PDA

View Full Version : Virtumonde help!!!



fatmama
2008-06-05, 19:14
Hi can somebody help me with virtumonde please:red:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 2:37:03 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/06/2008
Kaspersky Anti-Virus database records: 826461
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 118166
Number of viruses found: 33
Number of infected objects: 70
Number of suspicious objects: 0
Duration of the scan process: 01:53:55

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\sentinel\2.1\gwhashs.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\cert8.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\history.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\key3.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\search.sqlite Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\gido\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\MSHist012008060420080605\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\90PD1818\installer_gr[1].exe Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\gido\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\CLONECDv5.2.9.1\Slysoft.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar RAR: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe NSIS: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\MshConf\scoffset.bin.incr Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0022160.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sca skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023165.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trw skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP101\A0024183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.srh skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP102\A0024329.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP103\A0024522.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.syt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP105\A0024798.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0025939.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tra skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sce skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026146.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026314.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0026483.dll Infected: Trojan.Win32.Monder.jn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0027519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028599.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028612.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028618.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028783.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028784.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP112\A0029206.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP113\A0029276.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP114\A0029445.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP115\change.log Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010746.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010747.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP64\A0011071.dll Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP70\A0015913.exe Infected: Trojan.Win32.Obfuscated.aqn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018079.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021752.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqy skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP98\A0022049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022109.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sbz skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022137.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sby skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S3EED914A.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\arqpwvyp.dll Object is locked skipped
C:\WINDOWS\system32\axutogcf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\deytfypy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\gktgiajq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqz skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\lwoggatw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tro skipped
C:\WINDOWS\system32\sssnuvkw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn skipped
C:\WINDOWS\system32\svdhost.exe Infected: Net-Worm.Win32.Kolab.ws skipped
C:\WINDOWS\system32\tthxekms.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wvokwjas.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

steamwiz
2008-06-06, 21:02
Dupe...

Answered here :-

http://forums.spybot.info/showthread.php?t=29115