Infected by Vesbiz downloader

  1. #21
    UlfErik is offline Junior Member

    Re: Infected by Vesbiz downloader

    The infection is returning every day and every day I run TrenMicro' s scan and HijjackThis. I have also tried XoftSpy which detected several malware. TrenMicro detects WORM_RDOT.ASC in system32\p3.exe almost every day and I seem to spend most of my time scanning and collecting information about virus. Here comes my latest scan. I am bit suspicious about netdde.exe but really, I am suspicious about almost everything. I run W XP PRO.

    Logfile of HijackThis v1.99.0
    Scan saved at 2:30:51, on 01/02/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Archivos de programa\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\p3.exe
    C:\Archivos de programa\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 192.168.1.1:3128
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
    F2 - REG:system.ini: Shell=
    O1 - Hosts: 62.189.6.85 _sip._tls.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.85 _sip._ssl.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._tls.sip6.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._ssl.sip6.phoneserve.com
    O1 - Hosts: 62.189.6.93 _sip._tls.sip7.phoneserve.com
    O1 - Hosts: 62.189.6.93 _sip._ssl.sip7.phoneserve.com
    O1 - Hosts: 62.189.6.78 _sip._tls.sip1.callserve.com
    O1 - Hosts: 62.189.6.78 _sip._ssl.sip1.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._tls.sip2.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._ssl.sip2.callserve.com
    O1 - Hosts: 62.189.6.108 _sip._tls.sip8.phoneserve.com
    O1 - Hosts: 62.189.6.108 _sip._ssl.sip8.phoneserve.com
    O1 - Hosts: 62.189.6.61 _sip._tls.sip17.phoneserve.com
    O1 - Hosts: 62.189.6.61 _sip._ssl.sip17.phoneserve.com
    O1 - Hosts: 62.189.6.62 _sip._tls.sip18.phoneserve.com
    O1 - Hosts: 62.189.6.62 _sip._ssl.sip18.phoneserve.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar1.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.3000.1001\es\msntb.dll
    O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Archivos de programa\CoreStreet\SpoofStick\SpoofStickBHO.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.3000.1001\es\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar1.dll
    O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Archivos de programa\CoreStreet\SpoofStick\SpoofStick.dll
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 9.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Archivos de programa\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Archivos de programa\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Archivos de programa\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [SpySweeper] "C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - HKCU\..\Run: [Srvce Pack Updte] svcpack.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: SystemRecovery.com TaskBar Icon.LNK = C:\Archivos de programa\SystemRecovery\OLSysTray.exe
    O8 - Extra context menu item: &Download with &DAP - C:\ARCHIV~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Google Search - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Instantánea de caché de la página - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Páginas similares - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Páginas vinculadas - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmbacklinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: CUseeMe Conferencing Companion - {44EFB53C-C965-43CF-9F45-52242D134187} - C:\Archivos de programa\CUseeMe\Amigo.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1097416344213
    O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/es/de.../GoogleNav.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {86698251-D2C0-4D0F-A3E4-95CEF12F9F18} - http://64.156.188.99/iwasher/internetwasherpro.cab
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://photos.msn.es/r/neutral/contr...cab?5,0,1730,0
    O16 - DPF: {DE833CC3-52E7-4C9A-BDC4-8EC24B422A2B} (Superscape VisLite) - http://www.arsvirtual.com/monum/visi...te/vislite.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/regi...ActiveData.cab
    O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Archivos de programa\HP\hpcoretech\comp\hpuiprot.dll
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Servicio del administrador de discos lógicos - Unknown - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Registro de sucesos - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: GBPoll - Roxio, Inc. - C:\Archivos de programa\Roxio\GoBack\GBPoll.exe
    O23 - Service: Servicio COM de grabación de CD de IMAPI - Unknown - C:\WINDOWS\System32\Imapi.exe
    O23 - Service: Escritorio remoto compartido de NetMeeting - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: DDE de red - Unknown - C:\WINDOWS\system32\netdde.exe
    O23 - Service: DSDM de DDE de red - Unknown - C:\WINDOWS\system32\netdde.exe
    O23 - Service: SystemRecovery.com RegCap - SystemRecovery.com - C:\Archivos de programa\SystemRecovery\OLRegCap.EXE
    O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: Administrador de sesión de Ayuda de escritorio remoto - Unknown - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Sistema de ayuda de tarjeta inteligente - Unknown - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Tarjeta inteligente - Unknown - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Registros y alertas de rendimiento - Unknown - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: SystemRecovery.com Launcher - SystemRecovery.com - C:\Archivos de programa\SystemRecovery\OLlaunch.exe
    O23 - Service: Telnet - Unknown - C:\WINDOWS\System32\tlntsvr.exe
    O23 - Service: Instantáneas de volumen - Unknown - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: Adaptador de rendimiento de WMI - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


  2. #22
    owen is offline D-A-L Team Member (UK)
    Download the Pocket Killbox from here.

    Unzip it and run the program.

    Put a check in the Delete on Reboot box.

    Enter each of these lines into the white box one by one and then press the red X button. If firsts asks to confirm the deletion after each entry is added and the red X is pressed, you need to click yes, but it also asks if you want to Reboot. Click No each time until the last entries been entered.

    C:\WINDOWS\System32\p3.exe
    C:\WINDOWS\System32\svcpack.exe

    When KillBox has rebooted your system, fix this entry:

    O4 - HKCU\..\Run: [Srvce Pack Updte] svcpack.exe

    Post a fresh log

  3. #23
    UlfErik is offline Junior Member
    When I scanned with TrenMicro the last few days the pattern of the results has been more or less as follows:The scan starts with message "HouseCall has found and cleaned a malware, WORM_RBOT.AIW", then it scans and I get the following results of detected virus (e.g. Febr 1):
    WORM_RBOT.ASC in C:\system32\p3.exe, WORM_RBOT.ASC in C:\Recykled\Dc1.exe, WORM_RBOT.ASC in C:\Recykled\Dc82.exe. After using Killbox the results today (Febr 3) were:
    "HouseCall has found and cleaned a malware, WORM_RBOT.AIW" and after finishing the scan: WORM_RBOT.AIW in C:\Windows\system32\icp.exe A second scan this afternoon started with: "HouseCall has found and cleaned a malware, WORM_RBOT.AIW" and finished with: WORM_SDBOT.AKJ in C:\system32\p6.exe and WORM_RBOT.AIW in C:\Recykled\Dc82.exe.
    In using KillBox I assumed that in the box (System process) I should use System. Do I continue to use KillBox in the same way with the infected files that appear?


    Logfile of HijackThis v1.99.0
    Scan saved at 1:35:19, on 04/02/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Archivos de programa\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 192.168.1.1:3128
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
    F2 - REG:system.ini: Shell=
    O1 - Hosts: 62.189.6.85 _sip._tls.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.85 _sip._ssl.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._tls.sip6.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._ssl.sip6.phoneserve.com
    O1 - Hosts: 62.189.6.93 _sip._tls.sip7.phoneserve.com
    O1 - Hosts: 62.189.6.93 _sip._ssl.sip7.phoneserve.com
    O1 - Hosts: 62.189.6.78 _sip._tls.sip1.callserve.com
    O1 - Hosts: 62.189.6.78 _sip._ssl.sip1.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._tls.sip2.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._ssl.sip2.callserve.com
    O1 - Hosts: 62.189.6.108 _sip._tls.sip8.phoneserve.com
    O1 - Hosts: 62.189.6.108 _sip._ssl.sip8.phoneserve.com
    O1 - Hosts: 62.189.6.61 _sip._tls.sip17.phoneserve.com
    O1 - Hosts: 62.189.6.61 _sip._ssl.sip17.phoneserve.com
    O1 - Hosts: 62.189.6.62 _sip._tls.sip18.phoneserve.com
    O1 - Hosts: 62.189.6.62 _sip._ssl.sip18.phoneserve.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar1.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.3000.1001\es\msntb.dll
    O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Archivos de programa\CoreStreet\SpoofStick\SpoofStickBHO.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.3000.1001\es\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar1.dll
    O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Archivos de programa\CoreStreet\SpoofStick\SpoofStick.dll
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 9.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Archivos de programa\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Archivos de programa\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Archivos de programa\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [SpySweeper] "C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MS Updating Utility] msupdater.exe
    O4 - Startup: SystemRecovery.com TaskBar Icon.LNK = C:\Archivos de programa\SystemRecovery\OLSysTray.exe
    O8 - Extra context menu item: &Download with &DAP - C:\ARCHIV~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Google Search - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Instantánea de caché de la página - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Páginas similares - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Páginas vinculadas - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmbacklinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: CUseeMe Conferencing Companion - {44EFB53C-C965-43CF-9F45-52242D134187} - C:\Archivos de programa\CUseeMe\Amigo.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1097416344213
    O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/es/de.../GoogleNav.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {86698251-D2C0-4D0F-A3E4-95CEF12F9F18} - http://64.156.188.99/iwasher/internetwasherpro.cab
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://photos.msn.es/r/neutral/contr...cab?5,0,1730,0
    O16 - DPF: {DE833CC3-52E7-4C9A-BDC4-8EC24B422A2B} (Superscape VisLite) - http://www.arsvirtual.com/monum/visi...te/vislite.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/regi...ActiveData.cab
    O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Archivos de programa\HP\hpcoretech\comp\hpuiprot.dll
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Servicio del administrador de discos lógicos - Unknown - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Registro de sucesos - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: GBPoll - Roxio, Inc. - C:\Archivos de programa\Roxio\GoBack\GBPoll.exe
    O23 - Service: Servicio COM de grabación de CD de IMAPI - Unknown - C:\WINDOWS\System32\Imapi.exe
    O23 - Service: Escritorio remoto compartido de NetMeeting - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: DDE de red - Unknown - C:\WINDOWS\system32\netdde.exe
    O23 - Service: DSDM de DDE de red - Unknown - C:\WINDOWS\system32\netdde.exe
    O23 - Service: SystemRecovery.com RegCap - SystemRecovery.com - C:\Archivos de programa\SystemRecovery\OLRegCap.EXE
    O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: Administrador de sesión de Ayuda de escritorio remoto - Unknown - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Sistema de ayuda de tarjeta inteligente - Unknown - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Tarjeta inteligente - Unknown - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Registros y alertas de rendimiento - Unknown - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: SystemRecovery.com Launcher - SystemRecovery.com - C:\Archivos de programa\SystemRecovery\OLlaunch.exe
    O23 - Service: Telnet - Unknown - C:\WINDOWS\System32\tlntsvr.exe
    O23 - Service: Instantáneas de volumen - Unknown - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: Adaptador de rendimiento de WMI - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

  4. #24
    owen is offline D-A-L Team Member (UK)
    Hiya,
    Sorry we haven't got anywhere. What I want you to do for me is this, and it should hopefully clean up your problem.

    Get to http://windowsupdate.microsoft.com and download all Critical Updates and Service Packs for XP. You have a vulnerability on your system that this worm is exploiting, thats the reason we can't get rid of it. This will take some time to download Service Pack 2. After you've done that, check back again and check for critical updates again and some more will be found.

    Then go to C:\ and create a folder called "Scanner". Download the Sysclean Package from here and save it to the Scanner folder. Also download the latest Virus Pattern File for Sysclean from here. Download it, unzip it and save the file contained in the scanner folder where Sysclean is located.

    NOTE: The unzipped virus pattern file called lpt$vpn.392 needs to be in the same folder as Sysclean as mentioned above, if not, Sysclean will not work.

    Boot into Safe Mode.

    Go to C:\Scanner and double click the Sysclean file. When the windows called Trend Micro Sysclean Package appears, ensure there is a checkmark in the box at the bottom called "Automatically Clean Or Delete detected files". Then click Scan.

    A black window will open and scroll through a long list of virus names beginning with the words Executing **Virus Name** pattern...

    The window will close after a few seconds and Sysclean will start scanning you system for viruses. Let it remove any detected viruses. When the scan is complete, click Exit. A logfile called sysclean will have been created in the C:\Scanner folder.

    Reboot into normal mode and post the sysclean log and a fresh Hijack This log.

  5. #25
    UlfErik is offline Junior Member
    I followed your instrutctions but it took me a long time. I didn´t have access to Internet and I couldn´t download SP2 in safe mode. With a combination of rebooting and scanning I finally managed yesterday to download 20 security updates and SP2. I downloaded today the Sysclean file but IE couldn´t find the zip file. My PC doesn´t work very well. Is is slow and Outlook and IE will only work for a few minutes. After that I cannot receive any mail or open any pages in Internet. I have disabled the firewall. When I open Internet I am directed to some game and sex pages. I might have a dialer or something like it, somwhere in my system. After running XoftSpy, at the end of the scanning the window flickers a little and it gives me time to read something like "Ardamas keylogger" in documents and settings, start menu (I think) but when the final log comes up it doesn´t record anything about it. I am thinking of starting again from scratch with the download of SP2 bu I have not got much time if I want to use GoBack. Best regards.

  6. #26
    owen is offline D-A-L Team Member (UK)
    I downloaded today the Sysclean file but IE couldn´t find the zip file
    I don't understand what your saying?

  7. #27
    UlfErik is offline Junior Member
    1- I finally succeeded in downloading SP2.

    2- I downloaded the Sysclean package but my IE couldn´t find the Virus Pattern File where you said it would be.

    3- Outlook and Internet only works for a few minutes after rebooting (disabling the firewall doesn´t help). I thought something might have gone wrong with the download of SP2 and thought of trying to GoBack and do it again

  8. #28
    owen is offline D-A-L Team Member (UK)
    2- You have to actually unzip the Pattern File into that folder...

  9. #29
    UlfErik is offline Junior Member
    Hello Owen, I don´t seem to be able to make myself understood. It is the third time I am trying to say that cklicking on the link doesn´t bring me to the page where I am supposed to download the zip file. I have tried to type the address as it comes in the mail I received from D-A-L, instead of using the link but I always get the same answer: Internet Explorer cannot find the page. Could you please check that the link works. If it does, I don´t know what I am doing wrong.

  10. #30
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    Hiya,
    The link works fine for me. Could you try this link instead please: http://uk.trendmicro-europe.com/glob...opr/lpt462.zip

    If that doesn't work, post back and I'll give you another address to download from.

+ Reply to Thread
Page 3 of 4 FirstFirst 1 2 3 4 LastLast