Results 1 to 3 of 3

Thread: Need help to remove Virtumonde - HJT log posted

  1. #1
    Junior Member
    Join Date
    Nov 2007
    Posts
    11

    Question Need help to remove Virtumonde - HJT log posted

    Hello,

    I have a Compaq P4 , 2.4 Ghz, 512 MB-RAM, running on Win XP PRO - browser : IE 6 sp1.

    My system got infected with malware and adwares recently. Initially, I tried removing a few manually by reading the online forums, but they came back every time i logged on to the net.

    To start with, I got lots of Security Alert! pop-ups recommending me to click OK to downlond spyware removal software and lot of IE windows going to various websites. There was also a toolbar in IE called Security Toolbar. I identified it as SmitFraud and tried removing the files using SmitFraudFix.exe (I dont have the log of SmitFraudFix). Next i tried cleaning with the SDFix tool (find the log of SDFix at the end of this post).

    I then downloaded a multi-av scanner (multi_av.exe) and ran it using Sophos, Trend, Mcafee - they found quite a number of files and got some cleaned and some deleted. Most of them were DLLs found in System32 folder and entries from Restore folders.

    Finally, I used Spybot and found a BHO - VIRTUMONDE & VIRTUMONDE.GENERIC

    But, everytime I run Spybot it detects Virtumonde and clean repetedly. I've stopped using IE (to stop getting infected) instead i browse with FireFox, whenever i use IE it downloads all the malware again.

    After these incidents I find my system speed drops frequently while opening apps and mostly when i refresh the desktop, the desktop icons disappear - this i solve by logging off windows user.

    Pre-requisites as per your 'BEFORE YOU POST' thread.

    1) Spybot - Everytime I run it after browsing (using Firefox) it shows me being infected by VIRTUMONDE and other wise the red items are Windows Update/Firewall/AntiVirus Disabled entries.

    2) Online Kaspersky Scan - Not performed, because i can't use IE

    3) HJT Log file :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:56:54 PM, on 03/Nov/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
    O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [094819ab] rundll32.exe "C:\WINDOWS\System32\hdehgxfl.dll",b
    O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
    O4 - Global Startup: Function Palette.lnk = C:\Program Files\RDS\PLTBar.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase2474.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1160916777295
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CB9C91E8-E137-4D2C-865B-46C9A07D91C1}: NameServer = 203.145.184.13,202.56.250.5
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    --
    End of file - 3641 bytes

    Log Report of SDFix.exe :
    SDFix: Version 1.104

    Run by ANS on 13/Sep/2007 at 03:58 PM

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:

    Name:
    cmdService

    ImagePath:

    cmdService - Deleted
    C:\WINDOWS\system32\Microsoft\backup.ftp Found
    C:\WINDOWS\system32\Microsoft\backup.tftp Found

    Checking files:

    Genuine:
    C:\WINDOWS\system32\Microsoft\backup.ftp
    C:\WINDOWS\system32\Microsoft\backup.tftp

    Dummy:
    C:\WINDOWS\system32\ftp.exe
    C:\WINDOWS\system32\tftp.exe
    C:\WINDOWS\system32\dllcache\ftp.exe
    C:\WINDOWS\system32\dllcache\tftp.exe

    Files copied to SDFix\Backups

    Restoring files if backups are found

    Final Check:

    Genuine:
    C:\WINDOWS\system32\Microsoft\backup.ftp
    C:\WINDOWS\system32\Microsoft\backup.tftp
    C:\WINDOWS\system32\ftp.exe
    C:\WINDOWS\system32\tftp.exe
    C:\WINDOWS\system32\dllcache\ftp.exe
    C:\WINDOWS\system32\dllcache\tftp.exe

    Dummy:
    C:\WINDOWS\system32\Microsoft\backup.ftp Found
    C:\WINDOWS\system32\Microsoft\backup.tftp Found

    Checking files:

    Genuine:
    C:\WINDOWS\system32\Microsoft\backup.ftp
    C:\WINDOWS\system32\Microsoft\backup.tftp
    C:\WINDOWS\system32\ftp.exe
    C:\WINDOWS\system32\tftp.exe
    C:\WINDOWS\system32\dllcache\ftp.exe
    C:\WINDOWS\system32\dllcache\tftp.exe

    Dummy:
    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...

    Normal Mode:
    Checking Files:

    Trojan Files Found:
    C:\WINDOWS\SYSTEM32\SETUP_~1.EXE - Deleted
    C:\WINDOWS\SYSTEM32\SETUP_~1.EXE - Deleted

    Removing Temp Files...

    ADS Check:
    C:\WINDOWS
    No streams found.

    C:\WINDOWS\system32
    No streams found.

    C:\WINDOWS\system32\svchost.exe
    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.

    Final Check:
    Remaining Services:
    ------------------
    Authorized Application Key Export:
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\\AV-CLS\\WGET.EXE"="C:\\AV-CLS\\WGET.EXE:*:Enabled:WGET.EXE"

    Remaining Files:
    ---------------
    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes:
    C:\Program Files\Uninstall Information\IE40.Comctl32\AINF0000
    C:\System Volume Information\_restore{BC17D113-DB30-4733-81C9-81CB71643DCB}\RP1090\A0301021.exe
    C:\System Volume Information\_restore{BC17D113-DB30-4733-81C9-81CB71643DCB}\RP1067\A0288510.exe
    C:\redir.sys
    C:\WINDOWS\page files\maxmeg.sys
    C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
    C:\Documents and Settings\ANS\Local Settings\Temp\Temporary Directory 1 for APR-07.zip\APR-07\Thumbs.db

    Finished!


    Please help me to get rid of these malicious virus/malaware. Many Thanks in advance for your help.

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi sribashyam

    We can definitely help you, but first you need to help us. You are quite behind on your Windows Updates and Patches!!

    The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
    Click here to get WinXP SP1a: http://www.microsoft.com/downloads/details...&DisplayLang=en

    Apply the update, reboot, then go to Windows Update and install all the Critical Updates (Note: Except for WinXP SP2)
    Click here for Windows Update: http://www.windowsupdate.com/

    After installing all the Patches and updates, reboot, then post a fresh Hijack This log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Due to the lack of feedback this Topic is closed.

    If you need this topic reopened, please request this by sending the moderating team
    a PM with the address of the thread. This applies only to the original topic starter.

    Everyone else please begin a New Topic.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •