Extemporaneous
New member
Hi,
[Logs as requested follow below. However, I was presented with a dilemma when I tried to post this message. My post contained over 36000 characters, and the limit is set to 20000. And no attachments... So, I have removed part of the HJT log, and would be happy to supply it in my next post (as an attachment, possibly?)]
I ended up with VirtuMonde (vundu.dll et al) on my computer about 6 weeks ago. After a lot of research and pain, I managed to remove it, although I was left with a few software anomalies.
Today VirtuMonde returned. SpyBot S&D found it, and supposedly removed it (I don't think so).
I run AdAware 2007, Ad-Watch 2007, SpyBot S&D 1.4 regularly. My virus scanner (McAfee Enterprise 8.0.0) happily tells me I have no issues.
Any help would be highly appreciated.
Thanking you in advance...
-------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 23:48:28, on 08/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
[Removed for this post]
...
F:\Download\__Incoming\HijackThis.exe
[R1 through to R3 removed for this post]
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,"C:\Enabler\server\bin\OMSShutd.exe"
[Most of O2 removed]
O2 - BHO: (no name) - {0EED2CAA-C85D-49A3-A3E7-5A1CAD9DE6D5} - C:\WINDOWS\system32\ddabx.dll (file missing)
O2 - BHO: (no name) - {D9CF9E72-1E65-4EC1-B57A-19BE12030BF5} - C:\WINDOWS\system32\qomkjjg.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
[O4, O8, O9 Removed]
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://dev6.tpg.au.com
[O16, O17, O18 Removed]
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\MusicIP\MusicIP Mixer\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SQL Server FullText Search (MSSQLSERVER) (msftesql) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f:MSSQLSERVER (file missing)
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
O23 - Service: SQL Server Analysis Services (MSSQLSERVER) (MSSQLServerOLAPService) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\Config (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NuTCRACKER Service (NuTCRACKERService) - DataFocus, Inc. - C:\WINDOWS\system32\nutsrv4.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: SQL Server Agent (MSSQLSERVER) (SQLSERVERAGENT) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE" -i MSSQLSERVER (file missing)
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: UDS Environment Manager 5.0.1 - Unknown owner - c:\forte\install\bin\nodemgr.exe
O23 - Service: UDS Repository Manager 5.0.1 - Unknown owner - c:\forte\install\bin\rpserver.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: ZoneTick Time (ZTime) - WR Consulting - C:\Program Files\ZoneTick\timesync.exe
--------------------------------------------------------
http://www.ca.com/us/securityadvisor/virusinfo/scan.aspx
--------------------------------------------------------
Virus scan finished. 10 viruses found.
Scan Results: 331896 files scanned. 10 viruses were detected.
File Infection Status Path
T-202477-Fruity Loops Studio 7 0 Producer Edition 2007 exe.zip.Vir Win32/Alcan.I infected C:\quarantine\
T-202477-Fruity Loops Studio 7 0 Producer Edition 2007 exe.zip.Vir.0 Win32/Alcan.I!ZIP infected C:\quarantine\
T-742753-Fruity Loops Studio v.7 XXL Edition 2007.rar.Vir Win32/Nooz.A!ZIP infected C:\quarantine\
hkmjptpv.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
kjygscfl.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
oqmnqaty.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
qomkjjg.dll.bad Win32/Chisyne!generic infected C:\VundoFix Backups\
whcvwuri.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
ngewqisj.exe Win32/Secdrop.OB infected C:\WINDOWS\system32\
nwaeurcr.exe Win32/Secdrop.OB infected C:\WINDOWS\system32\
[Logs as requested follow below. However, I was presented with a dilemma when I tried to post this message. My post contained over 36000 characters, and the limit is set to 20000. And no attachments... So, I have removed part of the HJT log, and would be happy to supply it in my next post (as an attachment, possibly?)]
I ended up with VirtuMonde (vundu.dll et al) on my computer about 6 weeks ago. After a lot of research and pain, I managed to remove it, although I was left with a few software anomalies.
Today VirtuMonde returned. SpyBot S&D found it, and supposedly removed it (I don't think so).
I run AdAware 2007, Ad-Watch 2007, SpyBot S&D 1.4 regularly. My virus scanner (McAfee Enterprise 8.0.0) happily tells me I have no issues.
Any help would be highly appreciated.
Thanking you in advance...
-------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 23:48:28, on 08/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
[Removed for this post]
...
F:\Download\__Incoming\HijackThis.exe
[R1 through to R3 removed for this post]
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,"C:\Enabler\server\bin\OMSShutd.exe"
[Most of O2 removed]
O2 - BHO: (no name) - {0EED2CAA-C85D-49A3-A3E7-5A1CAD9DE6D5} - C:\WINDOWS\system32\ddabx.dll (file missing)
O2 - BHO: (no name) - {D9CF9E72-1E65-4EC1-B57A-19BE12030BF5} - C:\WINDOWS\system32\qomkjjg.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
[O4, O8, O9 Removed]
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://dev6.tpg.au.com
[O16, O17, O18 Removed]
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\MusicIP\MusicIP Mixer\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SQL Server FullText Search (MSSQLSERVER) (msftesql) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f:MSSQLSERVER (file missing)
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
O23 - Service: SQL Server Analysis Services (MSSQLSERVER) (MSSQLServerOLAPService) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\Config (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NuTCRACKER Service (NuTCRACKERService) - DataFocus, Inc. - C:\WINDOWS\system32\nutsrv4.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: SQL Server Agent (MSSQLSERVER) (SQLSERVERAGENT) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE" -i MSSQLSERVER (file missing)
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: UDS Environment Manager 5.0.1 - Unknown owner - c:\forte\install\bin\nodemgr.exe
O23 - Service: UDS Repository Manager 5.0.1 - Unknown owner - c:\forte\install\bin\rpserver.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: ZoneTick Time (ZTime) - WR Consulting - C:\Program Files\ZoneTick\timesync.exe
--------------------------------------------------------
http://www.ca.com/us/securityadvisor/virusinfo/scan.aspx
--------------------------------------------------------
Virus scan finished. 10 viruses found.
Scan Results: 331896 files scanned. 10 viruses were detected.
File Infection Status Path
T-202477-Fruity Loops Studio 7 0 Producer Edition 2007 exe.zip.Vir Win32/Alcan.I infected C:\quarantine\
T-202477-Fruity Loops Studio 7 0 Producer Edition 2007 exe.zip.Vir.0 Win32/Alcan.I!ZIP infected C:\quarantine\
T-742753-Fruity Loops Studio v.7 XXL Edition 2007.rar.Vir Win32/Nooz.A!ZIP infected C:\quarantine\
hkmjptpv.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
kjygscfl.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
oqmnqaty.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
qomkjjg.dll.bad Win32/Chisyne!generic infected C:\VundoFix Backups\
whcvwuri.dll.bad Win32/Vundo.DB infected C:\VundoFix Backups\
ngewqisj.exe Win32/Secdrop.OB infected C:\WINDOWS\system32\
nwaeurcr.exe Win32/Secdrop.OB infected C:\WINDOWS\system32\