IPB

Welcome Guest ( Log In | Register )

 
Closed TopicStart new topic
> Possible Virtumonde Infection, Computer running slow
Lesha
post Aug 16 2008, 08:38 PM
Post #1


Newbie Member
*

Group: Member
Posts: 2
Joined: 16-August 08
From: Louisiana
Member No.: 1,166



I am not sure what is going on with the computer. I had Win.Win32.Netbooster virus earlier this week. I downloaded and installed Malewarebytes' Antimalware software and it removed it, supposedly! I also downloaded superanti SPyware and have used it a few times. When someone gets a chance, will you please look at my log and let me know what is wrong? In advance, I do thank you for your time and effort.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:29:34 PM, on 8/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Century Rehab\Desktop\LESHA\HJT\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O15 - Trusted Zone: http://www.java.com
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - Unknown owner - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (file missing)
O23 - Service: hpqwmiex - Unknown owner - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - Unknown owner - C:\Program Files\PDF Complete\pdfsvc.exe (file missing)

--
End of file - 3464 bytes
unsure.gif
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 18 2008, 12:21 AM
Post #2


Multi Megaton Malware Munition
Group Icon

Group: Global Moderator
Posts: 404
Joined: 21-June 08
From: Northfield, Ohio
Member No.: 1,092



Hello, Lesha.
welcome.gif to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)
Please give me some time to look over your computer's log(s).
Please take note of the following:
  • In the meantime, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. smile.gif
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Finally, please reply using the button in the lower left hand corner of your screen.


I don't see any malware in that log, but I would like to take a closer look at what's going on:

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  1. Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  2. Scroll down to where it says "Java Runtime Environment (JRE)6 Update 7...allows end-users to run Java applications".
  3. Click the "Download" button to the right.
  4. Select your Platform: "Windows".
  5. Select your Language: "Multi-Language".
  6. Read the License Agreement, and then check the box that says: "Accept License Agreement".
  7. Click Continue and the page will refresh.
  8. Click on the link to download Windows Offline Installation and save the file to your desktop.
  9. Close any programs you may have running - especially your web browser.
  10. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  11. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  12. Click the Remove or Change/Remove button.
  13. Follow the onscreen instructions for the Java uninstaller.
  14. Repeat as many times as necessary to remove each Java version.
  15. Reboot your computer once all Java components are removed.
  16. Then from your desktop double-click on jre-6u7-windows-i586-p.exe
  17. Follow the on screen instructions to install the latest Java version.


We need to run OTScanIt
Before running a new scan let's clean out the temporary folders.
Download ATF Cleaner to your Desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Close ALL Internet browsers (very important).
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
      Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
  • Save the file to your desktop or other location where you can find it back.

Use the Add Reply button and attach the file in your next post.

In your next reply, please include the following:
  • OTScanIt report

Billy3
Go to the top of the page
 
+Quote Post
Lesha
post Aug 19 2008, 03:16 AM
Post #3


Newbie Member
*

Group: Member
Posts: 2
Joined: 16-August 08
From: Louisiana
Member No.: 1,166



Billy

Thank you for your patience. Below is a link to the report you requested. Please let me know if there is anything else you need me to do.
Thanks


OTScanIt Report
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 19 2008, 05:40 AM
Post #4


Multi Megaton Malware Munition
Group Icon

Group: Global Moderator
Posts: 404
Joined: 21-June 08
From: Northfield, Ohio
Member No.: 1,092



That doesn't appear to be working right now. Can you re-scan and paste the report here instead of attaching it?

Billy3
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 24 2008, 04:24 AM
Post #5


Multi Megaton Malware Munition
Group Icon

Group: Global Moderator
Posts: 404
Joined: 21-June 08
From: Northfield, Ohio
Member No.: 1,092



This thread is being closed due to inactivity. If you would like it to be reopened please contact me or another member of the Moderating Team.

As always, we thank you for using 247fixes. Thank you, and have a great day!
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:


Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts  
9 Desperate 1,386 21st September 2005 - 10:11 PM
Last post by: therock247uk
No New Posts  
0 Chachazz 728 9th November 2005 - 12:40 AM
Last post by: Chachazz
No New Posts  
2 Brothas 913 18th December 2005 - 07:59 AM
Last post by: sin247nm
No New Posts  
5 wbhatch 936 14th January 2006 - 03:26 AM
Last post by: sin247nm
No New Posts  
11 yaboonst 1,967 16th July 2006 - 03:45 AM
Last post by: therock247uk


 



Add to Google Subscribe in Bloglines Lo-Fi Version Time is now: 21st November 2008 - 07:42 PM