Cobalt Blue
New member
Hi, Support,
Need your help Please. I have a personal machine that was hit with virtumonde. Spybot could not completely remove it and it now has also been hit with Smitfraud-C.
I initially posted for help and Windows IE was erroring out so I could not run Kaspersky Online Scanner to completion. System is running VERY slowly at best. I was able to load the non-IE version completed a session with a lot of bad things removed, see below report. The HJT log is in the next post as it is to large for one posting.
Any help would be greatly appreciated. I know my system was very much out of date and probably opened up for this attack. BR, ...Cobalt Blue
KAV report 1.txt 11/24/07 for Cobalt Blue
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\00211555.exe.bac_a09840//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\00211556.exe.bac_a09840//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\isamini.exe.bac_a09252//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\isamntr.exe.bac_a09252//CryptFF.b
deleted: Trojan program Trojan.Win32.Agent.qt File: C:\Documents and Settings\Administrator\Local Settings\Temp\mst10.tmp//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Dropper.Win32.Agent.chq File: C:\Documents and Settings\Administrator\Local Settings\Temp\silverstar.exe
deleted: Trojan program Trojan-Downloader.Java.Agent.f File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07LFMAJX\jvmsecman[1].jar/vlocal.class
deleted: Trojan program Trojan-Downloader.Win32.Agent.emo File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07LFMAJX\tsitra[1].exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CHER8LQV\mrofinu[1].zip/mrofinu.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.Tiny.zh File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\good[1].php//Packman//#//PE_Patch.UPX//UPX
deleted: Trojan program Trojan.Win32.Dialer.qn File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\image1[1].gif//PE_Patch.PECompact//PecBundle//PECompact
deleted: malware not-virus:Hoax.Win32.Renos.hx File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\image20[1].gif
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\startseitelsls[1].gif//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GH6JO9QR\17PHolmes[1].cmt//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Zlob.ejm File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\HL1JYEZE\image27[1].gif//UPX
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\hlpsrv[1].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\hlpsrv[2].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\image30[1].gif//PE_Patch.PECompact//PecBundle//PECompact
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\CPU-10~2.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\MORROW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\OPTIONS.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\RESTOCK.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\LITTONDS\BD963062.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\MOTOROLA\20VT_ENV.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\MOTOROLA\SBUSPID.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\SCI\BD963060.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Human Resources\96TRAIN.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\MEETINGS\AREA0796.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\BDOLAN\NUTD.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\DAVE\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Henry Chun\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\JoAnne Rosandich\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Kirk Davis\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Tom Yenny\EMPPREP.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\TOM.G\96REVIEW.DOC
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Program Files\269850484.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: adware not-a-virus:AdWare.Win32.TTC.a File: C:\Program Files\TTC.dll
deleted: Trojan program Trojan-Downloader.Win32.Zlob.ejm File: C:\Program Files\fafaxolq\vqfsbyby.dll
deleted: malware HackTool.Win32.Clearlog.c File: C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\728E025A.exe//CryptFF
deleted: adware not-a-virus:AdWare.Win32.PurityScan.fk File: C:\Program Files\Outerinfo\OiUninstaller.exe//data0002//PE_Patch.UPX//UPX
deleted: adware not-a-virus:AdWare.Win32.ZenoSearch.ad File: C:\Program Files\Outerinfo\FF\components\FF.dll
deleted: Trojan program Trojan-Downloader.Win32.Small.gkh File: C:\RECYCLER\NPROTECT\00398320.DLL
deleted: Trojan program Trojan-Downloader.Win32.Small.buy File: C:\RECYCLER\NPROTECT\00399549.EXE//UPX
deleted: Trojan program Trojan.Win32.Pakes.akr File: C:\RECYCLER\NPROTECT\00399735.dll
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\WINNT\17PHolmes572.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\WINNT\mrofinu.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\apcjqxhf.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\cbxxuuv.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\ddcdcca.dll
deleted: adware not-a-virus:AdWare.Win32.PurityScan.gl File: C:\WINNT\system32\doo.dll//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Tiny.id File: C:\WINNT\system32\iikgwfax.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.gkh File: C:\WINNT\system32\ldcore.dll_tobedeleted_old
deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINNT\system32\nwjrxfxm.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\sdjwgsed.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\spvobywk.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\sxpndykx.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.app File: C:\WINNT\system32\tuvutsq.dll
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\tvcvqdop.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\urqqrpn.dll
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\yjyfnocr.exe
deleted: adware not-a-virus:AdWare.Win32.TTC.a File: C:\WINNT\system32\e2\caws83122.exe//data0002
deleted: Trojan program Trojan-Downloader.Win32.Small.gks File: C:\WINNT\system32\x22\c124wvr.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\WINNT\Temp\win7C.tmp.exe//PE_Patch.PECompact//PecBundle//PECompact
Logfile of Trend Micro HijackThis v2.0.2 to follow with next post(to long for one post)
Need your help Please. I have a personal machine that was hit with virtumonde. Spybot could not completely remove it and it now has also been hit with Smitfraud-C.
I initially posted for help and Windows IE was erroring out so I could not run Kaspersky Online Scanner to completion. System is running VERY slowly at best. I was able to load the non-IE version completed a session with a lot of bad things removed, see below report. The HJT log is in the next post as it is to large for one posting.
Any help would be greatly appreciated. I know my system was very much out of date and probably opened up for this attack. BR, ...Cobalt Blue

KAV report 1.txt 11/24/07 for Cobalt Blue
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\00211555.exe.bac_a09840//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\00211556.exe.bac_a09840//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\isamini.exe.bac_a09252//CryptFF.b
deleted: Trojan program Trojan-Downloader.Win32.Zlob.bpn File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\isamntr.exe.bac_a09252//CryptFF.b
deleted: Trojan program Trojan.Win32.Agent.qt File: C:\Documents and Settings\Administrator\Local Settings\Temp\mst10.tmp//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Dropper.Win32.Agent.chq File: C:\Documents and Settings\Administrator\Local Settings\Temp\silverstar.exe
deleted: Trojan program Trojan-Downloader.Java.Agent.f File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07LFMAJX\jvmsecman[1].jar/vlocal.class
deleted: Trojan program Trojan-Downloader.Win32.Agent.emo File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07LFMAJX\tsitra[1].exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CHER8LQV\mrofinu[1].zip/mrofinu.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.Tiny.zh File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\good[1].php//Packman//#//PE_Patch.UPX//UPX
deleted: Trojan program Trojan.Win32.Dialer.qn File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\image1[1].gif//PE_Patch.PECompact//PecBundle//PECompact
deleted: malware not-virus:Hoax.Win32.Renos.hx File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\image20[1].gif
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DNPFXUJ5\startseitelsls[1].gif//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GH6JO9QR\17PHolmes[1].cmt//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Zlob.ejm File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\HL1JYEZE\image27[1].gif//UPX
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\hlpsrv[1].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\hlpsrv[2].exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LMW6B1P4\image30[1].gif//PE_Patch.PECompact//PecBundle//PECompact
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\CPU-10~2.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\MORROW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\OPTIONS.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\AIRNET\RESTOCK.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\LITTONDS\BD963062.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\MOTOROLA\20VT_ENV.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\MOTOROLA\SBUSPID.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Customers\SCI\BD963060.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\Human Resources\96TRAIN.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\MEETINGS\AREA0796.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\BDOLAN\NUTD.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\DAVE\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Henry Chun\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\JoAnne Rosandich\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Kirk Davis\96REVIEW.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\Tom Yenny\EMPPREP.DOC
disinfected: virus Virus.MSWord.Concept File: C:\Force Backups\My Documents 12 18 04\My Documents\STAFF\TOM.G\96REVIEW.DOC
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\Program Files\269850484.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: adware not-a-virus:AdWare.Win32.TTC.a File: C:\Program Files\TTC.dll
deleted: Trojan program Trojan-Downloader.Win32.Zlob.ejm File: C:\Program Files\fafaxolq\vqfsbyby.dll
deleted: malware HackTool.Win32.Clearlog.c File: C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\728E025A.exe//CryptFF
deleted: adware not-a-virus:AdWare.Win32.PurityScan.fk File: C:\Program Files\Outerinfo\OiUninstaller.exe//data0002//PE_Patch.UPX//UPX
deleted: adware not-a-virus:AdWare.Win32.ZenoSearch.ad File: C:\Program Files\Outerinfo\FF\components\FF.dll
deleted: Trojan program Trojan-Downloader.Win32.Small.gkh File: C:\RECYCLER\NPROTECT\00398320.DLL
deleted: Trojan program Trojan-Downloader.Win32.Small.buy File: C:\RECYCLER\NPROTECT\00399549.EXE//UPX
deleted: Trojan program Trojan.Win32.Pakes.akr File: C:\RECYCLER\NPROTECT\00399735.dll
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\WINNT\17PHolmes572.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.fhv File: C:\WINNT\mrofinu.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\apcjqxhf.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\cbxxuuv.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\ddcdcca.dll
deleted: adware not-a-virus:AdWare.Win32.PurityScan.gl File: C:\WINNT\system32\doo.dll//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Tiny.id File: C:\WINNT\system32\iikgwfax.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.gkh File: C:\WINNT\system32\ldcore.dll_tobedeleted_old
deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINNT\system32\nwjrxfxm.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\sdjwgsed.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\spvobywk.exe
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\sxpndykx.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.app File: C:\WINNT\system32\tuvutsq.dll
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\tvcvqdop.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.art File: C:\WINNT\system32\urqqrpn.dll
deleted: Trojan program Trojan.Win32.Agent.bck File: C:\WINNT\system32\yjyfnocr.exe
deleted: adware not-a-virus:AdWare.Win32.TTC.a File: C:\WINNT\system32\e2\caws83122.exe//data0002
deleted: Trojan program Trojan-Downloader.Win32.Small.gks File: C:\WINNT\system32\x22\c124wvr.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Alphabet.gen File: C:\WINNT\Temp\win7C.tmp.exe//PE_Patch.PECompact//PecBundle//PECompact
Logfile of Trend Micro HijackThis v2.0.2 to follow with next post(to long for one post)