Vundo and Other Problems
Hi, lately I have been having malware problems. I think it started when Spybot picked up some worse than usual stuff (AVSystemCare, Virtumonde, Zenosearch). They kept coming back after I restarted my computer. Symptoms included AVSystemCare warning me about viruses, NOD32 showing alerts whenever I tried to open Firefox for the first time after restarting the computer, being taken to random webpages during internet browsing, and for some reason my Quick Launch shortcuts disappearing (also, at one point IE kept exiting whenever I right-clicked on a link and went to "open in new tab", but I'm not sure if that is related, or just an IE bug). After going to Add/Remove programs (for AVSystemCare), removing some cookies and temporary files, and scanning multiple times with Spybot and NOD32, some of it seems to have gone away. Nothing bad showed up the last time I ran Spybot. NOD32 now has a bunch of stuff under quarantine that I don't know what to do with (files related to Virtumonde, Agent.BCK, and SecToolbar). I ran the Windows Live OneCare safety scanner, but whatever it deleted kept coming back the next time I scanned with it. VundoFix found and apparently fixed "Win32/Vundo.K" and "Win32/Winfixer", but it cannot remove "C:\windows\system32\yayyxvu.dll". VirtumundoBeGone found nothing.
Besides that, I thought all the symptoms were gone. Last night I left the Kaspersky online scanner running and went to sleep. When I woke up it was done, but there was another random webpage open in IE, and NOD32 alerted me to several new threats.
I tried to take the next step of running Spybot in Safe Mode, but whenever I restart my computer in Safe Mode, it shuts down by itself before Spybot can finish!
I really have no idea how this stuff got onto my computer. I honestly don't do stupid stuff like look for cracks or pr0n or use p2p. I log out of my username whenever I'm not using my computer (if someone else did it I suppose they could have used the guest account?). Maybe I clicked a pop-up by accident or something. The only thing I can think of that I have been doing different lately is that recently I have begun to use IRC (with Firefox add-on ChatZilla). Could that have caused my problems somehow? Also, I did have an old version of java, which I have now removed and replaced with the latest version. Is there any way I can find out how my computer got infected?
Thanks a lot in advance!
I haven't run HijackThis yet because I can't run Spybot in safe mode. Here is the Kaspersky log though:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, October 21, 2007 3:39:34 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/10/2007
Kaspersky Anti-Virus database records: 442101
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 122813
Number of viruses found: 5
Number of infected objects: 6
Number of suspicious objects: 2
Duration of the scan process: 01:51:41
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VarioAntiVirus8.zip/Activate.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VarioAntiVirus8.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\cert8.db Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\history.dat Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\key3.db Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Cameron\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Cameron\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific_Vista_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Microsoft_Security.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Microsoft_Security_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Other.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Urgent.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Welcome.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\infected\1SJIMQCA.NQF Infected: Trojan.Win32.Agent.bck skipped
C:\Program Files\ESET\infected\ZQDOQJDA.NQF Infected: not-a-virus:AdWare.Win32.Virtumonde.ady skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP324\A0077363.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP324\A0077372.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP325\A0077529.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP327\change.log Object is locked skipped
C:\VundoFix Backups\nfeudlcy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Hi, lately I have been having malware problems. I think it started when Spybot picked up some worse than usual stuff (AVSystemCare, Virtumonde, Zenosearch). They kept coming back after I restarted my computer. Symptoms included AVSystemCare warning me about viruses, NOD32 showing alerts whenever I tried to open Firefox for the first time after restarting the computer, being taken to random webpages during internet browsing, and for some reason my Quick Launch shortcuts disappearing (also, at one point IE kept exiting whenever I right-clicked on a link and went to "open in new tab", but I'm not sure if that is related, or just an IE bug). After going to Add/Remove programs (for AVSystemCare), removing some cookies and temporary files, and scanning multiple times with Spybot and NOD32, some of it seems to have gone away. Nothing bad showed up the last time I ran Spybot. NOD32 now has a bunch of stuff under quarantine that I don't know what to do with (files related to Virtumonde, Agent.BCK, and SecToolbar). I ran the Windows Live OneCare safety scanner, but whatever it deleted kept coming back the next time I scanned with it. VundoFix found and apparently fixed "Win32/Vundo.K" and "Win32/Winfixer", but it cannot remove "C:\windows\system32\yayyxvu.dll". VirtumundoBeGone found nothing.
Besides that, I thought all the symptoms were gone. Last night I left the Kaspersky online scanner running and went to sleep. When I woke up it was done, but there was another random webpage open in IE, and NOD32 alerted me to several new threats.
I tried to take the next step of running Spybot in Safe Mode, but whenever I restart my computer in Safe Mode, it shuts down by itself before Spybot can finish!
I really have no idea how this stuff got onto my computer. I honestly don't do stupid stuff like look for cracks or pr0n or use p2p. I log out of my username whenever I'm not using my computer (if someone else did it I suppose they could have used the guest account?). Maybe I clicked a pop-up by accident or something. The only thing I can think of that I have been doing different lately is that recently I have begun to use IRC (with Firefox add-on ChatZilla). Could that have caused my problems somehow? Also, I did have an old version of java, which I have now removed and replaced with the latest version. Is there any way I can find out how my computer got infected?
Thanks a lot in advance!
I haven't run HijackThis yet because I can't run Spybot in safe mode. Here is the Kaspersky log though:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, October 21, 2007 3:39:34 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/10/2007
Kaspersky Anti-Virus database records: 442101
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 122813
Number of viruses found: 5
Number of infected objects: 6
Number of suspicious objects: 2
Duration of the scan process: 01:51:41
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VarioAntiVirus8.zip/Activate.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VarioAntiVirus8.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\cert8.db Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\history.dat Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\key3.db Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Cameron\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Cameron\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hi2dahw.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Cameron\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cameron\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Cameron\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Gateway_Specific_Vista_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Microsoft_Security.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Microsoft_Security_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Other.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Urgent.dat Object is locked skipped
C:\Program Files\BigFix\__Data\Gateway\__Local\Tmp\Welcome.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\infected\1SJIMQCA.NQF Infected: Trojan.Win32.Agent.bck skipped
C:\Program Files\ESET\infected\ZQDOQJDA.NQF Infected: not-a-virus:AdWare.Win32.Virtumonde.ady skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP324\A0077363.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP324\A0077372.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP325\A0077529.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP327\change.log Object is locked skipped
C:\VundoFix Backups\nfeudlcy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.