DeGhosty
Topic Starter
tried system restore
it seems to have deleted all my restore points before the infection
is there anyway to save a manual restore point?
thanks for your time
Malwarebytes' Anti-Malware 1.24
Database version: 1054
Windows 5.1.2600 Service Pack 3
2:14:55 PM 8/15/2008
mbam-log-8-15-2008 (14-14-51).txt
Scan type: Quick Scan
Objects scanned: 42812
Time elapsed: 4 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 13
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
E:\WINDOWS\system32\cbXRiiFW.dll (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\geBuRHWq.dll (Trojan.Vundo) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2dfebd00-0600-4024-ab82-ad1de850bad7} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2dfebd00-0600-4024-ab82-ad1de850bad7} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geburhwq (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: e:\windows\system32\cbxriifw -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: e:\windows\system32\cbxriifw -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
E:\WINDOWS\system32\cbXRiiFW.dll (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\WFiiRXbc.ini (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\WFiiRXbc.ini2 (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\geBuRHWq.dll (Trojan.BHO) -> No action taken.
E:\WINDOWS\pskt.ini (Trojan.Vundo) -> No action taken.
E:\WINDOWS\BMa7acf5c6.xml (Trojan.Vundo) -> No action taken.
E:\WINDOWS\BMa7acf5c6.txt (Trojan.Vundo) -> No action taken.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:22 PM, on 8/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal
Running processes:
E:\windows\System32\smss.exe
E:\windows\system32\winlogon.exe
E:\windows\system32\services.exe
E:\windows\system32\lsass.exe
E:\windows\system32\Ati2evxx.exe
E:\windows\system32\svchost.exe
E:\windows\System32\svchost.exe
E:\windows\system32\svchost.exe
E:\windows\system32\Ati2evxx.exe
E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
E:\windows\Explorer.EXE
E:\Program Files\Microsoft IntelliType Pro\itype.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
E:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
E:\Program Files\Winamp\winampa.exe
E:\PROGRA~1\AVG\AVG8\avgtray.exe
E:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
E:\windows\RTHDCPL.EXE
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\windows\system32\ctfmon.exe
E:\windows\system32\spoolsv.exe
E:\program files\steam\steam.exe
E:\Program Files\DAEMON Tools Lite\daemon.exe
E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
E:\Program Files\Messenger\msmsgs.exe
C:\Program Files\KKBOX\KKBOX_Tray.exe
E:\Program Files\Winamp Remote\bin\OrbTray.exe
E:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
E:\Program Files\Winamp Remote\bin\Orb.exe
E:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
E:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
E:\windows\system32\svchost.exe
E:\PROGRA~1\AVG\AVG8\avgrsx.exe
E:\PROGRA~1\AVG\AVG8\avgemc.exe
E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
E:\windows\system32\wscntfy.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
E:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Opera\opera.exe
E:\Documents and Settings\feb2008\Desktop\HijackThis.exe
O4 - HKLM\..\Run: [StartCCC] "E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] E:\windows\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\windows\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O17 - HKLM\System\CS1\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O17 - HKLM\System\CS3\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\windows\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O24 - Desktop Component 0: (no name) - E:\Documents and Settings\feb2008\Desktop\media\The Morning After_3360x1050.jpg
O24 - Desktop Component 2: (no name) - http://www.google.ca/
–
End of file - 3847 bytes
it seems to have deleted all my restore points before the infection
is there anyway to save a manual restore point?
thanks for your time
Malwarebytes' Anti-Malware 1.24
Database version: 1054
Windows 5.1.2600 Service Pack 3
2:14:55 PM 8/15/2008
mbam-log-8-15-2008 (14-14-51).txt
Scan type: Quick Scan
Objects scanned: 42812
Time elapsed: 4 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 13
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
E:\WINDOWS\system32\cbXRiiFW.dll (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\geBuRHWq.dll (Trojan.Vundo) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2dfebd00-0600-4024-ab82-ad1de850bad7} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2dfebd00-0600-4024-ab82-ad1de850bad7} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geburhwq (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{683a9f36-9284-4b2a-9d68-72a4c6c5bc4d} (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: e:\windows\system32\cbxriifw -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: e:\windows\system32\cbxriifw -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
E:\WINDOWS\system32\cbXRiiFW.dll (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\WFiiRXbc.ini (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\WFiiRXbc.ini2 (Trojan.Vundo) -> No action taken.
E:\WINDOWS\system32\geBuRHWq.dll (Trojan.BHO) -> No action taken.
E:\WINDOWS\pskt.ini (Trojan.Vundo) -> No action taken.
E:\WINDOWS\BMa7acf5c6.xml (Trojan.Vundo) -> No action taken.
E:\WINDOWS\BMa7acf5c6.txt (Trojan.Vundo) -> No action taken.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:22 PM, on 8/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal
Running processes:
E:\windows\System32\smss.exe
E:\windows\system32\winlogon.exe
E:\windows\system32\services.exe
E:\windows\system32\lsass.exe
E:\windows\system32\Ati2evxx.exe
E:\windows\system32\svchost.exe
E:\windows\System32\svchost.exe
E:\windows\system32\svchost.exe
E:\windows\system32\Ati2evxx.exe
E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
E:\windows\Explorer.EXE
E:\Program Files\Microsoft IntelliType Pro\itype.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
E:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
E:\Program Files\Winamp\winampa.exe
E:\PROGRA~1\AVG\AVG8\avgtray.exe
E:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
E:\windows\RTHDCPL.EXE
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\windows\system32\ctfmon.exe
E:\windows\system32\spoolsv.exe
E:\program files\steam\steam.exe
E:\Program Files\DAEMON Tools Lite\daemon.exe
E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
E:\Program Files\Messenger\msmsgs.exe
C:\Program Files\KKBOX\KKBOX_Tray.exe
E:\Program Files\Winamp Remote\bin\OrbTray.exe
E:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
E:\Program Files\Winamp Remote\bin\Orb.exe
E:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
E:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
E:\windows\system32\svchost.exe
E:\PROGRA~1\AVG\AVG8\avgrsx.exe
E:\PROGRA~1\AVG\AVG8\avgemc.exe
E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
E:\windows\system32\wscntfy.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
E:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Opera\opera.exe
E:\Documents and Settings\feb2008\Desktop\HijackThis.exe
O4 - HKLM\..\Run: [StartCCC] "E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] E:\windows\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\windows\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O17 - HKLM\System\CS1\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O17 - HKLM\System\CS3\Services\Tcpip\..\{64CFD578-475C-4F7D-BD9A-43FB588B19E3}: NameServer = 206.248.154.22,206.248.154.170
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\windows\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O24 - Desktop Component 0: (no name) - E:\Documents and Settings\feb2008\Desktop\media\The Morning After_3360x1050.jpg
O24 - Desktop Component 2: (no name) - http://www.google.ca/
–
End of file - 3847 bytes