This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Thought I had it all cleared out, but I was wrong...

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Download The Avenger Copyright © Swandog46
You must extract avenger.exe to your desktop, before you run it.

Copy all the text contained in the code box below to your Clipboard.

Files to delete:
C:\WINDOWS\SYSTEM32\ddaba.dll
C:\WINDOWS\System32\abadd.ini


The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply along with a fresh HJT log.

Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.
Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\otatlaxb ******************* Script file located at: \??\C:\Documents and Settings\cquultua.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\WINDOWS\SYSTEM32\ddaba.dll deleted successfully. File C:\WINDOWS\System32\abadd.ini deleted successfully. Completed script processing. ******************* Finished! Terminate. — Logfile of HijackThis v1.99.1 Scan saved at 3:39:50 PM, on 7/28/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\ps2.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\MSN\MSNCoreFiles\msn.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe C:\Program Files\Spyware Tools\HijackThis\letmebe.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022 O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\jccatch.dll O2 - BHO: (no name) - {FF6BA19E-68A2-426A-818D-6164CEEF1344} - C:\WINDOWS\system32\ddaba.dll (file missing) O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_link.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {FF6BA19E-68A2-426A-818D-6164CEEF1344} - C:\WINDOWS\system32\ddaba.dll (file missing)

O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot.

How's the machine running now?
:unsure:

Securing Your PC After An Attack
Okay, that seemed to do the trick! :) Everything seems fine. I'm no longer getting warnings from Ewido about Virtumonde, and I ran an HJT scan, and both of those files are now gone. Did that take care of the other stuff you noticed in my combofix log, as well?
Evil file, delete if still found:
2006-07-25 19:29:16 65556 ( A…. ) "C:\WINDOWS\system32\rbwojyes.exe"

Evil file, delete if still found:
2006-07-16 06:16:46 20992 ( A…. ) "C:\WINDOWS\system32\a5b84408.exe"

Evil file, delete if still found:
2006-07-16 02:20:36 2 ( A…. ) "C:\WINDOWS\system32\wtssvit.exe"

Evil FOLDER, delete if still found:
2006-07-16 02:15:54 ( .D… ) "C:\Program Files\Common Files\svchostsys

Evil file, delete if still found:
2006-07-16 01:58:26 38412 ( A…. ) "C:\WINDOWS\ssqbn.exe"

Evil file, delete if still found:
2006-07-16 00:33:46 32206 ( ..SH. ) "C:\Program Files\Common Files\Y1123OU.exe"
(This one is "HIDDEN")

Evil FOLDER, delete if still found:
2006-07-16 00:33:34 ( .D… ) "C:\Program Files\F?nts"

Suspicious FOLDER:
2006-07-16 02:11:50 ( .D… ) "C:\Program Files\Common Files\iwkk"

What's in there?
:unsure:
Hmm. There are three files, all three are 0 kb: iwkka.lck, iwkkl.lck, iwkkm.lck, as well as another folder, "iwkkd," which has two files: one called "class-barrel" that is about 4.8 mb, and one called "vocabulary" that's around 1.2 mb. No clue what any of that stuff is. :) Should I delete all the files and folders you listed manually, or should I use KillBox or some such tool? Thanks again for the help!
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI