I'm moving your post over to the Malware Removal Forum where you will receive assistance from our experts as your turn and their attention becomes available.
Doug
Hi all i have to say after reading a lot of posts regarding the trojan Virtumonde it seems like you guys really know your stuff so i figured this would be the best place to get help. Basically i have confirmed that i have Virtumonde through both NORTONS AV CORPORATE EDITION as well as Spydoctor. The trojan has somehow disabled my nortons and now i cant even uninstall or reinstall even after running nortons own removal tool. So at the moment i have only spryware doctor running for protection and when i run a scan it picks up the suspected files but will not delete them. I have run the vundofix tool as well as the virtumondeBeGone tool but to no prevail. I have run the combofix tool and various reg cleaners as well but still no good. So i have run a hijackthis diagnostic and heve the reports but dont reall know where to post them for help? Somebody help me out there? Thanks Kindly Scoot bugged
Hijack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:07:12 PM, on 29/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\Program Files\Personal\bin\Personal.exe
C:\PROGRA~1\SPYWAR~1\swdoctor .exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\SPYWAR~1\Update.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\mljji.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.fujidirekt.se/aurigma/ImageUploader4.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.7.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
–
End of file - 7382 bytes
Combofix Log
ComboFix 07-12-21.4 - Scott & Maria 2007-12-29 16:15:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.534 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Removal Tools\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\HotbarSA
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA_kyf.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAAbout.mht
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAau.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAEULA.mht
C:\Documents and Settings\Scott & Maria\Application Data\Hotbar_Icons
C:\Documents and Settings\Scott & Maria\Application Data\Hotbar_Icons\meetic.ico
C:\Documents and Settings\Scott & Maria\Application Data\Hotbar_Icons\Registryrepair.ico
C:\Documents and Settings\Scott & Maria\Application Data\Hotbar_Icons\wallpapere1.ico
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\SSSInst\bin\SSSUninst.exe
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\drivers\sfsync03.sys
C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\ijjlm.ini2
C:\WINDOWS\system32\jjkmp.ini2
C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\rrutv.ini
C:\WINDOWS\system32\rrutv.ini2
C:\WINDOWS\system32\xybeg.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_SFSYNC03
——-\sfsync03
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.
2007-12-29 16:06 . 2007-12-29 16:06 d——– C:\Program Files\Trend Micro
2007-12-29 16:03 . 2007-12-29 16:03 348,160 –a—— C:\WINDOWS\system32\RCXE.tmp
2007-12-29 14:56 . 2007-12-29 14:56 348,160 –a—— C:\WINDOWS\system32\RCXC.tmp
2007-12-29 14:29 . 2007-12-29 16:16 348,160 –a—— C:\WINDOWS\system32\mljji.exe
2007-12-29 13:40 . 2007-12-29 13:40 348,160 –a—— C:\WINDOWS\system32\RCX9.tmp
2007-12-29 12:33 . 2007-12-29 12:43 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-29 12:13 . 2007-12-29 12:17 d——– C:\Program Files\RegCure
2007-12-29 12:12 . 2007-12-29 12:12 38,400 –a—— C:\WINDOWS\system32\fccbyab.dll.vir
2007-12-29 11:22 . 2007-12-29 11:22 23 –ahs—- C:\WINDOWS\system32\cecabcb5_d.dll
2007-12-29 11:22 . 2007-12-29 11:22 23 –a—— C:\WINDOWS\system32\aafcdaefb_d.ocx
2007-12-29 00:45 . 2007-12-29 01:00 d——– C:\VundoFix Backups
2007-12-27 22:21 . 2007-12-29 14:31 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-27 19:59 . 2007-12-27 22:21 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2007-12-27 19:58 . 2007-12-27 22:21 40,960 –a—— C:\WINDOWS\VM_STI .EXE
2007-12-27 18:24 . 2007-12-27 18:24 d——– C:\Program Files\Nsasoft
2007-12-27 17:16 . 2007-12-27 22:33 d——– C:\Program Files\QuickTime
2007-12-26 23:07 . 2007-12-26 23:07 37,376 –a—— C:\WINDOWS\system32\qommjii.dll.vir
2007-12-20 15:50 . 2007-12-20 15:50 d–h—– C:\WINDOWS\PIF
2007-12-12 10:38 . 2007-12-12 10:38 63 –a—— C:\WINDOWS\mdm.ini
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 15:27 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-29 15:25 ——— d—–w C:\Program Files\Spyware Doctor
2007-12-29 11:09 ——— d—–w C:\Program Files\Windows Live Safety Center
2007-12-28 23:13 ——— d—–w C:\Program Files\Microsoft Works
2007-12-27 21:21 ——— d—–w C:\Program Files\DAEMON Tools
2007-12-23 07:30 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Skype
2007-12-09 12:12 ——— d—–w C:\Program Files\Sixtens Games Folder
2007-11-30 15:25 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-23 18:52 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Yahoo!
2007-11-23 13:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-23 13:39 ——— d—–w C:\Program Files\Yahoo!
2007-11-23 13:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-19 15:33 ——— d—–w C:\Program Files\Pettson1
2007-11-18 19:14 ——— d—–w C:\Program Files\Jardinains!
2007-11-18 14:56 ——— d—–w C:\Program Files\Björne
2007-11-13 16:00 ——— d—–w C:\Program Files\Pettson3
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 18:37 2,288 —-a-w C:\Documents and Settings\Scott & Maria\Application Data\wklnhst.dat
2007-11-11 11:45 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Microsoft Web Folders
2007-11-05 20:42 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\LimeWire
2007-11-05 20:39 ——— d—–w C:\Program Files\Common Files\Real
2007-11-05 20:37 ——— d—–w C:\Program Files\Apple Software Update
2007-11-04 08:50 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\WeatherDPA
2007-11-04 08:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-03-19 16:06 3,704,990 —-a-w C:\Program Files\GG-WINDOWS-894.EXE
2007-01-06 11:33 10,503,520 —-a-w C:\Program Files\sdsetup.exe
2006-08-13 17:16 880,779 —-a-w C:\Program Files\Eusing Free Registry CleanerSetup.exe
2007-03-27 16:19 168 –sh–r C:\WINDOWS\system32\708743E34D.sys
2007-03-27 16:20 5,330 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"Spyware Doctor"="C:\PROGRA~1\SPYWAR~1\swdoctor.exe" [2007-12-29 16:05]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 11:00 C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 06:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-08-23 20:12 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 06:00 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-12-29 16:05]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-11-10 16:34:00]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:56]
MiniMavis.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe [2006-12-29 20:43:02]
Personal.lnk - C:\Program Files\Personal\bin\Personal.exe [2007-02-03 12:49:33]
S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [2005-07-27 14:11]
S3 WINIO;WINIO;C:\winio.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-12-27 09:51:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-29 15:14:10 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-12-29 15:26:28 C:\WINDOWS\Tasks\RegCure Program Check.job"
"2007-12-29 11:15:28 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 16:26:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2007-12-29 16:28:32 - machine was rebooted
.
2007-12-12 12:08:32 — E O F —
Please HELP