Hello,
I have been hit by Winfixer Trojan couple days ago. I used VundoFix and VirtumundoBeGone to clean it. However, when I checked my system with SUPERAntiSpyware, it still found infections of Winfixer and cleaned it. When I ran SUPERAntiSpyware again, it found same infections again.
Please find below my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 10:51:17, on 2007/10/26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\mqrgsh.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Microsoft] mqrgsh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [3c5fbd0f] rundll32.exe "C:\WINDOWS\system32\eqecngwi.dll",b
O4 - HKLM\..\RunServices: [Microsoft] mqrgsh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1191931315218
O20 - AppInit_DLLs: at.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod 服務 (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 8011 bytes
And below is the log generated by VirtumundoBeGone:
[10/26/2007, 2:14:47] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 2:15:09] - Detected System Information:
[10/26/2007, 2:15:09] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 2:15:09] - Current Username: RICKYLEE (Admin)
[10/26/2007, 2:15:09] - Windows is in SAFE mode with Networking.
[10/26/2007, 2:15:09] - Searching for Browser Helper Objects:
[10/26/2007, 2:15:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:09] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:09] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:09] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:09] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:09] - BHO 5: {F6B1F430-52B5-4478-9FC6-A94F79D423C3} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\yayyxyx
[10/26/2007, 2:15:09] - Found: HKLM\...\Winlogon\Notify\yayyxyx - This is probably Virtumundo.
[10/26/2007, 2:15:09] - Assigning {F6B1F430-52B5-4478-9FC6-A94F79D423C3} MSEvents Object
[10/26/2007, 2:15:09] - BHO list has been changed! Starting over...
[10/26/2007, 2:15:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:09] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:09] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:09] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:09] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:09] - BHO 5: {F6B1F430-52B5-4478-9FC6-A94F79D423C3} (MSEvents Object)
[10/26/2007, 2:15:09] - ALERT: Found MSEvents Object!
[10/26/2007, 2:15:09] - Finished Searching Browser Helper Objects
[10/26/2007, 2:15:09] - *** Detected MSEvents Object
[10/26/2007, 2:15:09] - Trying to remove MSEvents Object...
[10/26/2007, 2:15:10] - Terminating Process: IEXPLORE.EXE
[10/26/2007, 2:15:10] - Terminating Process: RUNDLL32.EXE
[10/26/2007, 2:15:10] - Disabling Automatic Shell Restart
[10/26/2007, 2:15:10] - Terminating Process: EXPLORER.EXE
[10/26/2007, 2:15:10] - Suspending the NT Session Manager System Service
[10/26/2007, 2:15:10] - Terminating Windows NT Logon/Logoff Manager
[10/26/2007, 2:15:11] - Re-enabling Automatic Shell Restart
[10/26/2007, 2:15:11] - File to disable: C:\WINDOWS\system32\yayyxyx.dll
[10/26/2007, 2:15:11] - Renaming C:\WINDOWS\system32\yayyxyx.dll -> C:\WINDOWS\system32\yayyxyx.dll.vir
[10/26/2007, 2:15:11] - File successfully renamed!
[10/26/2007, 2:15:11] - Removing HKLM\...\Browser Helper Objects\{F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Removing HKCR\CLSID\{F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Adding Kill Bit for ActiveX for GUID: {F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Deleting ATLEvents/MSEvents Registry entries
[10/26/2007, 2:15:11] - Removing HKLM\...\Winlogon\Notify\yayyxyx
[10/26/2007, 2:15:11] - Searching for Browser Helper Objects:
[10/26/2007, 2:15:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:11] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:11] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:11] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:11] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:11] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:11] - Finished Searching Browser Helper Objects
[10/26/2007, 2:15:11] - Finishing up...
[10/26/2007, 2:15:11] - A restart is needed.
[10/26/2007, 2:15:20] - Attempting to Restart via STOP error (Blue Screen!)
[10/26/2007, 22:39:36] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 22:39:42] - Detected System Information:
[10/26/2007, 22:39:42] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 22:39:42] - Current Username: RICKYLEE (Admin)
[10/26/2007, 22:39:42] - Windows is in SAFE mode with Networking.
[10/26/2007, 22:39:42] - Searching for Browser Helper Objects:
[10/26/2007, 22:39:42] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 22:39:42] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 22:39:42] - BHO 3: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 22:39:42] - Finished Searching Browser Helper Objects
[10/26/2007, 22:39:42] - Finishing up...
[10/26/2007, 22:39:42] - Nothing found! Exiting...
[10/26/2007, 22:47:34] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 22:47:36] - Detected System Information:
[10/26/2007, 22:47:36] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 22:47:36] - Current Username: RICKYLEE (Admin)
[10/26/2007, 22:47:36] - Windows is in SAFE mode with Networking.
[10/26/2007, 22:47:36] - Searching for Browser Helper Objects:
[10/26/2007, 22:47:36] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 22:47:36] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 22:47:36] - BHO 3: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 22:47:36] - Finished Searching Browser Helper Objects
[10/26/2007, 22:47:36] - Finishing up...
[10/26/2007, 22:47:36] - Nothing found! Exiting...
I would appreciate if someone can advise me if I have removed the Trojan.
Thanks in advance for your help.
Best regards,
Rickronn
I have been hit by Winfixer Trojan couple days ago. I used VundoFix and VirtumundoBeGone to clean it. However, when I checked my system with SUPERAntiSpyware, it still found infections of Winfixer and cleaned it. When I ran SUPERAntiSpyware again, it found same infections again.
Please find below my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 10:51:17, on 2007/10/26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\mqrgsh.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Microsoft] mqrgsh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [3c5fbd0f] rundll32.exe "C:\WINDOWS\system32\eqecngwi.dll",b
O4 - HKLM\..\RunServices: [Microsoft] mqrgsh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1191931315218
O20 - AppInit_DLLs: at.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod 服務 (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 8011 bytes
And below is the log generated by VirtumundoBeGone:
[10/26/2007, 2:14:47] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 2:15:09] - Detected System Information:
[10/26/2007, 2:15:09] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 2:15:09] - Current Username: RICKYLEE (Admin)
[10/26/2007, 2:15:09] - Windows is in SAFE mode with Networking.
[10/26/2007, 2:15:09] - Searching for Browser Helper Objects:
[10/26/2007, 2:15:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:09] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:09] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:09] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:09] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:09] - BHO 5: {F6B1F430-52B5-4478-9FC6-A94F79D423C3} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\yayyxyx
[10/26/2007, 2:15:09] - Found: HKLM\...\Winlogon\Notify\yayyxyx - This is probably Virtumundo.
[10/26/2007, 2:15:09] - Assigning {F6B1F430-52B5-4478-9FC6-A94F79D423C3} MSEvents Object
[10/26/2007, 2:15:09] - BHO list has been changed! Starting over...
[10/26/2007, 2:15:09] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:09] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:09] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:09] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:09] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:09] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:09] - BHO 5: {F6B1F430-52B5-4478-9FC6-A94F79D423C3} (MSEvents Object)
[10/26/2007, 2:15:09] - ALERT: Found MSEvents Object!
[10/26/2007, 2:15:09] - Finished Searching Browser Helper Objects
[10/26/2007, 2:15:09] - *** Detected MSEvents Object
[10/26/2007, 2:15:09] - Trying to remove MSEvents Object...
[10/26/2007, 2:15:10] - Terminating Process: IEXPLORE.EXE
[10/26/2007, 2:15:10] - Terminating Process: RUNDLL32.EXE
[10/26/2007, 2:15:10] - Disabling Automatic Shell Restart
[10/26/2007, 2:15:10] - Terminating Process: EXPLORER.EXE
[10/26/2007, 2:15:10] - Suspending the NT Session Manager System Service
[10/26/2007, 2:15:10] - Terminating Windows NT Logon/Logoff Manager
[10/26/2007, 2:15:11] - Re-enabling Automatic Shell Restart
[10/26/2007, 2:15:11] - File to disable: C:\WINDOWS\system32\yayyxyx.dll
[10/26/2007, 2:15:11] - Renaming C:\WINDOWS\system32\yayyxyx.dll -> C:\WINDOWS\system32\yayyxyx.dll.vir
[10/26/2007, 2:15:11] - File successfully renamed!
[10/26/2007, 2:15:11] - Removing HKLM\...\Browser Helper Objects\{F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Removing HKCR\CLSID\{F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Adding Kill Bit for ActiveX for GUID: {F6B1F430-52B5-4478-9FC6-A94F79D423C3}
[10/26/2007, 2:15:11] - Deleting ATLEvents/MSEvents Registry entries
[10/26/2007, 2:15:11] - Removing HKLM\...\Winlogon\Notify\yayyxyx
[10/26/2007, 2:15:11] - Searching for Browser Helper Objects:
[10/26/2007, 2:15:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 2:15:11] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 2:15:11] - BHO 3: {9E506E70-80C2-4266-961C-AB51B8C933D6} ()
[10/26/2007, 2:15:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/26/2007, 2:15:11] - Checking for HKLM\...\Winlogon\Notify\ssttt
[10/26/2007, 2:15:11] - Key not found: HKLM\...\Winlogon\Notify\ssttt, continuing.
[10/26/2007, 2:15:11] - BHO 4: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 2:15:11] - Finished Searching Browser Helper Objects
[10/26/2007, 2:15:11] - Finishing up...
[10/26/2007, 2:15:11] - A restart is needed.
[10/26/2007, 2:15:20] - Attempting to Restart via STOP error (Blue Screen!)
[10/26/2007, 22:39:36] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 22:39:42] - Detected System Information:
[10/26/2007, 22:39:42] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 22:39:42] - Current Username: RICKYLEE (Admin)
[10/26/2007, 22:39:42] - Windows is in SAFE mode with Networking.
[10/26/2007, 22:39:42] - Searching for Browser Helper Objects:
[10/26/2007, 22:39:42] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 22:39:42] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 22:39:42] - BHO 3: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 22:39:42] - Finished Searching Browser Helper Objects
[10/26/2007, 22:39:42] - Finishing up...
[10/26/2007, 22:39:42] - Nothing found! Exiting...
[10/26/2007, 22:47:34] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RICKYLEE\桌面\VirtumundoBeGone.exe" )
[10/26/2007, 22:47:36] - Detected System Information:
[10/26/2007, 22:47:36] - Windows Version: 5.1.2600, Service Pack 2
[10/26/2007, 22:47:36] - Current Username: RICKYLEE (Admin)
[10/26/2007, 22:47:36] - Windows is in SAFE mode with Networking.
[10/26/2007, 22:47:36] - Searching for Browser Helper Objects:
[10/26/2007, 22:47:36] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[10/26/2007, 22:47:36] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/26/2007, 22:47:36] - BHO 3: {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper)
[10/26/2007, 22:47:36] - Finished Searching Browser Helper Objects
[10/26/2007, 22:47:36] - Finishing up...
[10/26/2007, 22:47:36] - Nothing found! Exiting...
I would appreciate if someone can advise me if I have removed the Trojan.
Thanks in advance for your help.
Best regards,
Rickronn