sailorman
Topic Starter
A unknown dialer is installed on my PC and start calling on dialup modem after some minutes I use the ADSL line. It seems that the malware start tasks named Vfie1 or Vfie2, Starting from this moment, the PC becames extremelly slow and sometimes an error on page appears. I try alreadu with ADWARE, SPYBOOT and EWIDO but without results.
I attached the log of HJJACK:
Logfile of HijackThis v1.99.1
Scan saved at 21.36.11, on 28/09/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\Programmi\ewido anti-spyware 4.0\guard.exe
E:\WINDOWS\Explorer.EXE
E:\Programmi\Norton AntiVirus\navapsvc.exe
E:\Programmi\Norton Internet Security\NISUM.EXE
E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\SOUNDMAN.EXE
C:\MediaKeyNT\MediaKey.exe
E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
E:\Programmi\iPod\iTunesHelper.exe
E:\Programmi\QuickTime\qttask.exe
E:\WINDOWS\System32\snmp.exe
E:\Programmi\Babylon\Babylon.exe
E:\PROGRA~1\NORTON~1\navapw32.exe
E:\Programmi\Norton Internet Security\IAMAPP.EXE
E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Temp\vfie1.exe
E:\Programmi\ewido anti-spyware 4.0\ewido.exe
E:\Programmi\Norton Internet Security\SymProxySvc.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\WINDOWS\system32\fxssvc.exe
E:\WINDOWS\System32\mqsvc.exe
E:\Programmi\Norton Internet Security\NISSERV.EXE
E:\WINDOWS\System32\mqtgsvc.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\Norton Internet Security\ATRACK.EXE
E:\Programmi\Hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {404E8B4C-6B40-33B0-B006-49C09745B821} - E:\WINDOWS\ejioe1.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\programmi\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ALiUSBfix] E:\WINDOWS\System32\ALiUSB20.exe
O4 - HKLM\..\Run: [MediaKey] C:\MediaKeyNT\MediaKey.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMLABTECMOUSE] E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Programmi\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Programmi\iPod\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Babylon Client] E:\Programmi\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NAV Agent] E:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] E:\Programmi\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [bikini] bikini.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
O4 - HKLM\..\Run: [vfie5.exe] E:\WINDOWS\Temp\vfie5.exe
O4 - HKLM\..\Run: [vfie2.exe] E:\WINDOWS\Temp\vfie2.exe
O4 - HKLM\..\Run: [vfie1.exe] E:\WINDOWS\Temp\vfie1.exe
O4 - HKLM\..\Run: [!ewido] "E:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [_SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKCU\..\Run: [Skype] "E:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = E:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Alice - {D555502E-C2E9-4993-88EF-1DDF7683F6E2} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O12 - Plugin for .pdf: E:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - https://safe.tele2.com/inc/accounthelper.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D77ED36C-1DAE-4038-A09B-3CE36D70E186}: NameServer = 193.12.150.2 212.247.152.2
O23 - Service: Ati HotKey Poller - Unknown owner - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - E:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - E:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmi\Norton Internet Security\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - E:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe (file missing)
The log of EWIDO:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 21.19.56 28/09/2006
+ Scan result:
D:\CartellaW98\Documents\Programmi\Babylon.zip/Babylon/babylon.pro.5.0.1.r7.fixed.read.nfo.crack-tsrh.zip/start.exe -> Downloader.Small.gl : No action taken.
E:\Programmi\Babylon\start.exe -> Downloader.Small.gl : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0160865.exe -> Trojan.LowZones.dt : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0169751.exe -> Trojan.LowZones.dt : No action taken.
::Report end
Waiting for your help, regards
The Sailorman
I attached the log of HJJACK:
Logfile of HijackThis v1.99.1
Scan saved at 21.36.11, on 28/09/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\Programmi\ewido anti-spyware 4.0\guard.exe
E:\WINDOWS\Explorer.EXE
E:\Programmi\Norton AntiVirus\navapsvc.exe
E:\Programmi\Norton Internet Security\NISUM.EXE
E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\SOUNDMAN.EXE
C:\MediaKeyNT\MediaKey.exe
E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
E:\Programmi\iPod\iTunesHelper.exe
E:\Programmi\QuickTime\qttask.exe
E:\WINDOWS\System32\snmp.exe
E:\Programmi\Babylon\Babylon.exe
E:\PROGRA~1\NORTON~1\navapw32.exe
E:\Programmi\Norton Internet Security\IAMAPP.EXE
E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Temp\vfie1.exe
E:\Programmi\ewido anti-spyware 4.0\ewido.exe
E:\Programmi\Norton Internet Security\SymProxySvc.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\WINDOWS\system32\fxssvc.exe
E:\WINDOWS\System32\mqsvc.exe
E:\Programmi\Norton Internet Security\NISSERV.EXE
E:\WINDOWS\System32\mqtgsvc.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\Norton Internet Security\ATRACK.EXE
E:\Programmi\Hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {404E8B4C-6B40-33B0-B006-49C09745B821} - E:\WINDOWS\ejioe1.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\programmi\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ALiUSBfix] E:\WINDOWS\System32\ALiUSB20.exe
O4 - HKLM\..\Run: [MediaKey] C:\MediaKeyNT\MediaKey.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMLABTECMOUSE] E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Programmi\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Programmi\iPod\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Babylon Client] E:\Programmi\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NAV Agent] E:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] E:\Programmi\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [bikini] bikini.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
O4 - HKLM\..\Run: [vfie5.exe] E:\WINDOWS\Temp\vfie5.exe
O4 - HKLM\..\Run: [vfie2.exe] E:\WINDOWS\Temp\vfie2.exe
O4 - HKLM\..\Run: [vfie1.exe] E:\WINDOWS\Temp\vfie1.exe
O4 - HKLM\..\Run: [!ewido] "E:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [_SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKCU\..\Run: [Skype] "E:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = E:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Alice - {D555502E-C2E9-4993-88EF-1DDF7683F6E2} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O12 - Plugin for .pdf: E:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - https://safe.tele2.com/inc/accounthelper.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D77ED36C-1DAE-4038-A09B-3CE36D70E186}: NameServer = 193.12.150.2 212.247.152.2
O23 - Service: Ati HotKey Poller - Unknown owner - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - E:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - E:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmi\Norton Internet Security\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - E:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe (file missing)
The log of EWIDO:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 21.19.56 28/09/2006
+ Scan result:
D:\CartellaW98\Documents\Programmi\Babylon.zip/Babylon/babylon.pro.5.0.1.r7.fixed.read.nfo.crack-tsrh.zip/start.exe -> Downloader.Small.gl : No action taken.
E:\Programmi\Babylon\start.exe -> Downloader.Small.gl : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0160865.exe -> Trojan.LowZones.dt : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0169751.exe -> Trojan.LowZones.dt : No action taken.
::Report end
Waiting for your help, regards
The Sailorman