Travel Fans
Go Back   Computer Juice Computer Software Virus, Spyware & Security

Register

 Default 

I beleive I have the Vundo or virtumond malware virus and cant shift it.




Reply
 
Thread Tools
  #11  
Old 4th Dec 2008, 01:22
Donor VIP
Posts: 8
 
Ok that one worked here is the log,


;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-12-04 08:19:10
PROTECTIONS: 1
MALWARE: 25
SUSPECTS: 4
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1296 [VPS 081203-0] 4.8.1296 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00029434 spyware/virtumonde Spyware No 1 Yes No c:\windows\system32\appsetup.exe
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@atdmt[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@mediaplex[2].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@statcounter[2].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@ad.yieldmanager[2].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@apmebf[2].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@bs.serving-sys[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@advertising[2].txt
00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@media.adrevolver[3].txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@statse.webtrendslive[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@overture[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@questionmarket[2].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@zedo[2].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@adrevolver[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@adviva[1].txt
00293517 Cookie/AdDynamix TrackingCookie No 0 Yes No C:\Documents and Settings\Colin Austin\Cookies\colin_austin@ads.addynamix[2].txt
01048936 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
01075773 Generic Trojan Virus/Trojan No 0 Yes No C:\Program Files\a-squared Free\Quarantine\a2quarantine.tmp[program files/bit lord 1.1/Downloads/#1 DVD Ripper 4.2 + key gen/#1 DVD Ripper 4.2 + key gen/keygen.exe]
01075773 Generic Trojan Virus/Trojan No 0 Yes No C:\Program Files\Bit Lord 1.1\Downloads\#1 DVD Ripper 4.2 + key gen\#1 DVD Ripper 4.2 + key gen\keygen.exe
02886685 W32/Sdbot.LMG.worm Virus/Trojan No 1 No No C:\Documents and Settings\Colin Austin\My Documents\Downloads\MagicISO Maker 5.4 + Serial - oFFiCaL\MagicISO Maker 5.4 + Serial\Magic ISO Maker 5.4 Build 239.exe[C:\Documents and Settings\Colin Austin\My Documents\Downloads\MagicISO Maker 5.4 + Serial - oFFiCaL\MagicISO Maker 5.4 + Serial\Magic ISO Maker 5.4 Build 239.exe][themida.exe]
03755584 Generic Malware Virus/Trojan No 0 Yes No C:\i386\GTDownDE_87.ocx
03755584 Generic Malware Virus/Trojan No 0 Yes No C:\WINDOWS\system32\GTDownDE_87.ocx
03919060 Generic Malware Virus/Trojan No 0 Yes No C:\internet downloads\no cd hacks\splinter cell chaos theory\SPLINTER.CELL.CHAOS.THEORY.ALL.SADUHORA.NOCD\sfcure.zip[SFAFSB.exe]
03919060 Generic Malware Virus/Trojan No 0 Yes No C:\internet downloads\no cd hacks\splinter cell chaos theory\sfcure.zip[SFAFSB.exe]
03919060 Generic Malware Virus/Trojan No 0 Yes No C:\internet downloads\no cd hacks\splinter cell chaos theory\SPLINTER.CELL.CHAOS.THEORY.ALL.SADUHORA.NOCD.ZIP[sfcure.zip][SFAFSB.exe]
;===================================================================================================================================================================================
SUSPECTS
Sent Location ŭ
;===================================================================================================================================================================================
No C:\Documents and Settings\Colin Austin\Desktop\Applications\SmitfraudFix\404Fix.exe ŭ
No C:\internet downloads\no cd hacks\splinter cell chaos theory\sfdrvrem.zip[sfdrvrem.exe] ŭ
No C:\internet downloads\no cd hacks\splinter cell chaos theory\SPLINTER.CELL.CHAOS.THEORY.ALL.SADUHORA.NOCD\sfdrvrem.zip[sfdrvrem.exe]
No C:\internet downloads\no cd hacks\splinter cell chaos theory\SPLINTER.CELL.CHAOS.THEORY.ALL.SADUHORA.NOCD.ZIP[sfdrvrem.zip][sfdrvrem.exe]
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description ŭ
;===================================================================================================================================================================================
;===================================================================================================================================================================================

  #12  
Old 4th Dec 2008, 12:08
Moderator
Posts: 7,545
 
* Double-click OTMoveIt3.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code:
:Processes
explorer.exe

:files
c:\windows\system32\appsetup.exe
C:\Program Files\Bit Lord 1.1\Downloads\#1 DVD Ripper 4.2 + key gen
C:\Documents and Settings\Colin Austin\My Documents\Downloads\MagicISO Maker 5.4 + Serial - oFFiCaL
C:\internet downloads\no cd hacks\splinter cell chaos theory
C:\Documents and Settings\Colin Austin\Desktop\Applications\SmitfraudFix

:Commands
[emptytemp]
[start explorer]
[Reboot]
* Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

How is the computer running now?
__________________

  #13  
Old 4th Dec 2008, 13:26
Donor VIP
Posts: 8
 
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
c:\windows\system32\AppSetup.exe moved successfully.
C:\Program Files\Bit Lord 1.1\Downloads\#1 DVD Ripper 4.2 + key gen\#1 DVD Ripper 4.2 + key gen moved successfully.
C:\Program Files\Bit Lord 1.1\Downloads\#1 DVD Ripper 4.2 + key gen moved successfully.
C:\Documents and Settings\Colin Austin\My Documents\Downloads\MagicISO Maker 5.4 + Serial - oFFiCaL\MagicISO Maker 5.4 + Serial moved successfully.
C:\Documents and Settings\Colin Austin\My Documents\Downloads\MagicISO Maker 5.4 + Serial - oFFiCaL moved successfully.
C:\internet downloads\no cd hacks\splinter cell chaos theory\SPLINTER.CELL.CHAOS.THEORY.ALL.SADUHORA.NOCD moved successfully.
C:\internet downloads\no cd hacks\splinter cell chaos theory moved successfully.
C:\Documents and Settings\Colin Austin\Desktop\Applications\SmitfraudFix moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\COLINA~1\LOCALS~1\Temp\~DF4EC2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\COLINA~1\LOCALS~1\Temp\~DF4ED8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_478.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5e8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12042008_201924
Files moved on Reboot...
File C:\DOCUME~1\COLINA~1\LOCALS~1\Temp\~DF4EC2.tmp not found!
File C:\DOCUME~1\COLINA~1\LOCALS~1\Temp\~DF4ED8.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_478.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_5e8.dat not found!

My computer seems to be running just fine now, however I am obviously still a little worried about these things that keep cropping up on scans.
  #14  
Old 4th Dec 2008, 14:46
Moderator
Posts: 7,545
 
Time to do some cleanup and secure the work you have done.
  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
----------

1. Double click OTMoveIt3.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt3 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
  • When finished exit out of OTMoveIt3


How is the computer running now?
__________________

  #15  
Old 5th Dec 2008, 13:18
Donor VIP
Posts: 8
 
Hi I thought i'd already responded to your last post so if it doubles up I aplogise. My computer does seem to be running a lot better now.
  #16  
Old 5th Dec 2008, 13:52
Moderator
Posts: 7,545
 
Sounds good.

Here are a few suggestions.

Use the Secunia Software Inspector to check for out of date software.
Out of date software has security vulnerabilities that malware can exploit.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

Make sure all of your security programs are up to date and run scans with them regularly.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

To prevent unknown applications from being installed on your computer install WinPatrol
* Using Winpatrol to protect your computer from malicious software

I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself safe On The Web for tips and free tools to keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
__________________

Reply

Register

Similar Threads
Thread Thread Starter Forum Replies Last Post
Is It a Cracker, Hacker or Virus/Malware? yuhr Virus, Spyware & Security 29 26th Oct 2009 15:03
I Can't Get Rid of the Troojan.Vundo.H Virus No Matter What I Do Drhunter2k Virus, Spyware & Security 8 26th Mar 2009 08:38
Vundo virus has altered things!! Terrano11 Virus, Spyware & Security 1 17th Jul 2008 13:07
Help with a malware/virus winspywareprotect badproduce Virus, Spyware & Security 8 12th Jun 2008 13:28
Crazy odd freez, is it malware/virus? bmdkafae Virus, Spyware & Security 3 29th Jan 2008 14:05
Thread Tools



Translations Powered by Powered by Google
Arabic Bulgarian Chinese Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Taiwanese Thai Turkish Ukrainian

Copyright ©2006 - 2010 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2010 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.