System:
Microsoft Windows XP Professional Version 2002
Service Pack 3
Intel® Pentium® 4
CPU 2.40 GHz
1.00 GB RAM
Other Info:
Turn off System Restore on all drives has been checked.
Symptons:
My router has to be manually reset to default everyonce in awhile due to "a page cannot be dispalyed error." The first several times it detects my connection as "static" even though under TCP/IP properties I have it set to DHCP. I also noticed that the page kept refreshing and under mozilla firefox navigation toolbar, the "X" or "stop loading this page" kept reapting while at the bottom it was saying "Done". After being very persistent and many attempts it finally detected DHCP. Another problem I notcied mozilla keeps stopping the page from being redirected. Also gmer.exe keeps crashing within several seconds of opening application. I also ran ATF Cleaner.
Hidden Object
C:\DOCUMENTS AND SETTINGS\STEVE.SLS_COMP\LOCAL SETTINGS\TEMP\RARSFX0\K643DXP.EXE
LOGS:
======================================================================
Kaspersky Anti-Virus
1/19/2010 1:15:30 PM Task started File Anti-Virus Kaspersky Anti-Virus
1/19/2010 1:28:23 PM Task started File Anti-Virus Kaspersky Anti-Virus
1/19/2010 3:55:38 PM Detected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199174.exe Generic Host Process for Win32 Services
1/19/2010 5:25:24 PM Deleted: not-a-virus:RemoteAdmin.Win32.WinVNC.4 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199174.exe Generic Host Process for Win32 Services
1/19/2010 5:25:24 PM Detected: not-a-virus:RiskTool.Win32.PsExec.123 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199175.exe Generic Host Process for Win32 Services
1/19/2010 6:22:57 PM Deleted: not-a-virus:RiskTool.Win32.PsExec.123 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199175.exe Generic Host Process for Win32 Services
1/19/2010 6:22:57 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Generic Host Process for Win32 Services
1/19/2010 6:30:00 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Skipped by user Generic Host Process for Win32 Services
1/19/2010 6:32:04 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Windows Explorer
1/19/2010 6:32:39 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Skipped by user Windows Explorer
1/19/2010 6:32:42 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Windows Explorer
1/19/2010 6:32:54 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Skipped by user Windows Explorer
1/19/2010 6:33:26 PM Detected: not-a-virus:Client-IRC.Win32.mIRC.g C:\Program Files\mIRC\mirc.exe Windows Explorer
1/19/2010 6:36:41 PM Deleted: not-a-virus:Client-IRC.Win32.mIRC.g C:\Program Files\mIRC\mirc.exe Windows Explorer
1/19/2010 6:38:19 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Windows Explorer
1/19/2010 6:38:56 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Skipped by user Windows Explorer
======================================================================
Malwarebytes' Anti-Malware 1.44
Database version: 3597
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/19/2010 2:12:27 AM
mbam-log-2010-01-19 (02-12-27).txt
Scan type: Full Scan (C:\|G:\|)
Objects scanned: 245444
Time elapsed: 49 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 23
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\huwebijum (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\yowujeje.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fefiweta.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hutoziyo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\juviyame.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yagerumu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186205.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186221.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186222.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186223.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191319.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191352.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191604.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191674.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1579\A0193853.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1589\A0196158.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1589\A0196333.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1600\A0198506.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1600\A0198742.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1601\A0198831.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1601\A0199005.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bilayupa.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fejepena.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tepepife.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
======================================================================
Microsoft Windows XP Professional Version 2002
Service Pack 3
Intel® Pentium® 4
CPU 2.40 GHz
1.00 GB RAM
Other Info:
Turn off System Restore on all drives has been checked.
Symptons:
My router has to be manually reset to default everyonce in awhile due to "a page cannot be dispalyed error." The first several times it detects my connection as "static" even though under TCP/IP properties I have it set to DHCP. I also noticed that the page kept refreshing and under mozilla firefox navigation toolbar, the "X" or "stop loading this page" kept reapting while at the bottom it was saying "Done". After being very persistent and many attempts it finally detected DHCP. Another problem I notcied mozilla keeps stopping the page from being redirected. Also gmer.exe keeps crashing within several seconds of opening application. I also ran ATF Cleaner.
Hidden Object
C:\DOCUMENTS AND SETTINGS\STEVE.SLS_COMP\LOCAL SETTINGS\TEMP\RARSFX0\K643DXP.EXE
LOGS:
======================================================================
Kaspersky Anti-Virus
1/19/2010 1:15:30 PM Task started File Anti-Virus Kaspersky Anti-Virus
1/19/2010 1:28:23 PM Task started File Anti-Virus Kaspersky Anti-Virus
1/19/2010 3:55:38 PM Detected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199174.exe Generic Host Process for Win32 Services
1/19/2010 5:25:24 PM Deleted: not-a-virus:RemoteAdmin.Win32.WinVNC.4 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199174.exe Generic Host Process for Win32 Services
1/19/2010 5:25:24 PM Detected: not-a-virus:RiskTool.Win32.PsExec.123 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199175.exe Generic Host Process for Win32 Services
1/19/2010 6:22:57 PM Deleted: not-a-virus:RiskTool.Win32.PsExec.123 C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199175.exe Generic Host Process for Win32 Services
1/19/2010 6:22:57 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Generic Host Process for Win32 Services
1/19/2010 6:30:00 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Skipped by user Generic Host Process for Win32 Services
1/19/2010 6:32:04 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Windows Explorer
1/19/2010 6:32:39 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1604\A0199177.exe Skipped by user Windows Explorer
1/19/2010 6:32:42 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Windows Explorer
1/19/2010 6:32:54 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Skipped by user Windows Explorer
1/19/2010 6:33:26 PM Detected: not-a-virus:Client-IRC.Win32.mIRC.g C:\Program Files\mIRC\mirc.exe Windows Explorer
1/19/2010 6:36:41 PM Deleted: not-a-virus:Client-IRC.Win32.mIRC.g C:\Program Files\mIRC\mirc.exe Windows Explorer
1/19/2010 6:38:19 PM Detected: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Windows Explorer
1/19/2010 6:38:56 PM Untreated: not-a-virus:NetTool.Win32.PsKill.a C:\RECYCLER\S-1-5-21-936119014-1497507713-1777090905-1002\Dc35.exe Skipped by user Windows Explorer
======================================================================
Malwarebytes' Anti-Malware 1.44
Database version: 3597
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/19/2010 2:12:27 AM
mbam-log-2010-01-19 (02-12-27).txt
Scan type: Full Scan (C:\|G:\|)
Objects scanned: 245444
Time elapsed: 49 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 23
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\huwebijum (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\yowujeje.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fefiweta.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hutoziyo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\juviyame.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yagerumu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186205.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186221.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186222.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1572\A0186223.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191319.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191352.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191604.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1573\A0191674.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1579\A0193853.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1589\A0196158.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1589\A0196333.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1600\A0198506.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1600\A0198742.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1601\A0198831.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7852596F-B680-4853-8413-FB6069A893DD}\RP1601\A0199005.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bilayupa.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fejepena.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tepepife.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
======================================================================