PDA

View Full Version : virtumonde.generic and ATLEvents.ATLEvents



recklessdriver
2009-06-03, 04:31
Hi,

My aunt gave me her super old work laptop and I've been able to use Spybot to get all other malware off of it except for virtumonde.generic and ATLEvents which keep popping up on the scans. I've been refraining from going online with the laptop to prevent virtumonde from doing whatever it does with an internet connection. Therefore, I'm posting these logs with my desktop PC and transferring the logs, diagnostic software, updates, etc. with a USB stick. Please see the below HJT log. Thanks.
========================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:12, on 2009-06-02
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\Help\scat.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\System32\UMonit2K.exe
C:\Program Files\Trend Micro\HijackThis\alternatename.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: CATLEvents Object - {BB54DE33-E539-4749-BFAC-CC49617E8F2A} - C:\DOCUME~1\jfuchino\LOCALS~1\Temp\tacs.dat
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [UMonit2K.exe] "C:\WINNT\System32\UMonit2K.exe"
O4 - HKLM\..\Run: [*oleras] C:\WINNT\Speech\oleras.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\RunOnce: [*scat] C:\WINNT\Help\scat.exe rerun
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O20 - Winlogon Notify: scat - C:\DOCUME~1\jfuchino\LOCALS~1\Temp\tacs.dat
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

--
End of file - 2973 bytes

Blade81
2009-06-04, 16:39
Hi,

Let's make sure USB is properly disinfected before using it.


1. Download Flash_Disinfector (http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe) and save it to your Desktop of your clean system.
2. After downloading, double-click on Flash_Disinfector to run it.
3. Just follow the prompts and continue until it begin scanning.
4. If asked to insert your flash drive or any removable device including USB Pen Drive and Memory Stick, please do so.
5. It will scan removable drives, wait for the scan to finish. Done.


Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.

recklessdriver
2009-06-05, 07:36
Hi Blade81,

I've already got a problem with your instructions. Seems your link to Flash_Disinfector (http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe) is broken. When I try to download from http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe, I get the following message from McAfee:

McAfee has automatically blocked and removed a Trojan.


About this Trojan
Detected: Generic.dx (Trojan), Generic.dx (Trojan)
Location: C:\Documents and Settings\Vincent\Local Settings\Temporary Internet Files\Content.IE5\4A7U9NQW\Flash_Disinfector[1].exe

Trojans appear as legitimate programs but can damage valuable files, disrupt performance, and allow unauthorized access to your computer.

What should I do?:confused:

recklessdriver
2009-06-05, 07:49
Hmmm, just did some searching on bleepingcomputer.com and it seems as though some antispyware such as McAfee will return a false positive on Flash_Disinfector because of some of the code in the program. I believe that I should just disable McAfee (which does not even give me the option to continue downloading Flash_Disinfector) and download the file.

HOWEVER, I will wait until you give me the green light to go ahead and do that because I don't want to screw anything up.:D:

Blade81
2009-06-05, 18:08
Yes, Flash Disinfector is falsely detected as positive by some protection software. You may let it run McAfee disabled :)

recklessdriver
2009-06-06, 04:16
Hi Blade81,

Here's the two logs generated by dds.scr:

Blade81
2009-06-06, 13:13
Hi

Original log shows Win2000 but DDS log shows WinXP. Could you tell me what's going on there, please?

recklessdriver
2009-06-06, 19:31
Hi Blade81,

I'm terribly sorry about that slip. I ran the dds.scr on my desktop instead of the laptop (I was distracted).:red: The CORRECT logs are now posted, sorry.:red:

Blade81
2009-06-06, 20:24
That's ok. I was just little confused to see logs from different OS :laugh:


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

recklessdriver
2009-06-06, 23:10
Well, the first time I ran Combofix, it rebooted the laptop and didn't produce a log. So I ran it a second time, it rebooted, and generated a log. And that is what I have attached. Thanks Blade81.

Blade81
2009-06-07, 11:05
Hi again,



Open notepad and copy/paste the text in the quotebox below into it:



http://forums.spybot.info/showthread.php?p=316372#post316372

Collect::
c:\program files\pup.exe
c:\winnt\system32\spool\prtprocs\dochard.exe
c:\winnt\inf\msvcabr.exe
c:\winnt\Help\scat.exe
c:\winnt\Fonts\dbsrv.exe
c:\winnt\Windows Update Setup Files\infocmd.exe
c:\winnt\Windows Update Setup Files\dmcofni.bak1
c:\winnt\Windows Update Setup Files\dmcofni.bak2
c:\winnt\Windows Update Setup Files\ksatvrs.bak2
c:\winnt\Speech\oleras.exe
c:\winnt\assembly\tmp\cmtnof.tmp

Driver::
vkquwexg

File::
c:\program files\InternetDialer.exe.ex_

DDS::
mSearch Bar = about:blank
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
uSearchURL,(Default) = about:blank
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB54DE33-E539-4749-BFAC-CC49617E8F2A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"*oleras"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"*scat"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\scat]



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. You'll be asked to submit some samples. Please follow instructions given to carry out submitting successfully.
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Download the latest version of Kaspersky Virus Removal Tool (ftp://downloads2.kaspersky-labs.com/devbuilds/AVPTool)

* Close all other applications and double-click and run the installer.
* When AVPTool starts, select all the scanable items except for CD-ROM drives and click the Scan button.
* If malware is detected, don't remove anything.
* After the scan finishes, don't neutralize anything.
* In the Scan window click the Reports button and select Save to file.
* Name the report AVPT.txt, and save it to the Desktop.
* Close AVPTool.
* You will be prompted if you want to uninstall the program; click Yes.
* You will then be prompted that to complete the uninstallation, the computer must be restarted. Select Yes to restart the system.
* Copy and paste the first part of the report (Detected) that you saved in your next reply. Do not include the longer list marked Events. Post also a fresh dds.txt log.

recklessdriver
2009-06-09, 08:00
Hi Blade81,

Thanks for having a look
=========================================
Kapersky Detected Log (Sorry, this is a long one!! :sad:)
=========================================

Scan
----
Scanned: 193665
Detected: 108
Untreated: 108
Start time: 2009-06-08 20:29
Duration: 01:55:59
Finish time: 2009-06-08 22:25


Detected
--------
Status Object
------ ------
detected: Trojan program Trojan-Downloader.Win32.Small.ks File: c:\program files\windows media player\wmplayer.exe
detected: adware not-a-virus:AdWare.Win32.ImiBar.b File: C:\WINNT\systb.exe/systb.dll
detected: Trojan program Trojan-Downloader.Win32.Agent.ae File: C:\WINNT\polmx3.exe//UPX
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\taskmp3.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\apacc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\rasms.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\tcpdns.exe
detected: Trojan program Trojan-Clicker.Win32.Agent.bc File: C:\WINNT\system32\scvi50.exe
detected: Trojan program Trojan-Spy.Win32.VBStat.b File: C:\WINNT\system32\ctts.exe
detected: adware not-a-virus:AdWare.Win32.F1Organizer.h File: C:\WINNT\system32\siae3123.exe//UPX
detected: Trojan program Trojan-Downloader.Win32.Revop File: C:\WINNT\system32\notepad.exe.tmp
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\config\abrjava.exe
detected: Trojan program Trojan.Win32.Qhost.f File: C:\WINNT\system32\drivers\etc\hosts.20090324-205938.backup
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\system32\spool\prtprocs\svccat.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\ShellExt\mainimg.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\URTTemp\abrmain.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\NtmsData\wmc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\system32\Microsoft\wavejpeg.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\Adobe\fontap.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system32\Adobe\bakacc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\system\playlib.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system\kbxml.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\system\keyas.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\repair\mfcdrv.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\repair\taskfont.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\repair\dlliis.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\repair\mainac.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\repair\libiis.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\repair\wavehard.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\repair\acmain.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\Help\pcdrv.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Help\inetlib.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Fonts\keyac.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Fonts\ascmd.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Config\dvdabr.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Config\maincom.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\msagent\intl\mcwave.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\msagent\intl\maindll.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\msagent\intl\dbdll.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\msagent\intl\msvcsys.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Cursors\regdvd.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Cursors\mp3font.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\java\faxcom.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\java\classes\taskap.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\java\trustlib\binvss.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\java\trustlib\apun.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Web\bakdvd.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Web\logexp.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\WINNT\Web\printers\iptcp.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Web\printers\mssvc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Web\printers\javamfc.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\WINNT\addins\adcat.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\addins\runbas.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\addins\javaad.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\addins\com.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\addins\fontfax.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\addins\csrv.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Driver Cache\iis.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\Driver Cache\compc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\security\templates\srvweb.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\security\templates\tcpdrv.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\security\templates\srvvga.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Windows Update Setup Files\pslog.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Windows Update Setup Files\svccat.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Windows Update Setup Files\wmsad.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Speech\hardbak.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Speech\msftp.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Speech\kbodbc.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.a File: C:\WINNT\Registration\dvdc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\Registration\vsswave.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\WINNT\Registration\dllcab.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Registration\webvss.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Registration\iissvc.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\WINNT\Drivers\mcabr.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\WINNT\Drivers\acbak.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Drivers\binbak.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Drivers\basanti.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Drivers\commfc.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\ServicePackFiles\web.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\ServicePackFiles\nettapi.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\ServicePackFiles\cmdole.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Microsoft.NET\crjava.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Microsoft.NET\srvwin.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\Microsoft.NET\cmdnet.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\assembly\wkb.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\WINNT\assembly\GAC\Microsoft.VisualBasic.Vsa\docvb.exe
detected: Trojan program Trojan.Win32.Revop.a File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_pup.exe.vir//WISE0006.BIN
detected: adware not-a-virus:AdWare.Win32.Virtumonde.f File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_dbsrv.exe.vir
detected: adware not-a-virus:AdWare.Win32.Virtumonde.m File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_scat.exe.vir
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_msvcabr.exe.vir
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_oleras.exe.vir
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_dochard.exe.vir
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\[4]-Submit_2009-06-08_20.11.01.zip/Collect_infocmd.exe.vir
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\C\WINNT\system32\spool\prtprocs\_dochard_.exe.zip/dochard.exe
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\Qoobox\Quarantine\C\WINNT\Tasks\cabbak.exe.vir
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.f File: C:\Qoobox\Quarantine\C\WINNT\Tasks\dvdcom.exe.vir
detected: Trojan program Trojan-Downloader.Win32.Virtumonde.a File: C:\Qoobox\Quarantine\C\WINNT\Tasks\vsscom.exe.vir
detected: adware not-a-virus:AdWare.Win32.Virtumonde.f File: C:\Qoobox\Quarantine\C\WINNT\Fonts\_dbsrv_.exe.zip/dbsrv.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.m File: C:\Qoobox\Quarantine\C\WINNT\Help\_scat_.exe.zip/scat.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\C\WINNT\inf\_msvcabr_.exe.zip/msvcabr.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\C\WINNT\Speech\_oleras_.exe.zip/oleras.exe
detected: Trojan program Trojan-Spy.Win32.Agent.l File: C:\Qoobox\Quarantine\C\WINNT\Windows Update Setup Files\_infocmd_.exe.zip/infocmd.exe
detected: Trojan program Trojan-Spy.Win32.Agent.j File: C:\Qoobox\Quarantine\C\Documents and Settings\jfuchino\Application Data\sysupd.exe.vir//UPX
detected: adware not-a-virus:AdWare.Win32.Virtumonde.m File: C:\Qoobox\Quarantine\C\Documents and Settings\jfuchino\LOCALS~1\Temp\_tacs_.dat.zip/tacs.dat
detected: adware not-a-virus:AdWare.Win32.Virtumonde.m File: C:\Qoobox\Quarantine\C\Documents and Settings\jfuchino\LOCALS~1\Temp\_tacs_.dat.zip/tacs.dat.2
detected: adware not-a-virus:AdWare.Win32.Virtumonde.m File: C:\Qoobox\Quarantine\C\Documents and Settings\jfuchino\LOCALS~1\Temp\_tacs_.dat.zip/tacs.dat.4
detected: Trojan program Trojan.Win32.Revop.a File: C:\Qoobox\Quarantine\C\Program Files\_pup_.exe.zip/pup.exe//WISE0006.BIN
detected: Trojan program Trojan.Win32.Revop.a File: C:\Qoobox\Quarantine\C\Program Files\_pup_.exe.zip/pup.exe

Blade81
2009-06-09, 16:12
Hi,

Please post also contents of c:\ComboFix.txt file :)

recklessdriver
2009-06-09, 16:47
oops, sorry!:red:

ComboFix 09-06-05.09 - jfuchino 2009-06-08 20:11.10 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.144 [GMT -7:00]
Running from: c:\documents and settings\jfuchino\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jfuchino\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\program files\InternetDialer.exe.ex_"

file zipped: c:\program files\Collect_pup.exe.vir
file zipped: c:\winnt\assembly\tmp\Collect_cmtnof.tmp.vir
file zipped: c:\winnt\Fonts\Collect_dbsrv.exe.vir
file zipped: c:\winnt\Help\Collect_scat.exe.vir
file zipped: c:\winnt\inf\Collect_msvcabr.exe.vir
file zipped: c:\winnt\Speech\Collect_oleras.exe.vir
file zipped: c:\winnt\system32\spool\prtprocs\Collect_dochard.exe.vir
file zipped: c:\winnt\Windows Update Setup Files\Collect_dmcofni.bak1.vir
file zipped: c:\winnt\Windows Update Setup Files\Collect_infocmd.exe.vir
file zipped: c:\winnt\Windows Update Setup Files\Collect_ksatvrs.bak2.vir
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\jfuchino\LOCALS~1\Temp\tacs.dat
c:\program files\InternetDialer.exe.ex_
c:\program files\pup.exe
c:\winnt\assembly\tmp\cmtnof.tmp
c:\winnt\Fonts\dbsrv.exe
c:\winnt\Help\scat.exe
c:\winnt\Help\tacs.bak1
c:\winnt\Help\tacs.bak2
c:\winnt\Help\tacs.ini
c:\winnt\inf\msvcabr.exe
c:\winnt\Speech\oleras.exe
c:\winnt\system32\spool\prtprocs\dochard.exe
c:\winnt\Windows Update Setup Files\dmcofni.bak1
c:\winnt\Windows Update Setup Files\dmcofni.bak2
c:\winnt\Windows Update Setup Files\infocmd.exe
c:\winnt\Windows Update Setup Files\ksatvrs.bak2

.
((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
.

2009-06-09 03:11 . 2009-06-09 03:11 187723 ----a-w- c:\program files\Collect_pup.exe.vir
2009-06-06 19:31 . 2009-06-06 19:31 -------- d-----w- C:\FOUND.000
2009-06-03 01:33 . 2009-06-03 01:33 -------- d-----w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 03:11 . 2009-06-09 03:11 855040 ----a-w- c:\winnt\inf\Collect_msvcabr.exe.vir
2009-06-09 03:11 . 2009-06-09 03:11 383508 ----a-w- c:\winnt\Help\Collect_scat.exe.vir
2002-12-19 22:44 . 2002-12-19 22:44 21952 ---h--w- c:\program files\folder.htt
.

------- Sigcheck -------

[-] 2001-05-08 19:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\svchost.exe
[-] 2001-05-08 11:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\dllcache\svchost.exe

[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\WININET.DLL
[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\dllcache\WININET.DLL
[7] 2003-06-19 19:05 466704 7DEF43F9247E47FDA32800953A581E0B c:\winnt\ServicePackFiles\i386\wininet.dll
[7] 2004-02-07 02:05 588288 4F64D1DF989E3AA2FAD91A2F1167B9C7 c:\winnt\$NtUninstallKB834707-IE6SP1-20040929.091901$\wininet.dll

[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\LSASS.EXE
[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\dllcache\lsass.exe
[-] 2001-05-08 19:00 33552 A26901CE15C815AE634BF2A6DEBE61E5 c:\winnt\$NtServicePackUninstall$\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\ServicePackFiles\i386\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\$NtUninstallKB835732$\lsass.exe

[-] 2001-02-20 20:09 8192 D36A33C21EEED5A6C1DAECB7C80A1909 c:\winnt\system32\CTFMON.EXE

[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\sfcfiles.dll
[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\dllcache\sfcfiles.dll
[-] 2001-05-08 19:00 971024 C8F5DF0E4750C49D0AE83054C5C1BC5A c:\winnt\$NtServicePackUninstall$\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\ServicePackFiles\i386\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\$NtUninstallKB835732$\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-01-09 151552]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-01-09 106496]
"UMonit2K.exe"="c:\winnt\System32\UMonit2K.exe" [2002-10-22 40960]
"Synchronization Manager"="mobsync.exe" - c:\winnt\system32\mobsync.exe [2003-06-19 111376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 186640]

c:\documents and settings\jfuchino\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2003-9-13 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)
"KodakCCS"=2 (0x2)

R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\winnt\system32\drivers\vch.sys [2002-12-19 18487]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2004-07-28 61712]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\winnt\system32\drivers\FTD2XX.sys [2009-03-25 29292]
S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);c:\winnt\system32\drivers\HPZs2k12.sys [2003-09-16 49944]
S3 RT-USB;Ross-Tech USB driver;c:\winnt\system32\drivers\RT-USB.SYS [2009-03-25 54400]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = about:blank
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-08 20:18
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(168)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
c:\winnt\system32\msv1_0.dll

- - - - - - - > 'explorer.exe'(1100)
c:\winnt\AppPatch\AcLayers.DLL
c:\winnt\system32\SHDOCVW.DLL
.
Completion time: 2009-06-09 20:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-09 03:20
ComboFix2.txt 2009-06-06 20:50
ComboFix3.txt 2009-03-26 19:16
ComboFix4.txt 2009-03-26 16:29
ComboFix5.txt 2009-06-09 03:10

Pre-Run: 16,344,268,800 bytes free
Post-Run: 16,297,721,856 bytes free

128

Blade81
2009-06-09, 20:24
Hi again :)

Upload following file to Virustotal (http://www.virustotal.com) and post back the results / link to the results:
c:\program files\windows media player\wmplayer.exe



Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\WINNT\systb.exe
C:\WINNT\polmx3.exe
C:\WINNT\taskmp3.exe
C:\WINNT\apacc.exe
C:\WINNT\rasms.exe
C:\WINNT\tcpdns.exe
C:\WINNT\system32\scvi50.exe
C:\WINNT\system32\ctts.exe
C:\WINNT\system32\siae3123.exe
C:\WINNT\system32\notepad.exe.tmp
C:\WINNT\system32\config\abrjava.exe
C:\WINNT\system32\drivers\etc\hosts.20090324-205938.backup
C:\WINNT\system32\spool\prtprocs\svccat.exe
C:\WINNT\system32\ShellExt\mainimg.exe
C:\WINNT\system32\URTTemp\abrmain.exe
C:\WINNT\system32\NtmsData\wmc.exe
C:\WINNT\system32\Microsoft\wavejpeg.exe
C:\WINNT\system32\Adobe\fontap.exe
C:\WINNT\system32\Adobe\bakacc.exe
C:\WINNT\system\playlib.exe
C:\WINNT\system\kbxml.exe
C:\WINNT\system\keyas.exe
C:\WINNT\repair\mfcdrv.exe
C:\WINNT\repair\taskfont.exe
C:\WINNT\repair\dlliis.exe
C:\WINNT\repair\mainac.exe
C:\WINNT\repair\libiis.exe
C:\WINNT\repair\wavehard.exe
C:\WINNT\repair\acmain.exe
C:\WINNT\Help\pcdrv.exe
C:\WINNT\Help\inetlib.exe
C:\WINNT\Fonts\keyac.exe
C:\WINNT\Fonts\ascmd.exe
C:\WINNT\Config\dvdabr.exe
C:\WINNT\Config\maincom.exe
C:\WINNT\msagent\intl\mcwave.exe
C:\WINNT\msagent\intl\maindll.exe
C:\WINNT\msagent\intl\dbdll.exe
C:\WINNT\msagent\intl\msvcsys.exe
C:\WINNT\Cursors\regdvd.exe
C:\WINNT\Cursors\mp3font.exe
C:\WINNT\java\faxcom.exe
C:\WINNT\java\classes\taskap.exe
C:\WINNT\java\trustlib\binvss.exe
C:\WINNT\java\trustlib\apun.exe
C:\WINNT\Web\bakdvd.exe
C:\WINNT\Web\logexp.exe
C:\WINNT\Web\printers\iptcp.exe
C:\WINNT\Web\printers\mssvc.exe
C:\WINNT\Web\printers\javamfc.exe
C:\WINNT\addins\adcat.exe
C:\WINNT\addins\runbas.exe
C:\WINNT\addins\javaad.exe
C:\WINNT\addins\com.exe
C:\WINNT\addins\fontfax.exe
C:\WINNT\addins\csrv.exe
C:\WINNT\Driver Cache\iis.exe
C:\WINNT\Driver Cache\compc.exe
C:\WINNT\security\templates\srvweb.exe
C:\WINNT\security\templates\tcpdrv.exe
C:\WINNT\security\templates\srvvga.exe
C:\WINNT\Windows Update Setup Files\pslog.exe
C:\WINNT\Windows Update Setup Files\svccat.exe
C:\WINNT\Windows Update Setup Files\wmsad.exe
C:\WINNT\Speech\hardbak.exe
C:\WINNT\Speech\msftp.exe
C:\WINNT\Speech\kbodbc.exe
C:\WINNT\Registration\dvdc.exe
C:\WINNT\Registration\vsswave.exe
C:\WINNT\Registration\dllcab.exe
C:\WINNT\Registration\webvss.exe
C:\WINNT\Registration\iissvc.exe
C:\WINNT\Drivers\mcabr.exe
C:\WINNT\Drivers\acbak.exe
C:\WINNT\Drivers\binbak.exe
C:\WINNT\Drivers\basanti.exe
C:\WINNT\Drivers\commfc.exe
C:\WINNT\ServicePackFiles\web.exe
C:\WINNT\ServicePackFiles\nettapi.exe
C:\WINNT\ServicePackFiles\cmdole.exe
C:\WINNT\Microsoft.NET\crjava.exe
C:\WINNT\Microsoft.NET\srvwin.exe
C:\WINNT\Microsoft.NET\cmdnet.exe
C:\WINNT\assembly\wkb.exe
C:\WINNT\assembly\GAC\Microsoft.VisualBasic.Vsa\docvb.exe
c:\program files\Collect_pup.exe.vir
c:\winnt\inf\Collect_msvcabr.exe.vir
c:\winnt\help\Collect_scat.exe.vir
c:\winnt\fonts\Collect_dbsrv.exe.vir



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log & a fresh dds.txt log. How's the system running?


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

recklessdriver
2009-06-09, 21:59
Upload following file to Virustotal and post back the results / link to the results:
c:\program files\windows media player\wmplayer.exe

I don't know what happened, but that file is no longer on the laptop. :confused:

Anyways, the new DDS and ComboFix logs are attached.

As for how is it running? The laptop is starting up much more quickly. Although I think I may have lost Microsoft Office 2000. I can't be sure because I haven't really used this laptop at all due to the infections and I don't recall if I could use Office at all on it (it searches for the installation disks:sad:). All I was doing was hooking it up to my car to run diagnostics, which generate .txt and .csv logs that I transfer to my desktop for further analysis in Excel. Either way, no big loss as all this laptop will be used to do is surf the web occasionally and run diagnostics on my car.


Thanks for the good work Blade81!

Blade81
2009-06-10, 15:36
Hi,

You may need to reinstall Office. However, since Office 2000 is not supported anymore I recommend to either get a new version or to install free Open Office (www.openoffice.org), in case you need one.

Open notepad and copy/paste the text in the quotebox below into it:



Driver::
vkquwexg

File::
c:\winnt\Collect_tcpdns.exe.vir
c:\winnt\Collect_taskmp3.exe.vir
c:\winnt\system32\Collect_siae3123.exe.vir
c:\winnt\system32\Collect_scvi50.exe.vir
c:\winnt\system32\Collect_notepad.exe.tmp.vir
c:\winnt\system32\Collect_ctts.exe.vir
c:\winnt\system\Collect_playlib.exe.vir
c:\winnt\system\Collect_keyas.exe.vir
c:\winnt\system\Collect_kbxml.exe.vir
c:\winnt\Collect_systb.exe.vir
c:\winnt\Collect_rasms.exe.vir
c:\winnt\Collect_polmx3.exe.vir
c:\winnt\Collect_apacc.exe.vir
c:\program files\Collect_Collect_pup.exe.vir.vir
c:\winnt\Web\printers\Collect_mssvc.exe.vir
c:\winnt\Web\printers\Collect_javamfc.exe.vir
c:\winnt\Web\printers\Collect_iptcp.exe.vir
c:\winnt\Web\Collect_logexp.exe.vir
c:\winnt\Web\Collect_bakdvd.exe.vir



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log & a fresh dds.txt log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

recklessdriver
2009-06-11, 07:57
New ComboFix and DDS logs, thanks!

======================================================
======================================================

ComboFix 09-06-05.09 - jfuchino 2009-06-10 22:20.12 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.130 [GMT -7:00]
Running from: c:\documents and settings\jfuchino\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jfuchino\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\program files\Collect_Collect_pup.exe.vir.vir"
"c:\winnt\Collect_apacc.exe.vir"
"c:\winnt\Collect_polmx3.exe.vir"
"c:\winnt\Collect_rasms.exe.vir"
"c:\winnt\Collect_systb.exe.vir"
"c:\winnt\Collect_taskmp3.exe.vir"
"c:\winnt\Collect_tcpdns.exe.vir"
"c:\winnt\system\Collect_kbxml.exe.vir"
"c:\winnt\system\Collect_keyas.exe.vir"
"c:\winnt\system\Collect_playlib.exe.vir"
"c:\winnt\system32\Collect_ctts.exe.vir"
"c:\winnt\system32\Collect_notepad.exe.tmp.vir"
"c:\winnt\system32\Collect_scvi50.exe.vir"
"c:\winnt\system32\Collect_siae3123.exe.vir"
"c:\winnt\Web\Collect_bakdvd.exe.vir"
"c:\winnt\Web\Collect_logexp.exe.vir"
"c:\winnt\Web\printers\Collect_iptcp.exe.vir"
"c:\winnt\Web\printers\Collect_javamfc.exe.vir"
"c:\winnt\Web\printers\Collect_mssvc.exe.vir"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Collect_Collect_pup.exe.vir.vir
c:\winnt\Collect_apacc.exe.vir
c:\winnt\Collect_polmx3.exe.vir
c:\winnt\Collect_rasms.exe.vir
c:\winnt\Collect_systb.exe.vir
c:\winnt\Collect_taskmp3.exe.vir
c:\winnt\Collect_tcpdns.exe.vir
c:\winnt\system\Collect_kbxml.exe.vir
c:\winnt\system\Collect_keyas.exe.vir
c:\winnt\system\Collect_playlib.exe.vir
c:\winnt\system32\Collect_ctts.exe.vir
c:\winnt\system32\Collect_notepad.exe.tmp.vir
c:\winnt\system32\Collect_scvi50.exe.vir
c:\winnt\system32\Collect_siae3123.exe.vir
c:\winnt\Web\Collect_bakdvd.exe.vir
c:\winnt\Web\Collect_logexp.exe.vir
c:\winnt\Web\printers\Collect_iptcp.exe.vir
c:\winnt\Web\printers\Collect_javamfc.exe.vir
c:\winnt\Web\printers\Collect_mssvc.exe.vir

.
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.

2009-06-06 19:31 . 2009-06-06 19:31 -------- d-----w- C:\FOUND.000
2009-06-03 01:33 . 2009-06-03 01:33 -------- d-----w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 19:00 . 2009-06-09 19:00 40960 ----a-w- c:\winnt\Registration\Collect_webvss.exe.vir
2002-12-19 22:44 . 2002-12-19 22:44 21952 ---h--w- c:\program files\folder.htt
.

------- Sigcheck -------

[-] 2001-05-08 19:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\svchost.exe
[-] 2001-05-08 11:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\dllcache\svchost.exe

[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\WININET.DLL
[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\dllcache\WININET.DLL
[7] 2003-06-19 19:05 466704 7DEF43F9247E47FDA32800953A581E0B c:\winnt\ServicePackFiles\i386\wininet.dll
[7] 2004-02-07 02:05 588288 4F64D1DF989E3AA2FAD91A2F1167B9C7 c:\winnt\$NtUninstallKB834707-IE6SP1-20040929.091901$\wininet.dll

[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\LSASS.EXE
[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\dllcache\lsass.exe
[-] 2001-05-08 19:00 33552 A26901CE15C815AE634BF2A6DEBE61E5 c:\winnt\$NtServicePackUninstall$\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\ServicePackFiles\i386\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\$NtUninstallKB835732$\lsass.exe

[-] 2001-02-20 20:09 8192 D36A33C21EEED5A6C1DAECB7C80A1909 c:\winnt\system32\CTFMON.EXE

[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\sfcfiles.dll
[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\dllcache\sfcfiles.dll
[-] 2001-05-08 19:00 971024 C8F5DF0E4750C49D0AE83054C5C1BC5A c:\winnt\$NtServicePackUninstall$\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\ServicePackFiles\i386\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\$NtUninstallKB835732$\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-01-09 151552]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-01-09 106496]
"UMonit2K.exe"="c:\winnt\System32\UMonit2K.exe" [2002-10-22 40960]
"Synchronization Manager"="mobsync.exe" - c:\winnt\system32\mobsync.exe [2003-06-19 111376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 186640]

c:\documents and settings\jfuchino\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2003-9-13 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)
"KodakCCS"=2 (0x2)

R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\winnt\system32\drivers\vch.sys [2002-12-19 18487]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2004-07-28 61712]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\winnt\system32\drivers\FTD2XX.sys [2009-03-25 29292]
S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);c:\winnt\system32\drivers\HPZs2k12.sys [2003-09-16 49944]
S3 RT-USB;Ross-Tech USB driver;c:\winnt\system32\drivers\RT-USB.SYS [2009-03-25 54400]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = about:blank
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-10 22:34
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(168)
c:\winnt\system32\msv1_0.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL

- - - - - - - > 'explorer.exe'(1124)
c:\winnt\AppPatch\AcLayers.DLL
c:\winnt\system32\SHDOCVW.DLL
.
Completion time: 2009-06-11 22:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-11 05:36
ComboFix2.txt 2009-06-09 19:10
ComboFix3.txt 2009-06-09 03:20
ComboFix4.txt 2009-06-06 20:50
ComboFix5.txt 2009-06-11 05:18

Pre-Run: 16,296,378,368 bytes free
Post-Run: 16,279,289,856 bytes free

137

===================================================
===================================================


DDS (Ver_09-05-14.01) - FAT32x86
Run by jfuchino at 22:41:12.13 on Wed 2009-06-10
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.134 [GMT -7:00]


============== Running Processes ===============

C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\UMonit2K.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\jfuchino\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = about:blank
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [UMonit2K.exe] "c:\winnt\system32\UMonit2K.exe"
mRun: [Synchronization Manager] mobsync.exe /logon
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\documents and settings\jfuchino\start menu\programs\startup\PowerReg Scheduler.exe
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {32564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8ax.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37883.8549189815
DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - hxxp://download.abacast.com/download/files/abasetup142f1.cab
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} -
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} -
Notify: igfxcui - igfxsrvc.dll

============= SERVICES / DRIVERS ===============

R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\winnt\system32\drivers\vch.sys [2002-12-19 18487]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2004-7-28 61712]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\winnt\system32\drivers\FTD2XX.sys [2009-3-25 29292]
S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);c:\winnt\system32\drivers\HPZs2k12.sys [2003-9-16 49944]
S3 RT-USB;Ross-Tech USB driver;c:\winnt\system32\drivers\RT-USB.SYS [2009-3-25 54400]
SUnknown vkquwexg;vkquwexg; [x]

=============== Created Last 30 ================

2009-06-10 22:41 16,384 a------- c:\winnt\system32\Perflib_Perfdata_294.dat
2009-06-10 22:20 187,723 a------- c:\program files\Collect_Collect_Collect_pup.exe.vir.vir.vir
2009-06-06 12:31 <DIR> --d----- C:\FOUND.000
2009-06-06 12:23 161,792 a------- c:\winnt\SWREG.exe
2009-06-06 12:23 154,624 a------- c:\winnt\PEV.exe
2009-06-06 12:23 98,816 a------- c:\winnt\sed.exe
2009-06-06 09:09 <DIR> a-dshr-- C:\autorun.inf

==================== Find3M ====================

2009-06-09 12:00 40,960 a------- c:\winnt\registration\Collect_webvss.exe.vir
2002-12-19 15:44 21,952 ----h--- c:\program files\folder.htt
2002-12-19 15:44 271 ----h--- c:\program files\desktop.ini
2001-05-08 12:00 32,528 a------- c:\winnt\inf\wbfirdma.sys

============= FINISH: 22:41:44.60 ===============

Blade81
2009-06-11, 16:54
Hi,

Please run ComboFix again (without script this time) and let it update itself. Post the log it produces.

recklessdriver
2009-06-12, 04:34
Please find below the latest ComboFix log. I'm not sure what you mean about "let it update itself" because it didn't seem that ComboFix tried to connect to the internet to update or anything. Spybot S&D doesn't find any more traces of Virtumonde, but it does still find two entries for ATLEvents.ATLEvents.

=========================================================
ComboFix 09-06-05.09 - jfuchino 2009-06-11 19:05.13 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.125 [GMT -7:00]
Running from: c:\documents and settings\jfuchino\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.

2009-06-12 02:04 . 2009-06-12 02:04 16384 ----a-w- c:\winnt\system32\Perflib_Perfdata_298.dat
2009-06-06 19:31 . 2009-06-06 19:31 -------- d-----w- C:\FOUND.000
2009-06-03 01:33 . 2009-06-03 01:33 -------- d-----w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 19:00 . 2009-06-09 19:00 40960 ----a-w- c:\winnt\Registration\Collect_webvss.exe.vir
2002-12-19 22:44 . 2002-12-19 22:44 21952 ---h--w- c:\program files\folder.htt
.

------- Sigcheck -------

[-] 2001-05-08 19:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\svchost.exe
[-] 2001-05-08 11:00 7952 9E64AD53CFD9DA2D22E8A924F8C6E62C c:\winnt\system32\dllcache\svchost.exe

[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\WININET.DLL
[-] 2004-08-24 03:32 589312 01893ED35886AFF539B58A025736F7ED c:\winnt\system32\dllcache\WININET.DLL
[7] 2003-06-19 19:05 466704 7DEF43F9247E47FDA32800953A581E0B c:\winnt\ServicePackFiles\i386\wininet.dll
[7] 2004-02-07 02:05 588288 4F64D1DF989E3AA2FAD91A2F1167B9C7 c:\winnt\$NtUninstallKB834707-IE6SP1-20040929.091901$\wininet.dll

[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\LSASS.EXE
[-] 2004-02-25 23:59 33552 0C13D582EDAF90CBEA454A1AC535B913 c:\winnt\system32\dllcache\lsass.exe
[-] 2001-05-08 19:00 33552 A26901CE15C815AE634BF2A6DEBE61E5 c:\winnt\$NtServicePackUninstall$\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\ServicePackFiles\i386\lsass.exe
[7] 2003-06-19 19:05 33552 271229760CCED993E9E7CAB1C7274134 c:\winnt\$NtUninstallKB835732$\lsass.exe

[-] 2001-02-20 20:09 8192 D36A33C21EEED5A6C1DAECB7C80A1909 c:\winnt\system32\CTFMON.EXE

[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\sfcfiles.dll
[-] 2004-03-24 02:17 971536 33D82938C20BA61E4EDB6DA85829BF23 c:\winnt\system32\dllcache\sfcfiles.dll
[-] 2001-05-08 19:00 971024 C8F5DF0E4750C49D0AE83054C5C1BC5A c:\winnt\$NtServicePackUninstall$\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\ServicePackFiles\i386\sfcfiles.dll
[7] 2003-06-19 19:05 971024 A871E77694E9146B3C655A734B1ECF46 c:\winnt\$NtUninstallKB835732$\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\winnt\System32\igfxtray.exe" [2002-01-09 151552]
"HotKeysCmds"="c:\winnt\System32\hkcmd.exe" [2002-01-09 106496]
"UMonit2K.exe"="c:\winnt\System32\UMonit2K.exe" [2002-10-22 40960]
"Synchronization Manager"="mobsync.exe" - c:\winnt\system32\mobsync.exe [2003-06-19 111376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 186640]

c:\documents and settings\jfuchino\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2003-9-13 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)
"KodakCCS"=2 (0x2)

R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\winnt\system32\drivers\vch.sys [2002-12-19 18487]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2004-07-28 61712]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\winnt\system32\drivers\FTD2XX.sys [2009-03-25 29292]
S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);c:\winnt\system32\drivers\HPZs2k12.sys [2003-09-16 49944]
S3 RT-USB;Ross-Tech USB driver;c:\winnt\system32\drivers\RT-USB.SYS [2009-03-25 54400]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = about:blank
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-11 19:07
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(168)
c:\winnt\system32\msv1_0.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL

- - - - - - - > 'explorer.exe'(1044)
c:\winnt\AppPatch\AcLayers.DLL
c:\winnt\system32\SHDOCVW.DLL
.
Completion time: 2009-06-12 19:09
ComboFix-quarantined-files.txt 2009-06-12 02:09
ComboFix2.txt 2009-06-11 05:37
ComboFix3.txt 2009-06-09 19:10
ComboFix4.txt 2009-06-09 03:20
ComboFix5.txt 2009-06-12 02:04

Pre-Run: 16,289,529,856 bytes free
Post-Run: 16,277,389,312 bytes free

95

Blade81
2009-06-12, 15:45
Ok. In that case, please delete present ComboFix.exe file and download it again from the same place that you earlier did. Then run it and post back the result log :)

recklessdriver
2009-06-16, 05:16
please don't delete this thread. i was out over the weekend and my usb drive was broken by my dog, so I have to go pick up a new one tomorrow.

Blade81
2009-06-16, 15:25
Ok. Thanks for the heads up :)

Blade81
2009-06-24, 20:21
Still with us, recklessdriver?

Blade81
2009-07-02, 22:51
Due to inactivity, this thread will now be closed.

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.