virtualinsanity
2008-06-10, 16:59
I have tried running the VUndo tool but it doesn't find virtumonde - anyone help please?
My Spybot log:
Microsoft.Windows.RedirectedHosts: [SBI $15426327] Redirected host (Redirected host, nothing done)
virusscan.jotti.org=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $C13076CA] Redirected host (Redirected host, nothing done)
www.auditmypc.com=127.0.0.1
Microsoft.WindowsSecurityCenter.AntiVirusOverride: [SBI $3604910C] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride
Microsoft.Windows.RedirectedHosts: [SBI $7A27F828] Redirected host (Redirected host, nothing done)
security.symantec.com=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $2EF425BA] Redirected host (Redirected host, nothing done)
support.f-secure.com=127.0.0.1
Virtumonde: [SBI $42352499] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3264219588-1781700132-1342712184-500\Software\Microsoft\rdfa
Virtumonde: [SBI $47E741CD] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde.dll: [SBI $7442D4BC] Library (File, nothing done)
C:\WINDOWS\system32\jkkJcAsp.dll
Virtumonde.dll: [SBI $7442D4BC] Library (File, nothing done)
C:\WINDOWS\system32\urqQhgFv.dll
Virtumonde.dll: [SBI $960C7A04] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60965FD8-1FDE-4BD6-990A-62535B57B9A5}
Virtumonde.dll: [SBI $960C7A04] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60965FD8-1FDE-4BD6-990A-62535B57B9A5}
DoubleClick: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Zedo: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
BlueStreak: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
MediaPlex: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Right Media: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Adviva: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitsLink: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
WebTrends live: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
Adviva: Tracking cookie (Firefox: default) (Cookie, nothing done)
Adviva: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-06-10 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-06-03 Includes\Adware.sbi (*)
2008-06-03 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-06-03 Includes\DialerC.sbi (*)
2008-06-03 Includes\HeavyDuty.sbi (*)
2008-06-04 Includes\Hijackers.sbi (*)
2008-06-03 Includes\HijackersC.sbi (*)
2008-06-03 Includes\Keyloggers.sbi (*)
2008-06-03 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-06-03 Includes\Malware.sbi (*)
2008-06-03 Includes\MalwareC.sbi (*)
2008-06-03 Includes\PUPS.sbi (*)
2008-06-03 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-03 Includes\Security.sbi (*)
2008-06-03 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-06-03 Includes\Spyware.sbi (*)
2008-06-03 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-06-03 Includes\Trojans.sbi (*)
2008-06-03 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
My Spybot log:
Microsoft.Windows.RedirectedHosts: [SBI $15426327] Redirected host (Redirected host, nothing done)
virusscan.jotti.org=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $C13076CA] Redirected host (Redirected host, nothing done)
www.auditmypc.com=127.0.0.1
Microsoft.WindowsSecurityCenter.AntiVirusOverride: [SBI $3604910C] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride
Microsoft.Windows.RedirectedHosts: [SBI $7A27F828] Redirected host (Redirected host, nothing done)
security.symantec.com=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $2EF425BA] Redirected host (Redirected host, nothing done)
support.f-secure.com=127.0.0.1
Virtumonde: [SBI $42352499] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3264219588-1781700132-1342712184-500\Software\Microsoft\rdfa
Virtumonde: [SBI $47E741CD] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde.dll: [SBI $7442D4BC] Library (File, nothing done)
C:\WINDOWS\system32\jkkJcAsp.dll
Virtumonde.dll: [SBI $7442D4BC] Library (File, nothing done)
C:\WINDOWS\system32\urqQhgFv.dll
Virtumonde.dll: [SBI $960C7A04] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60965FD8-1FDE-4BD6-990A-62535B57B9A5}
Virtumonde.dll: [SBI $960C7A04] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60965FD8-1FDE-4BD6-990A-62535B57B9A5}
DoubleClick: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Zedo: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
BlueStreak: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
MediaPlex: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Right Media: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Adviva: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Internet Explorer: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
AdRevolver: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitBox: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
HitsLink: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
WebTrends live: Tracking cookie (Opera 7+: GB033796) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
Right Media: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
Adviva: Tracking cookie (Firefox: default) (Cookie, nothing done)
Adviva: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, nothing done)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-06-10 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-06-03 Includes\Adware.sbi (*)
2008-06-03 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-06-03 Includes\DialerC.sbi (*)
2008-06-03 Includes\HeavyDuty.sbi (*)
2008-06-04 Includes\Hijackers.sbi (*)
2008-06-03 Includes\HijackersC.sbi (*)
2008-06-03 Includes\Keyloggers.sbi (*)
2008-06-03 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-06-03 Includes\Malware.sbi (*)
2008-06-03 Includes\MalwareC.sbi (*)
2008-06-03 Includes\PUPS.sbi (*)
2008-06-03 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-03 Includes\Security.sbi (*)
2008-06-03 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-06-03 Includes\Spyware.sbi (*)
2008-06-03 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-06-03 Includes\Trojans.sbi (*)
2008-06-03 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll