51E9D834993E}\RP0\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\87354753411123211122534452667798.data Object is locked skipped
C:\WINDOWS\system32\87354753411123211122534452667798.log Object is locked skipped
C:\WINDOWS\system32\Bcxnstb.dll Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\ccccbeaffddfca.dll Object is locked skipped
C:\WINDOWS\system32\config\47781774.Evt Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dfcabcdf.dll Object is locked skipped
C:\WINDOWS\system32\dfcdbaffbcadba.dll Object is locked skipped
C:\WINDOWS\system32\gln.dll Infected: Trojan.Win32.BHO.dm skipped
C:\WINDOWS\system32\gln.exe Infected: Trojan-Downloader.Win32.Delf.byk skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat Object is locked skipped
C:\WINDOWS\Temp\win1026.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\Temp\win119F.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\Temp\win1820.tmp.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000003-00000000-00000003-00001102-00000004-00511102}.CDF Object is locked skipped
Scan process completed.
HijackThis (exe renamed to helpme.exe) log on the following post.