This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Dropper.Agent.GIT- mlljj.exe infecting start up items

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Simon, I'm sorry to say that I was not successful running Combofix in normal mode. My antivirus and antispyware are disabled and no other windows are open. Combofix made it to the Autoscan window ("Scanning for infected files. This typically doesn't take…"), where a flashing cursor remained on the 4th text line for 30 minutes (the usual series of text status messages did not appear). I tried rebooting, downloading a new Combofix, and again using the new CFScript to run Combofix. Same result.
Hi :)

OK, please perform my last instructions in Safe Mode. I'm sorry it's taking this long, but the infection is quite new and can be very stubborn. We're almost there though, it should be gone with the next try.
No problem at all, Simon. Thanks for sticking with me.

OK, I ran Combofix in safe mode via the most recent CFScript, and the log is below:




ComboFix 08-01-08.4 - PBJG 2008-01-08 5:38:30.6 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.757 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\PBJG\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.

2008-01-05 16:51 . 2008-01-08 05:29 0 –a—— C:\WINDOWS\system32\drivers\lvuvc.hs
2008-01-03 06:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 20:14 . 2008-01-02 20:15 d——– C:\WINDOWS\ERUNT
2008-01-02 20:02 . 2008-01-02 20:02 d——– C:\Program Files\CCleaner
2007-12-30 22:51 . 2008-01-06 16:05 d——– C:\Documents and Settings\PBJG\Application Data\AVG7
2007-12-30 22:50 . 2007-12-30 22:50 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-30 21:51 . 2008-01-07 07:36 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-30 19:54 . 2007-12-30 19:54 d——– C:\Documents and Settings\PBJG\Application Data\CyberLink
2007-12-30 16:59 . 2007-12-30 16:59 d——– C:\Program Files\Trend Micro
2007-12-30 15:46 . 2008-01-07 07:31 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 13:08 . 2007-12-30 13:08 d——– C:\Documents and Settings\PBJG\Application Data\Uniblue
2007-12-30 09:24 . 2007-12-30 13:59 262,144 –a—— C:\WINDOWS\system32\ElkCtrl.exe
2007-12-30 09:24 . 2007-12-30 13:59 221,184 –a—— C:\WINDOWS\system32\LVCOMSX.EXE
2007-12-30 07:19 . 2007-12-30 07:19 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-30 07:14 . 2007-12-30 14:00 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 07:07 . 2007-12-30 23:37 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-12-30 07:06 . 2007-12-31 13:47 d——– C:\Documents and Settings\PBJG\Application Data\Vso
2007-12-30 07:06 . 2007-12-31 13:47 87,608 –a—— C:\Documents and Settings\PBJG\Application Data\ezpinst.exe
2007-12-30 07:06 . 2007-12-30 07:06 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-30 07:06 . 2007-12-31 13:47 47,360 –a—— C:\Documents and Settings\PBJG\Application Data\pcouffin.sys
2007-12-25 13:15 . 2007-12-25 13:15 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-24 13:26 . 2007-12-24 13:26 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-24 13:11 . 2007-12-24 13:11 d——– C:\Program Files\Common Files\Macrovision Shared
2007-12-10 18:49 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-10 18:49 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-10 18:49 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 10:38 ——— d—–w C:\Program Files\MSN Messenger
2008-01-08 10:38 ——— d—–w C:\Program Files\dvd43
2008-01-08 10:38 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-08 03:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-04 12:58 ——— d—–w C:\Program Files\Java
2007-12-31 18:47 ——— d—–w C:\Program Files\DivX
2007-12-31 05:09 ——— d—–w C:\Program Files\QuickTime
2007-12-31 03:32 ——— d—–w C:\Program Files\Norton 360
2007-12-30 23:33 ——— d—–w C:\Program Files\InterActual
2007-12-30 18:48 ——— d–h–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-30 18:48 ——— d—–w C:\Program Files\Yahoo!
2007-12-30 18:47 ——— d—–w C:\Documents and Settings\PBJG\Application Data\Yahoo!
2007-12-30 16:14 ——— d—–w C:\Program Files\LimeWire
2007-12-30 11:16 ——— d—–w C:\Program Files\vso
2007-12-30 05:14 ——— d—–w C:\Program Files\GemMaster
2007-12-24 18:11 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-24 18:06 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-24 18:06 129,784 ——w C:\WINDOWS\system32\PxAFS.DLL
2007-12-24 18:06 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-12-24 18:06 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-06 23:03 71,168 —-a-w C:\WINDOWS\system32\LxrJD31s.exe
2007-12-06 23:03 69,824 —-a-w C:\WINDOWS\system32\drivers\LxrJD31d.sys
2007-12-06 23:03 61,440 —-a-w C:\WINDOWS\system32\LxrJD20Sat.dll
2007-12-06 23:03 249,856 —-a-w C:\WINDOWS\system32\LxrJD31.dll
2007-12-06 23:03 163,840 —-a-w C:\WINDOWS\system32\LxrJD31c.exe
2007-12-06 23:03 146,432 —-a-w C:\WINDOWS\system32\LxrJD31p.exe
2007-11-14 08:19 ——— d—–w C:\Program Files\DISC
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((( snapshot_2008-01-05_16.43.27.78 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-31 03:35:13 64,512 —-a-w C:\WINDOWS\ehome\ehtray.exe
+ 2007-12-30 18:58:41 237,568 —-a-w C:\WINDOWS\SMINST\RECGUARD.EXE
+ 2007-12-30 18:59:25 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 16:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 19:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 13:15 7311360]
"nwiz"="nwiz.exe" [2006-01-24 13:15 1519616 C:\WINDOWS\system32\nwiz.exe]
"PCDrProfiler"="" []
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 13:00 16050176 C:\WINDOWS\RTHDCPL.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-12-30 22:35 49152]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-04 00:12:18]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-07-28 12:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b2cf876-6cd6-11db-b63c-0017313595a3}]
\Shell\AutoRun\command - L:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 17:39:29 C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job"
- C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe?Sched RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 05:42:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-08 5:42:41
ComboFix-quarantined-files.txt 2008-01-08 10:42:39
ComboFix2.txt 2008-01-07 12:53:59
ComboFix3.txt 2008-01-06 20:24:59
ComboFix4.txt 2008-01-05 21:43:48
ComboFix5.txt 2008-01-04 13:05:44
.
2007-12-13 08:05:09 — E O F —
Hi :)

Looks like we finally got rid of it!

Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:

You can now delete the following program(s):

  • SDFix (Don't forget to delete this folder: C:\SDFix\)

To uninstall Combofix, please do the following:

Click Start then Run….

Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

[external image: Posted Image]

Make your Internet Explorer More Secure

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialise and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.

Use a Firewall - Without a firewall your computer is susceptible to being hacked and taken over. The Windows firewall isn't sufficient as it only monitors incoming connections.

Here are a few (free) firewalls, please download and install one of them:


Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option (if you have an older version of this program, please update it by downloading it from the link that follows). This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here: http://www.bleepingcomputer.com/tutorials/tutorial43.html

Install Ad-Aware - Download and install Ad-Aware (if you have Ad-Aware SE note that it is outdated, and you should update to Ad-Aware 2007). You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here: http://www.bleepingcomputer.com/tutorials/tutorial48.html

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A tutorial can be found here: http://www.bleepingcomputer.com/tutorials/tutorial49.html

Install IE-Spyad - IE-Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites. A tutorial on installing this product can be found here: http://www.spywarewarrior.com/uiuc/resource.htm#IESPYAD

Update All Your Security Programs Regularly - Make sure you update all your security programs (Anti-Virus, Firewall, Anti-Spyware) regularly (once a weak, at least). Without regular updates you WILL NOT be protected when new malicious programs are released.

You can also read this excellent article by TonyKlein: So how did I get infected in the first place?

Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted! - Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints: Malware Complaints. You have to be registered to post. After registering just find your country room and register your complaint. The infection you had was Vundo (Virtumundo)
Simon, thank you very much for all of your time in eliminating this malware from my PC!! I very much appreciate all your efforts. Please tell me, what is your opinion on how well my existing Norton 360 suite of anti virus / anti spyware / firewall products compares to the set of tools you mentioned?
Hi :)

Fist of all, running two anti-virus programs (Norton 360 and AVG 7.5) is a bad idea. They could conflict and cause all sorts of problems; uninstall one of them.

I cannot comment on the performance of Norton 360, as I've never used it. I'm not a fan of Norton products though, not only because they tend to be majore resource hogs, but also because they're so popular. That makes them an interesting target for the malware writers. I'd recommend to install the programs (except for the firewall if you plan to keep Norton 360) that were listed in my previous post, to be sure you're sufficiently protected.
Yes, one anti virus application only. Note I when my Norton apparently became compromised, I had uninstalled it and then used AVG to obtain some detail. My PC is running with no issues. Thank you very much for your insights and all your help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI