This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help! Vundo Infection!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, this is my first time posting here, so sorry if I made any mistakes. I'm posting because I'm infected with the Vundo virus and have tried many things to get rid of it. Its taking up my memory and the comp acts slower than before so help would be greatly appreciated. Below is my HijackThis Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:16:50 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Antivirus\CAV.EXE
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\vic\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [5b4fa1d5] rundll32.exe "C:\WINDOWS\system32\fpwxbqqe.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [QuickenBillminder] C:\Program Files\Quicken\Billmind.exe -startup
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky Update Setup] C:\Documents and Settings\vic\Local Settings\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe /updatesetup
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky Update Setup for All Users] C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe /updatesetup
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky] "C:\Documents and Settings\vic\Desktop\GBA\MimarSinan Rubber Ducky\RubberDucky.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0188E17F-B180-48A6-B199-055C219601B5} (DV_GistFontResourcesforWeb Control) - http://bhulekh.up.nic.in/IE/CAB/DVData.Cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…wlscbase370.cab
O16 - DPF: {E85FDB2D-2819-11D4-A59A-00600891E126} (IPlugin Control) - http://bhulekh.up.nic.in/IE/CAB/iPlugin.CAB
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 8716 bytes
Hello Madman001 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


WINDOWS DEFENDER
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)



AD-AWARE AD-WATCH
  • Right click on the Ad-Watch icon in the system tray.
  • At the bottom of the screen there will be two checkable items called "Active" and "Automatic".
    • Active: This will turn Ad-Watch On\Off without closing it.
    • Automatic: Suspicious activity will be blocked automatically.
  • Uncheck both of those boxes.
  • (When done, you can re-enable it using the same steps but this time check both boxes.)


B. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Heres the Log

ComboFix 08-03-04.4 - vic 2008-03-04 15:23:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.542 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Fonts\'
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\773C3DC4BD.dll
C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\ewqefgex.dll
C:\WINDOWS\system32\hbsghxny.dll
C:\WINDOWS\system32\igjpwhfk.dll
C:\WINDOWS\system32\ignblfyi.dll
C:\WINDOWS\system32\jxukmhcn.dll
C:\WINDOWS\system32\kglbkklj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini2
C:\WINDOWS\system32\taskmgr.com
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-04 to 2008-03-04 )))))))))))))))))))))))))))))))
.

2008-02-26 16:37 . 2008-02-26 16:38 d——– C:\Program Files\Windows Live Safety Center
2008-02-26 16:09 . 2008-02-26 16:09 100 –a—— C:\23990098.$$$
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\zts2.exe
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\system32\vcmgcd32.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\system32\iifgfgf.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\rundll16.exe
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\rundl132.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\logo1_.exe
2008-02-26 16:07 . 2004-08-09 20:00 146,432 –a—— C:\WINDOWS\R.COM
2008-02-26 16:07 . 2004-08-09 13:00 135,680 –a—— C:\WINDOWS\system32\T.COM
2008-02-26 16:07 . 2008-02-26 16:07 26 –a—— C:\WINDOWS\Lic.xxx
2008-02-23 13:46 . 2008-02-23 13:46 d——– C:\Program Files\Virtools
2008-02-18 12:56 . 2008-02-25 16:17 1,494 —hs—- C:\WINDOWS\system32\ltjxaupk.ini
2008-02-17 12:53 . 2008-02-18 12:54 1,374 —hs—- C:\WINDOWS\system32\cxskkoyg.ini
2008-02-15 19:17 . 2008-02-17 12:50 1,314 —hs—- C:\WINDOWS\system32\xsqjnfbn.ini
2008-02-14 18:34 . 2008-02-15 19:08 1,254 —hs—- C:\WINDOWS\system32\junsgxoh.ini
2008-02-13 18:38 . 2008-02-13 18:38 1,194 —hs—- C:\WINDOWS\system32\eqqbxwpf.ini
2008-02-12 08:55 . 2008-02-13 18:29 1,134 —hs—- C:\WINDOWS\system32\wuarumof.ini
2008-02-11 08:54 . 2008-02-12 08:54 1,014 —hs—- C:\WINDOWS\system32\nedoewqd.ini
2008-02-10 08:48 . 2008-02-11 08:49 954 —hs—- C:\WINDOWS\system32\nirdwrax.ini
2008-02-09 14:24 . 2008-02-09 14:24 894 —hs—- C:\WINDOWS\system32\yxgbpivf.ini
2008-02-08 17:05 . 2008-02-08 17:05 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-08 08:44 . 2008-02-09 14:21 834 —hs—- C:\WINDOWS\system32\ihmbvosi.ini
2008-02-06 18:11 . 2008-02-08 08:41 714 —hs—- C:\WINDOWS\system32\vltnibqs.ini
2008-02-05 16:17 . 2008-02-06 18:09 654 —hs—- C:\WINDOWS\system32\aoxjpfow.ini
2008-02-04 16:08 . 2008-02-05 16:14 354 —hs—- C:\WINDOWS\system32\fihsfubs.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 02:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-02 23:07 ——— d—–w C:\Documents and Settings\vic\Application Data\LimeWire
2008-03-01 13:34 1,612 —-a-w C:\Documents and Settings\vic\Application Data\wklnhst.dat
2008-02-23 23:08 ——— d—–w C:\Program Files\LimeWire
2008-02-09 01:05 ——— d—–w C:\Program Files\Lavasoft
2008-02-09 01:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 22:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}
2008-02-01 21:57 ——— d—–w C:\Program Files\BroadJump
2006-02-19 10:28 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
2006-09-10 06:14 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
2007-11-12 19:05 6,547 –sha-w C:\WINDOWS\system32\abadd.ini2
2007-11-12 02:30 6,547 –sha-w C:\WINDOWS\system32\cfhkj.ini2
2007-11-18 16:09 6,617 –sha-w C:\WINDOWS\system32\fgjlm.ini2
2007-11-18 20:38 418,859 –sha-w C:\WINDOWS\system32\nnnmp.ini2
2007-11-19 05:37 6,547 –sha-w C:\WINDOWS\system32\uttss.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7f1636fb-034c-4da3-8c86-c9a16b4a07ff}]
C:\WINDOWS\system32\bbhkptdg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 13:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 17:11 4670968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 14:41 68856]
"QuickenBillminder"="C:\Program Files\Quicken\Billmind.exe" [2006-10-30 05:39 17408]
"MimarSinan Rubber Ducky Update Setup"="C:\Documents and Settings\vic\Local Settings\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe" [ ]
"MimarSinan Rubber Ducky Update Setup for All Users"="C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe" [2006-09-21 22:45 2434944]
"MimarSinan Rubber Ducky"="C:\Documents and Settings\vic\Desktop\GBA\MimarSinan Rubber Ducky\RubberDucky.exe" [ ]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 09:37 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2008-01-24 09:22 2476408]
"5b4fa1d5"="C:\WINDOWS\system32\fpwxbqqe.dll" [ ]

C:\Documents and Settings\vic\Start Menu\Programs\Startup\
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1996-11-20 23:00:00 51984]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-05 14:41:00 124912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Dancer"="C:\Program Files\Windows Plus\Dancer\Dancer.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-09 13:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-04 02:39:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 15:28:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-03-04 15:30:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-04 23:30:48
.
2008-03-04 21:54:25 — E O F —


BTW: The darned thing didnt change back my time; its using military time now.
A. The time change can easily be remedied when we are finished.

B. Please ensure that your security programs are still disabled

C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\23990098.$$$
C:\WINDOWS\zts2.exe
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundl132.dll
C:\WINDOWS\logo1_.exe
C:\WINDOWS\R.COM
C:\WINDOWS\system32\T.COM
C:\WINDOWS\Lic.xxx
C:\WINDOWS\system32\ltjxaupk.ini
C:\WINDOWS\system32\cxskkoyg.ini
C:\WINDOWS\system32\xsqjnfbn.ini
C:\WINDOWS\system32\junsgxoh.ini
C:\WINDOWS\system32\eqqbxwpf.ini
C:\WINDOWS\system32\wuarumof.ini
C:\WINDOWS\system32\nedoewqd.ini
C:\WINDOWS\system32\nirdwrax.ini
C:\WINDOWS\system32\yxgbpivf.ini
C:\WINDOWS\system32\ihmbvosi.ini
C:\WINDOWS\system32\vltnibqs.ini
C:\WINDOWS\system32\aoxjpfow.ini
C:\WINDOWS\system32\fihsfubs.ini
C:\WINDOWS\system32\abadd.ini2
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\nnnmp.ini2
C:\WINDOWS\system32\uttss.ini2
C:\WINDOWS\Fonts\RandFont.dll

Folder:
C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7f1636fb-034c-4da3-8c86-c9a16b4a07ff}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MimarSinan Rubber Ducky Update Setup"=-
"MimarSinan Rubber Ducky"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"5b4fa1d5"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


D. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Sorry for the delay; I have been very busy and will be for the next few days, but I will try to get on as much as possible.

As for now, I only have the ComboFix Log, the Kaspersky Scan takes a long while so I havent got to it for a while. I'll try to get the Kaspersky Log on sometime soon.

ComboFix 08-03-04.4 - vic 2008-03-04 16:13:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.655 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\vic\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\23990098.$$$
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\Lic.xxx
C:\WINDOWS\logo1_.exe
C:\WINDOWS\R.COM
C:\WINDOWS\rundl132.dll
C:\WINDOWS\rundll16.exe
C:\WINDOWS\system32\abadd.ini2
C:\WINDOWS\system32\aoxjpfow.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cxskkoyg.ini
C:\WINDOWS\system32\eqqbxwpf.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\fihsfubs.ini
C:\WINDOWS\system32\ihmbvosi.ini
C:\WINDOWS\system32\iifgfgf.dll
C:\WINDOWS\system32\junsgxoh.ini
C:\WINDOWS\system32\ltjxaupk.ini
C:\WINDOWS\system32\nedoewqd.ini
C:\WINDOWS\system32\nirdwrax.ini
C:\WINDOWS\system32\nnnmp.ini2
C:\WINDOWS\system32\T.COM
C:\WINDOWS\system32\uttss.ini2
C:\WINDOWS\system32\vcmgcd32.dll
C:\WINDOWS\system32\vltnibqs.ini
C:\WINDOWS\system32\wuarumof.ini
C:\WINDOWS\system32\xsqjnfbn.ini
C:\WINDOWS\system32\yxgbpivf.ini
C:\WINDOWS\zts2.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\23990098.$$$
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\Lic.xxx
C:\WINDOWS\R.COM
C:\WINDOWS\system32\abadd.ini2
C:\WINDOWS\system32\aoxjpfow.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cxskkoyg.ini
C:\WINDOWS\system32\eqqbxwpf.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\fihsfubs.ini
C:\WINDOWS\system32\ihmbvosi.ini
C:\WINDOWS\system32\junsgxoh.ini
C:\WINDOWS\system32\ltjxaupk.ini
C:\WINDOWS\system32\nedoewqd.ini
C:\WINDOWS\system32\nirdwrax.ini
C:\WINDOWS\system32\nnnmp.ini2
C:\WINDOWS\system32\T.COM
C:\WINDOWS\system32\uttss.ini2
C:\WINDOWS\system32\vltnibqs.ini
C:\WINDOWS\system32\wuarumof.ini
C:\WINDOWS\system32\xsqjnfbn.ini
C:\WINDOWS\system32\yxgbpivf.ini

.
————— FMove —————

.
((((((((((((((((((((((((( Files Created from 2008-02-05 to 2008-03-05 )))))))))))))))))))))))))))))))
.

2008-03-04 16:08 . 2004-08-09 13:00 388,608 –a—— C:\CF1670.exe
2008-02-26 16:37 . 2008-02-26 16:38 d——– C:\Program Files\Windows Live Safety Center
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\zts2.exe
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\system32\vcmgcd32.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\system32\iifgfgf.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\rundll16.exe
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\rundl132.dll
2008-02-26 16:08 . 2008-02-26 16:08 d-a—— C:\WINDOWS\logo1_.exe
2008-02-23 13:46 . 2008-02-23 13:46 d——– C:\Program Files\Virtools
2008-02-08 17:05 . 2008-02-08 17:05 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 02:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-02 23:07 ——— d—–w C:\Documents and Settings\vic\Application Data\LimeWire
2008-03-01 13:34 1,612 —-a-w C:\Documents and Settings\vic\Application Data\wklnhst.dat
2008-02-23 23:08 ——— d—–w C:\Program Files\LimeWire
2008-02-09 01:05 ——— d—–w C:\Program Files\Lavasoft
2008-02-09 01:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 22:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}
2008-02-01 21:57 ——— d—–w C:\Program Files\BroadJump
2006-09-10 06:14 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 13:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 17:11 4670968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 14:41 68856]
"QuickenBillminder"="C:\Program Files\Quicken\Billmind.exe" [2006-10-30 05:39 17408]
"MimarSinan Rubber Ducky Update Setup for All Users"="C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe" [2006-09-21 22:45 2434944]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 09:37 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2008-01-24 09:22 2476408]

C:\Documents and Settings\vic\Start Menu\Programs\Startup\
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1996-11-20 23:00:00 51984]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-05 14:41:00 124912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Dancer"="C:\Program Files\Windows Plus\Dancer\Dancer.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-09 13:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-05 00:31:11 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 16:28:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-03-04 16:31:55 - machine was rebooted [vic]
ComboFix-quarantined-files.txt 2008-03-05 00:31:47
ComboFix2.txt 2008-03-04 23:30:56
.
2008-03-04 21:54:25 — E O F —
Please include the results from the Kaspersky scan as soon as possible for they are vital to containing the infection. Trevuren
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
Im very sorry, but I'm still not getting enough time for the scan. The scan takes quite a while to load and complete, but I might be able to do it this evening. I hope this isn't getting in the way of helping other people.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI