PDA

View Full Version : virtumonde trojan removal ?



resq093
2008-05-14, 17:17
not sure what more info you need - here is the kaspersky scan - i appreciate all your help in advance
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 14, 2008 10:08:58 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/05/2008
Kaspersky Anti-Virus database records: 772302
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 101866
Number of viruses found: 28
Number of infected objects: 50
Number of suspicious objects: 0
Duration of the scan process: 01:21:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\aolusers.fus Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\idb\freckledbeauty32\MyDB.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\idb\freckledbeauty32\toolbar.lst Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\idb\SNMaster.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\organize\CACHE\freckledbeauty00 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\organize\freckledbeauty32 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\organize\freckledbeauty32.abi Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.1\organize\freckledbeauty32.aby Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01242008-211252.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Application Data\AOL\C_AOL 9.1\IDB\Apps.Lst Object is locked skipped
C:\Documents and Settings\Owner\Application Data\AOL\C_AOL 9.1\IDB\art.idx Object is locked skipped
C:\Documents and Settings\Owner\Application Data\AOL\C_AOL 9.1\IDB\sap.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\AOL\C_AOL 9.1\IDB\spool.lst Object is locked skipped
C:\Documents and Settings\Owner\Application Data\AOL\C_AOL 9.1\IDB\sysnews.lst Object is locked skipped
C:\Documents and Settings\Owner\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\gdql_lsa_LinksysAgent.log Object is locked skipped
C:\Documents and Settings\Owner\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\glog.log Object is locked skipped
C:\Documents and Settings\Owner\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent.log Object is locked skipped
C:\Documents and Settings\Owner\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent_GTActions.log Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\44\232f2a6c-360ff21e/vmain.class Infected: Exploit.Java.Gimsh.a skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\44\232f2a6c-360ff21e ZIP: infected - 1 skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-51fad18-171b1f31.zip/vmain.class Infected: Exploit.Java.Gimsh.a skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-51fad18-171b1f31.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\My Music\03 Track 3 (screamo).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Owner\My Documents\My Music\DALTONS LYRICS\Dragonforce - Inhuman Rampage.wma Infected: Trojan-Downloader.WMA.GetCodec.a skipped
C:\Documents and Settings\Owner\My Documents\My Music\Slayer - Christ Illusion 2006.wma Infected: Trojan-Downloader.WMA.GetCodec.a skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Steam\logs\connection_log.txt Object is locked skipped
C:\Program Files\Steam\Steam.log Object is locked skipped
C:\Program Files\Steam\SteamApps\winui.gcf Object is locked skipped
C:\syowpheg.exe Infected: Trojan-Downloader.Win32.Small.vfx skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016072.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016073.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016074.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016075.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016076.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016077.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016078.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016079.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016081.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016082.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016083.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016084.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016085.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016086.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016087.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016088.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016089.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016090.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016091.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016092.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016093.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016095.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016096.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016098.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016100.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016101.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016102.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016104.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016105.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP100\A0016106.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP187\A0031006.dll Infected: Trojan-Downloader.Win32.Mutant.vo skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP187\A0031012.exe Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP187\A0031013.dll Infected: Trojan-Downloader.Win32.Zlob.myk skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP187\A0031014.exe Infected: Trojan-Downloader.Win32.Zlob.mym skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031032.dll Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031035.exe Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031036.exe Infected: Trojan-Downloader.Win32.Zlob.mzk skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031038.exe Infected: Trojan-Downloader.Win32.Zlob.mzr skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031039.exe Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031040.exe Infected: Trojan-Downloader.Win32.Zlob.myn skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031041.exe Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031042.dll Infected: Trojan-Downloader.Win32.Zlob.myl skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031101.dll Infected: Trojan-Downloader.Win32.Zlob.myk skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031109.exe Infected: Trojan-Downloader.Win32.Zlob.mym skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP188\A0031111.exe Infected: Trojan-Downloader.Win32.Zlob.mzw skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP189\A0031329.dll Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP189\change.log Object is locked skipped
C:\System Volume Information\_restore{DA02B9FD-DEEB-4833-B590-69E750BFD563}\RP84\A0015306.DLL Infected: not-a-virus:AdWare.Win32.FunWeb.e skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\RTacDbg.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\834668\834668.dll Infected: not-a-virus:AdWare.Win32.E404.ar skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\opnmLdde.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.

pskelley
2008-05-14, 23:29
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

Pinned to the top of the forum and posted above are the instructions. What I need you to do is read them, so you will know what you are doing, then I need you to post a HJT log, follow these instructions:


Download Trend Micro Hijack This™
http://download.bleepingcomputer.com/hijackthis/HJTInstall.exe
Doubleclick the HJTInstall.exe to start it.
By default it will install HijackThis in the Program Files\Trendmicro folder and create a desktop shortcut.
HijackThis will open after install. Press the Scan button below.
This will start the scan and open a log.
Copy and paste the contents of the log in your next reply.

Thanks

pskelley
2008-05-21, 16:36
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.