PDA

View Full Version : New help vs. Win32, Virtumonde, etc.



LostinNJ
2009-11-05, 00:07
I've had Trojan horses, viruses, and malware since Friday night. Different ones are found and removed by each SpyBot or AVG scan, but then they or others show up again. This morning:
1. At startup, "svchost.exe - Application Error" window, reading: The instruction at "0x00aaaa49" referenced memory at "0x00000000". The memory could not be "read". Click on OK to terminate the program. Click on Cancel to debug the program.
2. Clicking on the close window X (because I wasn't sure if it was a legitimate message) caused a System Shutdown window to open (inc. "because the DCOM Server Process Launcher Service terminated unexpectedly").
3. Since then, startup opens only one window: RUNDLL, reading: Error loading kujejato.dll. The specified module could not be found.
4. After startup, I do a SpyBot Check for Problems complete scan, of about 660,000 files. At about 145,000, Virtumonde appears to the right of the file numbers being checked, and stays visible (with different extensions: .dll, .sdn, etc.) for most of the rest of the check. (Virtumonde, with different extensions, showed up in earliest scans, starting Friday night, but not in the last several.)
5. Lately, the scan turns up 3 or 4 entries of Win32.Agent.pz malware and Win32.ZBot Trojan. I click on Fix Selected Problems and green check marks appear, with a window that it's solved.
6. Closing SpyBot then opens a SpyBotSD.exe - Application Error window, reading: The instruction at "0x072a40c2" referenced memory at "0x0754e060". The memory could not be "read".
7. Whether I close the window or click OK, I get an Error window, reading, "Runtime error 216 at 072A40C2". Note: These are the latest numbers; after previous scans, the referenced memory at was "0x074adec8" or "0x0754e018" or others, and the runtime error 216 also read "072040C2".
8. A separate AVG scan today, right after the "selected problems" were "fixed" at SpyBot, turned up PSW.Generic7.APIQ threats in two files, which were moved to the Virus Vault, which I then emptied.
9. Later today I clicked on the Recovery button at SpyBot and saw apparently saved backups for the Win32 threats, which I then purged. But a second SpyBot scan again turned up the threats, and the backups were backed in Recovery (and then purged again).
10. Still in Recovery as backups (because I don't know if they're threats or OK) are: Fraud.Sysguard 3, WinSpywareProtect 1, Microsoft.Windows.AppFirewallBypass 2, Microsoft.WindowsSecurity.InternetExplorer 1, Microsoft.WindowsSecurityCenter.FirewallBypass 2, and MyWay.MyWebSearch 2

So, what--if anything--can I do to get rid of the threats (without losing everything in my hard drive, esp. Word files, e-mail messages, etc.)? If I see windows open up for svchost.exe - Application Error, RUNDLL (Error loading kujejato.dll), SpyBotSD.exe - Application Error, or Error (Runtime error 216), should I click on OK, or cancel (if that options exists), or the close window X, or do something else? Are those Recovery entries OK or threats? What else should I do, or know?

In other words, Helllllllllllllllp!!!!!!!!!

LostinNJ

LostinNJ
2009-11-05, 18:26
I'm sorry I'm a technical novice and don't know how to post properly, find any logs to insert, explain my persistent infections simply, etc. I hope this posting is not only updated but clearer than yesterday's. If I need to post this somewhere else in the Forum, or do it differently, someone please tell me.

I have a personal (residential), non-networked computer connected to the Internet by cable modem. Since Oct. 30, it's been infected (from a common, non-porn website or some other way on the Internet) by various Trojan Horses and viruses. The most persistent are Win32.Agent.pz ("3 entries Malware") and Win32.ZBot ("1 entries Trojans"), which keep showing up in SpyBot S&D scans, including today (Nov. 5). I "fix selected problems," then check Recovery, where backups of both suddenly appear (not there before the scan today), then Purge those in Recovery. Today's scan also found Win32/Cryptor in C\WINDOWS\Temp\rd114.tmp.exe; moved to virus vault and deleted there (in AVG Free 8.5).

Also found in Recovery on Nov. 4: Fraud.Sysguard, WinSpywareProtect, Microsoft.Windows.AppFirewallBypass, MS.WindowsSecurity.InternetExplorer, MS.WindowsSecurityCenter.FirewallBypass, and MyWay.MyWebSearch. I Purged them all and they haven't returned (yet).

After each SpyBot scan, 2 windows open, in turn: 1. Spybot SD.exe - Application Error (with white x in big red circle at left), reading: The instruction "0x072a40c2" referenced memory at "0x0754e060". The memory could not be "read". Click on OK to terminate the program.

That second number (referenced memory at) is slightly different each time--the letter after the 0754). I don't trust clicking OK, so I close the window (the close-window X at upper right). Then a small window opens: Error, reading: Runtime error 216 at 072A40C2.

I close this window too.

Found in previous AVG Free 8.5 scans: Oct. 31, Trojan Horses, Vundo.II and Vundo.IH; Nov. 2, Viruses, Packed.Hidden; Nov. 4 morning, Trojan Horse, PSW.Generic7.APIQ; and Nov. 4 evening, Trojan Horse, Generic14.BLRH. All moved to Virus Vault, and then manually deleted there (or VV emptied).

Note: At every start-up, a window opens, RUNDLL, reading: Error loading kujejato.dll.

I also close this window, and then SEEM to be able to operate the PC OK, starting with the SpyBot scan described above.

For a few days, start-up also opened a larger window, svchost.exe -Application Error, reading: The instruction at "0x00aaaa49" referenced memory at "0x00000000" [also different each time, I think]. The memory could not be "read". Click on OK to terminate the program. Click on cancel to debug the program.

I closed this window one time and got a System Shutdown window: Windows must now restart because the DCOM Server Process Launcher Service terminated unexpectedly." After the reboot, just the RUNDLL (kujejato.dll) window opened.

One other thing: Up until Nov. 4, the SpyBot scan was checking 660242 files; yesterday and today, the number now totals 745215. Are there 85,000 infected files dumped into my PC? Or were they being blocked from the scan but now are being scanned too, properly? (The scans since October 30 were generally taking only 11 minutes--unusually fast--but today's took 34 minutes to complete.

I think that's everything I know about this. Again, I apologize for my technically un-savvy way of describing all this. I hope someone can read all this and help me.

tashi
2009-11-05, 18:35
Hello LostinNJ,

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Please start a new topic and provide the HJT log. If HJT won't run please make note of that.

Also provide a link back to this thread rather than repeat all the information that you provided, a volunteer analyst will advise you when available.

Best regards. :)