Hi I have a customer with a virus that is proving difficult to remove
Trend Micro internet security reorts it is :
Cryp tap-2 virus -Vundo
Infected File is called awtqqrsp.dll and recommends deleting it manually, of course when i try this 'access is denied'
i have tried using killbox to delete the file, on reboot dregister dll , end shell etc, to no avail
have tried running trend micro scan, spybot s&d, avg, vundo fix 7.0, virtumundo begone, windows defender but these will not remove it either
Symptons of infection:
Browser (IE) has following written in top left corner on random pages (google, msn etc)
Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware...
when clicking 'here' link redirects to these URLS:
http://protect.trustedantivirus.com/MTY4Nzc=/2/5993/ed=1/ex=1/h=10/zheltaya_hernya/http://www.pcsecurityshield.com/lp/shield-pro-3.aspx?trk=WTK&affid=541I have posted Hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 6:53:16 PM, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.
exe
C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\PROGRA~1\TRENDM~1\INTER
N~1\TmPfw.
exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\system32\ICO.EX
E
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\WINDOWS\system32\Pelmic
ed.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\hpz
tsb11.exe
C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe
C:\WINDOWS\system32\hphmon
06.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Java\jre1.6.0_05\bin
\jusched.e
xe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\HPZipm
12.exe
C:\Program Files\ScanSoft\PaperPort\p
ptd40nt.ex
e
C:\Program Files\Brother\Brmfcmon\BrM
fcWnd.exe
C:\Program Files\Brother\ControlCente
r3\brccMCt
l.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Brother\Brmfcmon\BrM
fcmon.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFComm
ander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlat
formCOMSvr
.exe
C:\Program Files\Trend Micro\TrendSecure\Transact
ionProtect
or\Depende
nt\HSChkPr
oxyExe.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\temp\1HJK\HijackThis.ex
e
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.worldtimeserver.com/current_time_in_EG.aspxR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
N4 - Mozilla: user_pref("browser.search.
defaulteng
ine", "
http://www.google.com/");
(C:\Documents and Settings\user\Application Data\Mozilla\Profiles\defa
ult\v3c68y
wv.slt\pre
fs.js)
O3 - Toolbar: Skype" For Internet Explorer - {B13721C7-F507-4982-B2E5-5
02A71474FE
D} - C:\Program Files\Skype\toolbars\Skype
for Internet Explorer\skype_toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C
7685D2E1E4
0} - C:\Program Files\Trend Micro\TrendSecure\Transact
ionProtect
or\TSToolb
ar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [BluetoothAuthenticationAg
ent] rundll32.exe irprops.cpl,,BluetoothAuth
entication
Agent
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstar
tup.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [ibmmessages] c:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\hpz
tsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-45
87-8DD3-EB
C57C83374D
}\hphupd06
.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon
06.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" -Embedding -boot
O4 - HKLM\..\Run: [PDF4 Registry Controller] "C:\Program Files\ScanSoft\PDF Professional 4.0\RegistryController.exe
"
O4 - HKLM\..\Run: [ScanSoft PDF Professional 4-reminder] "C:\Program Files\ScanSoft\PDF Professional 4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Professional\4\Ereg\Ereg.i
ni
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\p
ptd40nt.ex
e
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\I
ndexSearch
.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrM
fcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrS
tDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCente
r3\brctrce
n.exe /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [lxwfvxuq] C:\WINDOWS\system32\zalwlo
rq.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\Common Files\IBMTOOLS\Apps\Common
\Bin\WinCi
nemaMgr.ex
e
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.h
tm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\
GPhotos.sc
r/200
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: Open with ScanSoft PDF Converter 4.1 - res://C:\Program Files\ScanSoft\PDF Professional 4.0\cnvres_eng.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_05\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_05\bin
\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D
9FCDDC9D60
0} - C:\Program Files\Windows Live\Writer\WriterBrowserE
xtension.d
ll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D
9FCDDC9D60
0} - C:\Program Files\Windows Live\Writer\WriterBrowserE
xtension.d
ll
O9 - Extra button: Skype" For Internet Explorer - {77BF5300-1474-4EC7-9980-D
32B190E9B0
7} - C:\PROGRA~1\Skype\toolbars
\SKYPEF~1\
SKYPE_~1.D
LL
O9 - Extra 'Tools' menuitem: Skype" For Internet Explorer - {77BF5300-1474-4EC7-9980-D
32B190E9B0
7} - C:\PROGRA~1\Skype\toolbars
\SKYPEF~1\
SKYPE_~1.D
LL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O15 - Trusted Zone:
http://au.match.comO16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {31B7EB4E-8B4B-11D1-A789-0
0A0CC6651A
8} (Cult3D ActiveX Player) -
http://www.cult3d.com/download/cult.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1165445981000O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WI1F86~1\MESSE
N~1\MSGRAP
~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WI1F86~1\MESSE
N~1\MSGRAP
~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-1
0D7BE1653C
0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
4D524869DB
5} - C:\WINDOWS\system32\WPDShS
erviceObj.
dll
O21 - SSODL: PrxUnknown - {deb74ef9-3c99-45f5-8290-6
39549ee857
e} - C:\WINDOWS\Installer\{deb7
4ef9-3c99-
45f5-8290-
639549ee85
7e}\PrxUnk
nown.dll (file missing)
O21 - SSODL: zip - {8bd45a57-c054-43ef-a6e0-f
87d90577e3
1} - C:\WINDOWS\Installer\{8bd4
5a57-c054-
43ef-a6e0-
f87d90577e
31}\zip.dl
l (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Unknown owner - C:\Program Files\Trend Micro\BM\TMBMSRV.exe" /service (file missing)
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTER
N~1\TmPfw.
exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
I am assuming this is a new variant of Vundo and its driving me nuts!!
Any help appreciated
Michael