Other > Viruses and worms
two viruses i can not get rid of Help plz
(1/3) > >>
LEGSAKIMBO:
hi  i have got two virus,s i can not get rid of =WIN32:Virtumonde-CI  and  WIN32:Small-IAK
 I Have googled it but not come up with much, run most of the virus scans with no luck ...
any body shine some light on these virus,es... getting very close to for-mat...lol..
 here,s the log=
Logfile of HijackThis v1.99.1
Scan saved at 22:44:10, on 30/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\Mz16r\Mz16r2291.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\tsitra1000106.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Roger\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {C8B5CE99-4C3A-4006-8D12-D9A3CE973918} - C:\Program Files\Online Services\tedolusC:\WINDOWS\system32\m2\caws83122.exe.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [b5700x drive] C:\WINDOWS\cnssr.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Adobe LAN] C:\WINDOWS\system32\adobelan.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193326380156
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

cheers   rog!. 8)
DavidR:
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ? 
Check the avast! Log Viewer (right click the avast 'a' icon), Warning section, this contains information on all avast detections. Possibly the ones I've mentioned below.

Why can't you get rid of them ?
What error messages, file in use, etc. ?

Try this, Vundo Fix Tool - Aliases - WinFixer / Virtumonde / Msevents / Trojan.vundo.
Here are the cleansing instructions for Virtumonde (download link in the instructions): http://www.bleepingcomputer.com/forums/topic18610.html

You don't appear to have an active firewall, what is your firewall ?
It should be capable of blocking unauthorised outbound Internet Connections.

There is a later version of HJT, FileHippo Download - HiJackThis.

Suspect, check and fix as required:
C:\WINDOWS\system32\Mz16r\Mz16r2291.exe
C:\WINDOWS\tsitra1000106.exe
O4 - HKLM\..\Run: [b5700x drive] C:\WINDOWS\cnssr.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

- Upload the files in bold to VirusTotal (VT) - Multi engine on-line virus scanner and report the findings of these files here. If any are detected by multiple scanners send example to avast if avast isn't detecting them, see below.

Fix:
O2 - BHO: (no name) - {C8B5CE99-4C3A-4006-8D12-D9A3CE973918} - C:\Program Files\Online Services\tedolusC:\WINDOWS\system32\m2\caws83122.exe.dll (file missing)
First check if this file really has gone, if not upload and check at VT also.

####
Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
####
oldman:
Besides doing what DavidR has posted and answering his questions, you can try this with superantispyware, it's had some luck lately with vundo.


First update SAS Then

Under Configuration and Preferences, click the Preferences button.
Then click the Scanning Control tab.

Under Scanner Options make sure the following are checked
- Close browsers before scanning
- Scan for tracking cookies
- Terminate memory threats before quaranine.

 leave the others unchecked.

Return to the main page by clicking close on that screen. On the main screen, under Scan for Harmful Software click Scan your computer. On the left check C:\Fixed Drive.(and other fixed drives)
Under Complete Scan, choose Perform Complete Scan.
ยท Click Next to start the scan.

When the scan is done, quaretine everthing found . Reboot if asked. You can post the log in your next reply if you wish.
 
LEGSAKIMBO:
hi gents thanks for your quick reply.
yes i have the windows firewall but at the time of log the virus switches it off.
chain of events
sw/ on boot avast finds-avast stops connection -go,s to blue screen of death.
re-boot avast finds win32:smalHAK-avast aborts connection-then win32:virtumonde-ci-then win32:Maha-i -firewall is s/w off by virus.
avast finds ask to delet dose the job ,but on boot up ..round it go,s again.

007 09:46:06   Roger   1492   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
30/10/2007 09:47:17   Roger   1492   Sign of "Win32:Maha-I [trj]" has been found in "C:\WINDOWS\sqlserver.dll" file. 
30/10/2007 09:47:18   Roger   1492   Sign of "Win32:Maha-I [trj]" has been found in "C:\WINDOWS\sqlserver.dll" file. 
30/10/2007 09:47:47   Roger   1492   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
30/10/2007 09:48:03   Roger   1492   Sign of "Win32:Virtumonde-CI [Adw]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/is68197.exe" file. 
30/10/2007 10:14:06   Roger   1492   Sign of "Win32:Virut" has been found in "E:\SYSTEM VOLUME INFORMATION\_RESTORE{CA9B3162-A347-465B-9631-00F03047C931}\RP22\A0001306.EXE\[PECompact]" file. 
30/10/2007 10:32:11   Roger   1528   Sign of "Win32:Maha-I [trj]" has been found in "C:\WINDOWS\sqlserver.dll" file. 
30/10/2007 10:32:21   Roger   1528   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
 10:44:40   Roger   1500   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
30/10/2007 10:44:45   Roger   1500   Sign of "Win32:Virtumonde-CI [Adw]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/is68197.exe" file. 
2:19:21   SYSTEM   1548   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
30/10/2007 22:19:54   SYSTEM   1548   Sign of "Win32:Virtumonde-CI [Adw]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/is68197.exe" file. 
30/10/2007 22:20:06   SYSTEM   1548   Sign of "Win32:Maha-I [trj]" has been found in "C:\WINDOWS\sqlserver.dll" file. 
30/10/2007 22:20:12   SYSTEM   1548   Sign of "Win32:Trojano-2873 [trj]" has been found in "C:\WINDOWS\system32\w5\rarndrll2.exe" file. 
30/10/2007 22:20:14   SYSTEM   1548   Sign of "Win32:Adloader-KH [trj]" has been found in "C:\Program Files\TTC.dll" file. 
31/10/2007 08:04:59   SYSTEM   1500   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
31/10/2007 08:06:53   SYSTEM   1488   Sign of "Win32:Small-IAK [trj]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/wr-1-312.exe\[UPX]" file. 
31/10/2007 08:07:49   SYSTEM   1488   Sign of "Win32:Virtumonde-CI [Adw]" has been found in "http://www.brokawelectronics.com/h0lygamer/downloads/is68197.exe" file. 
31/10/2007 08:08:10   SYSTEM   1488   Sign of "Win32:Maha-I [trj]" has been found in "C:\WINDOWS\sqlserver.dll" file. 

ok just about to do your instuctions...
thanks again.rog
DavidR:
Even if the XP firewall was enabled it would provide little protection against what is happening as it provides zero outbound protection and something on your system is trying to download more malware and avast's Web Shield is blocking that.

Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential and in your case very urgently required.

- There are many freeware firewalls such as, Comodo, PCTools Firewall Plus, Jetico, etc.

If you haven't already got SAS, or run VundoFix, act soon SUPERantispyware.

You have to get motivated and check out those files at virustotal (VT) quickly and if confirmed as malware run HJT again and fix the entries as one or more could be responsible for the attempted downloads.
Navigation
Message Index
Next page

Go to full version