This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Horse Vundo JD, Trojan Horse Generic 16

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, here is the DeQuarantine.txt log: C:\Qoobox\Quarantine\C\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir -> C:\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe ( 18030130 bytes ) I hope that's all that has to be done. I have to leave for the day, but I'll check back tomorrow to see if there's anything else you think I need to do. Again, I really appreciate your help – you've been great! Don
Hi Mission Man,

A small error in my CFScript.txt :smack:

This is the last fix then we clean up.


Run combofix like you did last time with this CFScript.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DeQuarantine::
C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

A log called DeQuarantine.txt will be produced. Please post it's contents.

Thanks
Thanks, sorry I couldn't get back until today.

Here is the DeQuarantine.txt log:

DeQuarantine::
C:\Qoobox\Quarantine\C\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir
c\windows\$NtUninstallKB922582$


Here is the CFScript.txt log:

ComboFix 10-01-15.01 - John 01/15/2010 15:05:10.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.415 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\John\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe
L:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.

2010-01-13 13:40 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 19:25 . 2010-01-12 19:25 ——– d—–w- c:\program files\ESET
2010-01-12 18:10 . 2010-01-12 18:10 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-08 21:21 . 2010-01-08 21:21 ——– d—–w- c:\program files\Seagate
2010-01-08 21:20 . 2010-01-08 21:20 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Downloaded Installations
2010-01-07 17:04 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 17:04 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 17:01 . 2010-01-07 17:01 ——– d—–w- c:\program files\ERUNT
2010-01-07 16:50 . 2010-01-07 16:50 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-02 03:11 . 2010-01-02 03:11 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-01-02 03:10 . 2010-01-04 00:23 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-02 03:09 . 2010-01-07 23:35 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-12-24 19:52 . 2009-12-24 19:52 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-24 04:34 . 2009-12-24 04:34 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-12-23 16:53 . 2009-12-23 16:53 4043544 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-23 16:53 . 2009-12-23 16:53 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-23 16:53 . 2009-12-18 23:01 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 18:10 . 2009-09-04 22:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 19:15 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-07 20:19 . 2006-03-15 12:00 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-07 04:19 . 2009-05-16 14:53 ——– d—–w- c:\documents and settings\John\Application Data\U3
2010-01-06 19:19 . 2009-11-25 19:19 ——– d—–w- c:\program files\InterActual
2009-12-06 22:54 . 2009-10-20 17:39 ——– d—–w- c:\documents and settings\John\Application Data\HPAppData
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Sonic
2009-11-21 15:51 . 2006-03-15 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-17 16:55 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-17 16:54 . 2009-04-23 18:19 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-17 16:54 . 2009-04-23 18:19 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-17 16:54 . 2009-04-23 18:19 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 ——– d—–w- c:\program files\AVG
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\program files\Lavasoft
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-13 02:02 . 2009-05-11 16:16 45056 —-a-w- c:\windows\NCUNINST.EXE
2009-10-29 07:45 . 2006-03-15 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-03-15 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-03-15 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 17:31 . 2009-10-20 16:47 165190 —-a-w- c:\windows\hpoins33.dat
2009-10-20 16:20 . 2006-03-15 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-01-12_18.05.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-03-15 12:00 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2006-03-15 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-06-16 14:36 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2006-03-15 12:00 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll
- 2006-03-15 12:00 . 2009-06-16 14:36 119808 c:\windows\system32\t2embed.dll
+ 2009-06-16 14:36 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2009-04-23 19:35 . 2010-01-05 00:17 29634504 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-04-01 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-7-25 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-17 16:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-08-01 07:14 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/23/2009 11:19 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/23/2009 11:19 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/17/2009 9:54 AM 285392]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [6/8/2009 12:23 PM 42432]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 15:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-15 15:10:45
ComboFix-quarantined-files.txt 2010-01-15 22:10
ComboFix2.txt 2010-01-12 18:07
ComboFix3.txt 2010-01-09 19:27
C:\DeQuarantine.txt

Pre-Run: 187,283,808,256 bytes free
Post-Run: 187,250,237,440 bytes free

- - End Of File - - DB8EDDFFD9F2FF18F14E45C943019FA9

Thanks again for your help, and I'll be waiting to hear as to the next step.
Don
Hi Mission Man,

You ran the wrong CFScript. Here is the correct one. Since you ran combofix I had to add another file to it.

Run combofix like you did last time with this CFScript.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DeQuarantine::
C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$
C:\Qoobox\Quarantine\c\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir

Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

A log called DeQuarantine.txt will be produced. Please post it's contents.

Thanks
OK, here is the new log you requested. Hope this is the right one. C:\Qoobox\Quarantine\c\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir -> c:\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe ( 18030130 bytes ) C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\fltlib.dll -> C:\windows\$NtUninstallKB922582$\fltlib.dll C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\fltmc.exe -> C:\windows\$NtUninstallKB922582$\fltmc.exe C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\fltmgr.sys -> C:\windows\$NtUninstallKB922582$\fltmgr.sys C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\spuninst\spuninst.exe -> C:\windows\$NtUninstallKB922582$\spuninst\spuninst.exe C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\spuninst\spuninst.inf -> C:\windows\$NtUninstallKB922582$\spuninst\spuninst.inf C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\spuninst\spuninst.txt -> C:\windows\$NtUninstallKB922582$\spuninst\spuninst.txt C:\Qoobox\Quarantine\c\windows\$NtUninstallKB922582$\spuninst\updspapi.dll -> C:\windows\$NtUninstallKB922582$\spuninst\updspapi.dll 7 File(s) copied
Hi Mission Man,

The files ESET detected are either files we have quarantined or are in old system restore points. These will be removed when we remove the tools as outlined below.

If no other problems, we can clean up our tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.zip
  • GMER.exe
  • DDS.scr
Eset online can be removed via add/remove programs if you wish.


Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall



Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM, kepp it updated and use it regularly.

Some Recommendations and prevention tips


Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

For an antispyware program with resident (real time) scanning. I suggest

Windows Defender
OR
Winpatrol


* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios"
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI