I've been fighting against Virtumonde for four weeks, maybe longer and have just finally gotten to the point that I can't figure out what to do.
I'll post the log files of each program that I have tried to use against it.
F-SECURE
-=-=-=-=-=-
Scanning Report
17 September 2007 10:08:56 - 10:52:15
Computer name: CISBELL
Scanning type: Perform full computer check
Target: C:\ + system
Result: 7 malware found
Win32.TrojanDownloader.Agent (Data miner)
* FILE:C:\WINDOWS\system32\ssttt.dll
FILE:C:\WINDOWS\wr.txt
REGKEY:HKCR\wr
REGKEY:HKLM\software\microsoft\tracing\fwcfg
REGVALUE:HKLM\software\microsoft\windows nt\currentversion\winlogon\autoadminlogon
* FILE:C:\WINDOWS\system32\ssttt.dll
REGKEY:HKLM\software\microsoft\tracing\fwcfg
REGVALUE:HKLM\software\microsoft\windows nt\currentversion\winlogon\autoadminlogon
Action: deleted FAILED
Virtumonde (Malware)
* FILE:C:\WINDOWS\system32\yayyaxv.dll
REGKEY:HKCR\clsid\{c6039e6c-bde9-4de5-bb40-768caa584fdc}
REGKEY:HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{c6039e6c-bde9-4de5-bb40-768caa584fdc}
REGKEY:HKCR\CLSID\{DCD53738-C4F9-414A-A03C-C7405A4AC844}
REGKEY:HKU\S-1-5-21-2089614548-2313981026-4210963882-1391\software\microsoft\ms juan
REGVALUE:HKLM\software\microsoft\windows\currentversion\run\systemoptimizer
REGKEY:HKLM\software\microsoft\jkwslist
REGKEY:HKLM\software\microsoft\jsearchcount
* FILE:C:\WINDOWS\system32\yayyaxv.dll
FILE:C:\WINDOWS\wr.txt
REGKEY:HKCR\wr
REGKEY:HKCR\clsid\{c6039e6c-bde9-4de5-bb40-768caa584fdc}
REGKEY:HKU\S-1-5-21-2089614548-2313981026-4210963882-1391\software\microsoft\ms juan
REGVALUE:HKLM\software\microsoft\windows\currentversion\run\systemoptimizer
REGKEY:HKLM\software\microsoft\jkwslist
REGKEY:HKLM\software\microsoft\jsearchcount
REGKEY:HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{c6039e6c-bde9-4de5-bb40-768caa584fdc}
REGKEY:HKCR\CLSID\{DCD53738-C4F9-414A-A03C-C7405A4AC844}
Action: deleted FAILED
Trojan-Downloader.Win32.Small.eqn (virus)
* C:\RECYCLER\S-1-5-21-2089614548-2313981026-4210963882-1391\Dc172\d0125.exe Action: deleted
Trojan-Downloader.Win32.VB.awj (virus)
* C:\RECYCLER\S-1-5-21-2089614548-2313981026-4210963882-1391\Dc173\f02WtR1065.exe Action: deleted
Trojan-Downloader.Win32.VB.ang (virus)
* C:\WINDOWS\lwdyxmlA.exe Action: deleted
Trojan-Downloader.Win32.Small.buy (virus)
* C:\WINDOWS\system32\tmps2\MTIDocs.exe Action: deleted
Password-protected-EXE (virus)
* C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip Action: deleted
Statistics
Files:
* Scanned: 35953
* System: 5708
* Not scanned: 38
Result:
* Viruses: 3
* Spyware: 2
* Suspected: 2
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 7
* Quarantined: 0
* Failed: 2
Boot Sectors:
* Scanned: 1
* Infected: 0
* Suspected: 0
* Disinfected: 0
Files not scanned:
* Cannot open file C:\hiberfil.sys
* Cannot open file C:\pagefile.sys
* Cannot open file C:\WINDOWS\system32\config\DEFAULT
* Cannot open file C:\WINDOWS\SoftwareDistribution\EventCache\{74FFB88F-491E-4D33-8326-39FB22F1ED87}.bin
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar1.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar2.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar3.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar4.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar5.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CouponBar6.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde10.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde11.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde12.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde13.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde16.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde17.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde18.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde19.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip\removalfile.bat is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde6.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde7.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde9.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeWinpop.zip\sbRecovery.reg is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip\Yazzle1281OinUninstaller.exe is encrypted
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip\Yazzle1281OinAdmin.exe is encrypted
* Cannot open file C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_50e417e0-e461-474b-96e2-077b80325612
* File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip\Yazzle1281OinUninstaller.exe is encrypted
* An error occurred while scanning (error code 60002)
* An error occurred while scanning (error code 60002)
Options
Definitions version:
* Viruses: 2007-09-17_04
* Spyware: 2007-09-06_02
Scanning Engines:
* F-Secure AVP: 6.00.169, 2007-09-17
* F-Secure Libra: 2.03.11, 2007-09-15
* F-Secure Orion: 1.02.37, 2007-09-17
* F-Secure Draco: 1.00.35, 2007-09-03
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ANI AVB BAT CEO CMD LSP MAP MHT MIF PHP POT WMF NWS TAR TGZ ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
* Scan inside archives
Actions:
* Viruses: Ask after scan
* Spyware: Ask after scan