Help - Search - Members - Calendar
Full Version: i've been infected by Virtumonde
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
jensmm
Hey !
I posted a topic here a day ago and i just realised i misspelled .. i'm infected with the virtumonde trojan/bug...please help...removed it with ad aware, my mcaffe deteceted and deleted it but at every starup it wants to load gebcy.exe and a g....dll

Please help
Here's the hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:41:14, on 25.01.2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\McAfee\Common Framework\UdaterUI .exe
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F3 - REG:win.ini: load=C:\Windows\system32\gebcy.exe
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Taskmanager] svchost.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\gebcb.dll,#1
O4 - HKLM\..\Run: [3003adf3] rundll32.exe "C:\Windows\system32\pyodttgy.dll",b
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe

--
End of file - 6118 bytes
bamajim
jensmm

Sorry for the delay.

I see you have run VundoFix. Could you please post the results of the C:\Vundofix.txt log.
jensmm
Hi, thank you very much for your reply..heres the log you demanded... i removed what it found but it couldn't delete everything gebcy.dll or something. so i wanted to scan again but the laptop just shutdown...so anyways here's the log:


VundoFix V6.7.7

Checking Java version...

Scan started at 19:56:31 25.01.2008

Listing files found while scanning....

C:\Windows\System32\aowjgwbv.dll
C:\Windows\System32\awvvu.dll
C:\Windows\System32\bpujnmsg.dll
C:\Windows\System32\dctgyuxf.dll
C:\Windows\System32\fcbzkoru.dll
C:\windows\System32\fcbzkoru.dllbox
C:\Windows\System32\gbwlcixp.dll
C:\windows\System32\gbwlcixp.dllbox
C:\Windows\System32\gebcy.dll
C:\Windows\System32\hggfccb.dll
C:\Windows\System32\hgggggf.dll
C:\Windows\System32\mlljh.dll
C:\Windows\System32\nrqmrrre.dll
C:\windows\System32\nrqmrrre.dllbox
C:\Windows\System32\pyodttgy.dll
C:\Windows\System32\qikrffdx.dll
C:\Windows\System32\rqrrpnl.dll
C:\windows\System32\uvvwa.ini
C:\windows\System32\uvvwa.ini2
C:\Windows\System32\vjkynsox.dll
C:\Windows\System32\xaelojsg.dll
C:\Windows\System32\xdffrkiq.ini
C:\Windows\System32\xquebvtv.dll
C:\windows\System32\ycbeg.ini
C:\windows\System32\ycbeg.ini2
C:\Windows\System32\ygttdoyp.ini

Beginning removal...

Beginning removal...

Attempting to delete C:\Windows\System32\aowjgwbv.dll
C:\Windows\System32\aowjgwbv.dll Has been deleted!

Attempting to delete C:\Windows\System32\awvvu.dll
C:\Windows\System32\awvvu.dll Has been deleted!

Attempting to delete C:\Windows\System32\bpujnmsg.dll
C:\Windows\System32\bpujnmsg.dll Has been deleted!

Attempting to delete C:\Windows\System32\dctgyuxf.dll
C:\Windows\System32\dctgyuxf.dll Has been deleted!

Attempting to delete C:\Windows\System32\fcbzkoru.dll
C:\Windows\System32\fcbzkoru.dll Has been deleted!

Attempting to delete C:\windows\System32\fcbzkoru.dllbox
C:\windows\System32\fcbzkoru.dllbox Has been deleted!

Attempting to delete C:\Windows\System32\gbwlcixp.dll
C:\Windows\System32\gbwlcixp.dll Has been deleted!

Attempting to delete C:\windows\System32\gbwlcixp.dllbox
C:\windows\System32\gbwlcixp.dllbox Has been deleted!

Attempting to delete C:\Windows\System32\gebcy.dll
C:\Windows\System32\gebcy.dll Could not be deleted.

Attempting to delete C:\Windows\System32\hggfccb.dll
C:\Windows\System32\hggfccb.dll Has been deleted!

Attempting to delete C:\Windows\System32\hgggggf.dll
C:\Windows\System32\hgggggf.dll Has been deleted!

Attempting to delete C:\Windows\System32\mlljh.dll
C:\Windows\System32\mlljh.dll Has been deleted!

Attempting to delete C:\Windows\System32\nrqmrrre.dll
C:\Windows\System32\nrqmrrre.dll Has been deleted!

Attempting to delete C:\windows\System32\nrqmrrre.dllbox
C:\windows\System32\nrqmrrre.dllbox Has been deleted!

Attempting to delete C:\Windows\System32\qikrffdx.dll
C:\Windows\System32\qikrffdx.dll Has been deleted!

Attempting to delete C:\Windows\System32\rqrrpnl.dll
C:\Windows\System32\rqrrpnl.dll Has been deleted!

Attempting to delete C:\windows\System32\uvvwa.ini
C:\windows\System32\uvvwa.ini Has been deleted!

Attempting to delete C:\windows\System32\uvvwa.ini2
C:\windows\System32\uvvwa.ini2 Has been deleted!

Attempting to delete C:\Windows\System32\vjkynsox.dll
C:\Windows\System32\vjkynsox.dll Has been deleted!

Attempting to delete C:\Windows\System32\xaelojsg.dll
C:\Windows\System32\xaelojsg.dll Has been deleted!

Attempting to delete C:\Windows\System32\xdffrkiq.ini
C:\Windows\System32\xdffrkiq.ini Has been deleted!

Attempting to delete C:\Windows\System32\xquebvtv.dll
C:\Windows\System32\xquebvtv.dll Has been deleted!

Attempting to delete C:\windows\System32\ycbeg.ini
C:\windows\System32\ycbeg.ini Has been deleted!

Attempting to delete C:\windows\System32\ycbe
VundoFix V6.7.7

Checking Java version...

Scan started at 23:36:39 29.01.2008

Listing files found while scanning....


Beginning removal...
bamajim
jensmm

Yes that particular version of Vundo can be difficult. We are going to change tactics just a little here.

1. Rerun Hijackthis (scan only) and place checks beside the following entries
    F3 - REG:win.ini: load=C:\Windows\system32\gebcy.exe
    O4 - HKLM\..\Run: [Windows Taskmanager] svchost.exe
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\gebcb.dll,#1
    O4 - HKLM\..\Run: [3003adf3] rundll32.exe "C:\Windows\system32\pyodttgy.dll",b
Close all other open windows except Hijackthis and Select "Fix checked"

Close Hijackthis ->> Reboot your PC.

2. Then Rerun Vundofix and post the results of the C:\Vundofix.txt log.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.