Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished)

 
 
LinkBack Thread Tools Display Modes
Old 06-28-2008, 09:13 PM   #1 (permalink)
True Techie
 
Join Date: Jun 2008
Posts: 137
Default virtumonde virus HJT log..please help [F]

Logfile of HijackThis v1.99.1
Scan saved at 9:45:04 PM, on 6/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DNA\btdna.exe
C:\Documents and Settings\me.MOE.000\Desktop\UltraSurf 8.9.exe
C:\Program Files\Solways Task Scheduler\tasksched.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: (no name) - {D554A583-D4CF-4A6F-B07A-CB25F60FA743} - C:\WINDOWS\system32\hgGyvtSi.dll
O2 - BHO: (no name) - {DADCCFE7-103D-4566-9260-5C3806C2EE1B} - C:\WINDOWS\system32\wvULDWPf.dll (file missing)
O3 - Toolbar: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [dcb59a0d] rundll32.exe "C:\WINDOWS\system32\ljnacosx.dll",b
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msltstsoft_updt.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9978] command /c del "C:\WINDOWS\system32\wvULDWPf.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9722] cmd /c del "C:\WINDOWS\system32\wvULDWPf.dll_old"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: Shortcut to UltraSurf 8.9.exe.lnk = C:\Documents and Settings\me.MOE.000\Desktop\UltraSurf 8.9.exe
O4 - Startup: Solway's Task Scheduler.lnk = C:\Program Files\Solways Task Scheduler\tasksched.exe
O4 - Startup: SUPERAntiSpyware Free Edition.lnk = C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll C:\PROGRA~1\Comodo\Css\cssdll32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hgGyvtSi - C:\WINDOWS\SYSTEM32\hgGyvtSi.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
mossy1881 is offline  
Old 06-28-2008, 09:19 PM   #2 (permalink)
Commander Super Mod Joker
 
Mak213's Avatar
 
Join Date: Sep 2004
Location: In Trotter's crawl space
Posts: 14,352
Default Re: virtumonde virus HJT log..please help

Hello,

Step1 | ComboFixe

Download ComboFix from Here or Here to your Desktop.
Read first: "How to download and use ComboFix"
If you downloaded ComboFix previously, delete that version and download it again as the tool is frequently updated!
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
  • Be sure to re-enable your anti-virus and other security programs, after ComboFix finished.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall.

Extra-Note: Please, DO NOT use ComboFix on your own. It is a very powerful tool designed to deal with sophisticated infections and if something goes wrong or you use it incorrectly, you could possibly lose the use of your computer. It is ONLY meant to be used under the direct supervision of a malware removal specialist. Please read Combofix's Disclaimer

Logs needed in next post:

ComboFix

Cheers,
Mak
__________________


Mak213 is offline  
Old 06-28-2008, 10:33 PM   #3 (permalink)
True Techie
 
Join Date: Jun 2008
Posts: 137
Default Re: virtumonde virus HJT log..please help

Mak213, It is getting late and I will do this tomorrow morning and will post logs when I am done. At some point tomorrow, do you think you can help me with it when you get a chance please?

cheers
mossy1881 is offline  
Old 06-29-2008, 08:42 AM   #4 (permalink)
Commander Super Mod Joker
 
Mak213's Avatar
 
Join Date: Sep 2004
Location: In Trotter's crawl space
Posts: 14,352
Default Re: virtumonde virus HJT log..please help [P]

Hello Mossy,

Post your Log. I will evaluate it and give you the appropiate action ASAP after the log gets posted.

Cheers,
Mak
__________________


Mak213 is offline  
Old 06-29-2008, 10:28 AM   #5 (permalink)
True Techie
 
Join Date: Jun 2008
Posts: 137
Default Re: virtumonde virus HJT log..please help [P]

I tried shutting off windows firewall by selecting the off option but it is staying on, how do I turn it off? Without shutting this service off I can not run combofix.exe. Can someone please help me.

cheers

Last edited by mossy1881; 06-29-2008 at 11:19 AM.
mossy1881 is offline  
Old 06-29-2008, 01:58 PM   #6 (permalink)
Super Techie
 
Join Date: Aug 2007
Posts: 457
Default Re: virtumonde virus HJT log..please help [P]

What do you mean you can't 'run it'? What error does it give you?

Does Windows Firewall specifically say it blocked it?
Formerly the latter is offline  
Old 06-29-2008, 02:04 PM   #7 (permalink)
True Techie
 
Join Date: Jun 2008
Posts: 137
Default Re: virtumonde virus HJT log..please help [P]

I can't shut it down no matter what I try. If I leave it as is combofix will not run it just hangs. Any ideas why? I assume firewall is the issue.
mossy1881 is offline  
Old 06-29-2008, 03:41 PM   #8 (permalink)
Super Techie
 
Join Date: Aug 2007
Posts: 457
Default Re: virtumonde virus HJT log..please help [P]

Please delete that copy, and download a new version.
Formerly the latter is offline  
Old 06-29-2008, 04:13 PM   #9 (permalink)
True Techie
 
Join Date: Jun 2008
Posts: 137
Default Re: virtumonde virus HJT log..please help [P]

Quote:
Originally Posted by techpro5238 View Post
Please delete that copy, and download a new version.
I've tried 3 different ones. Please let me know when you have some time so we can go back and forth with questions and answers, please.

Cheers
mossy1881 is offline  
Old 06-29-2008, 09:23 PM   #10 (permalink)
Commander Super Mod Joker
 
Mak213's Avatar
 
Join Date: Sep 2004
Location: In Trotter's crawl space
Posts: 14,352
Default Re: virtumonde virus HJT log..please help [P]

Hello,

Windows firewall should not have to be disabled to run this. This goes beyond my knowledge of malware removal. Can try over at GTG (GeeksToGo) or format and reinstall as you have already suggested yourself.

Cheers,
Mak
__________________


Mak213 is offline  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Slow PC HJT Log for the heck of it.. [F] Peter.Cort HijackThis Logs (finished) 11 06-23-2008 04:13 PM
A sneaky, and annoying virus donaldj HijackThis Logs (finished) 25 06-16-2008 07:58 PM
HJT Log. Internet Issues Lukey114 HijackThis Logs (finished) 4 04-16-2008 08:02 AM
HJT log from a business computer cwr89 HijackThis Logs (finished) 7 02-15-2008 07:22 PM
HJT Log. Lukey114 HijackThis Logs (finished) 20 12-20-2007 05:49 AM


All times are GMT -5. The time now is 04:16 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0