This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi JP Hope this helps, I had a hard time with the f8, but finally got it! DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 15:38:22.45 on Wed 05/13/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.268 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\System32\hphmon05.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Documents and Settings\test\Desktop\dds.scr C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\iPod\bin\iPodService.exe C:\DOCUME~1\test\LOCALS~1\Temp\RarSFX0\FI.exe C:\WINDOWS\system32\rundll32.exe C:\DOCUME~1\test\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.my.yahoo.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll uRun: [BackupNotify] c:\program files\hp\digital imaging\bin\backupnotify.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [HPHmon05] c:\windows\system32\hphmon05.exe mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd.exe" mRun: [CamMonitor] c:\program files\hp\digital imaging\unload\hpqcmon.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] c:\program files\java\jre6\bin\jusched.exe mRun: [Share-to-Web Namespace Daemon] c:\program files\hp\hp share-to-web\hpgs2wnd.exe mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~1.lnk - c:\program files\quicken\bagent.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-2-4 425080] R3 EMCR;EMCR;c:\windows\system32\drivers\EMCR7SK.sys [2006-8-16 68480] S2 mrtRate;mrtRate; [x] =============== Created Last 30 ================ 2009-05-06 17:05 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-05-06 17:05 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-06 17:05 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-05-06 16:00 161,792 a——- c:\windows\SWREG.exe 2009-05-06 16:00 98,816 a——- c:\windows\sed.exe ==================== Find3M ==================== 2009-04-11 22:43 160,241,696 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-04-11 22:43 1,878,908 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-04-08 16:22 1,060,864 a——- c:\windows\system32\MFC71.dll 2009-04-08 16:22 499,712 a——- c:\windows\system32\msvcp71.dll 2009-04-08 16:22 434,252 a——- c:\windows\system32\MSVCRTD.DLL 2009-04-08 16:22 348,160 a——- c:\windows\system32\msvcr71.dll 2009-04-08 16:22 216,576 a——- c:\windows\system32\monln.dll 2009-03-10 22:18 934,792 ——– c:\windows\system32\dllcache\WgaTray.exe 2009-03-10 22:18 239,496 ——– c:\windows\system32\dllcache\wgaLogon.dll 2009-02-24 15:35 129,784 ——– c:\windows\system32\pxafs.dll 2009-02-24 15:35 120,056 ——– c:\windows\system32\pxcpyi64.exe 2009-02-24 15:35 118,520 ——– c:\windows\system32\pxinsi64.exe 2009-02-24 15:34 90,112 a——- c:\windows\system32\dpl100.dll 2009-02-24 15:34 823,296 a——- c:\windows\system32\divx_xx0c.dll 2009-02-24 15:34 823,296 a——- c:\windows\system32\divx_xx07.dll 2009-02-24 15:34 815,104 a——- c:\windows\system32\divx_xx0a.dll 2009-02-24 15:34 802,816 a——- c:\windows\system32\divx_xx11.dll 2009-02-24 15:34 684,032 a——- c:\windows\system32\DivX.dll 2008-09-27 19:29 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091520080922\index.dat 2008-09-27 19:29 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092720080928\index.dat ============= FINISH: 15:38:33.21 ===============

Attachments:

Hi,

Any luck with the Internet after that?

If not, please run SystemLook again with the following script:
:service
PlugPlay
TapiSrv
TCPIP
Hi Jp: Ok internet does not work wireless via router but does when I plug in ethernet cable directly to laptop. I'm sorry I did not mention it before. Now even though I can get a web page the internet connection icon keeps showing its acquiring a network address. This is the log from the system look: SystemLook v1.0 by jpshortstuff (24.04.09) Log created at 15:35 on 14/05/2009 by test (Administrator - Elevation successful) ========== service ========== PlugPlay Plug and Play "Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." Current Status: Started Startup Type: Automatic Error Control: Severe Binary: C:\WINDOWS\system32\services.exe Group: PlugPlay SafeBoot: Minimal Network Dependencies: (none) Dependant Services: ->Windows Driver Foundation - User-mode Driver Framework (WudfSvc) (Stopped) ->Remote Access Auto Connection Manager (RasAuto) (Stopped) ->Remote Access Connection Manager (RasMan) (Stopped) ->Telephony (TapiSrv) (Stopped) ->Smart Card (SCardSvr) (Stopped) ->Messenger (Messenger) (Stopped) ->Logical Disk Manager Administrative Service (dmadmin) (Stopped) ->Logical Disk Manager (dmserver) (Started) ->Windows Audio (AudioSrv) (Started) tapiSrv Telephony "Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service." Current Status: Stopped Startup Type: Disabled Error Control: Unable to Determine Binary: C:\WINDOWS\System32\svchost.exe -k netsvcs Group: (none) SafeBoot: Dependencies: ->PlugPlay ->RpcSs Dependant Services: ->Remote Access Auto Connection Manager (RasAuto) (Stopped) ->Remote Access Connection Manager (RasMan) (Stopped) TCPIP TCP/IP Protocol Driver "TCP/IP Protocol Driver" Current Status: Started Startup Type: System Error Control: Normal Binary: System32\DRIVERS\tcpip.sys Group: PNP_TDI SafeBoot: Network Network(Group) Dependencies: ->IPSec Dependant Services: ->Telnet (TlntSvr) (Stopped) ->QoS RSVP (RSVP) (Stopped) ->IPSEC Services (PolicyAgent) (Stopped) ->Network Location Awareness (NLA) (Nla) (Stopped) ->TCP/IP NetBIOS Helper (LmHosts) (Started) ->DHCP Client (Dhcp) (Started) ->NetBT (NetBT) (Started) ->IP Network Address Translator (IpNat) (Stopped) ->IP in IP Tunnel Driver (IpInIp) (Stopped) ->IP Traffic Filter Driver (IpFilterDriver) (Stopped) ->DNS Client (Dnscache) (Started) ->ATM ARP Client Protocol (Atmarpc) (Stopped) ->1394 ARP Client Protocol (Arp1394) (Stopped) -=End Of File=-
Hmm, this is very strange. I must say, I am not an expert on Networking. I can see no more signs of Malware in your log so I recommend you start a new topic in our Networking Forum where you will receive assistance from our excellent Tech Team.

Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.
NO Malware? But everytime I run ASQUARED scan it comes up with a virus. Can the other techs help with that too? Thanks so much for your help JP! I really appreciate your time!! a-squared Free - Version 4.0 Last update: 4/11/2009 10:41:39 PM Scan settings: Objects: Memory, Traces, Cookies, C:\ Scan archives: On Heuristics: Off ADS Scan: On Scan start: 5/13/2009 3:40:08 PM C:\System Volume Information\_restore{77CD0FD2-F758-4EE2-AE8C-BD61828C1D28}\RP2\A0000199.dll detected: Trojan-PWS.Win32.Lmir.mw!IK Scanned Files: 126316 Traces: 618087 Cookies: 1 Processes: 40 Found Files: 1 Traces: 0 Cookies: 0 Processes: 0 Registry keys: 0 Scan end: 5/13/2009 4:23:45 PM Scan time: 0:43:37
That is in your System Restore. If you uninstall ComboFix (as above), it should flush out your old System Restore points. Scan again after uninstalling ComboFix and rebooting, and see if you get anything. If you do get something else, let me know as the other Techs don't deal with Malware.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI