CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Solved new undetected Vundo Variant, BHO O2, O20

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
NHutch

Cadet
Cadet


Joined: May 25, 2008
Posts: 2
Location: USA

PostPosted: Sun May 25, 2008 12:35 pm    Post subject: Solved new undetected Vundo Variant, BHO O2, O20
Reply with quote

Filename: C:\WINDOWS\system32\devenumn.dll

Here was a HJT log from some point between pre-removal and removal:

O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: (no name) - {7278C9CA-8118-4F8A-80D5-D0BE6516F7F2} - c:\windows\system32\devenumn.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\program files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - Winlogon Notify: pxtqvhgj - devenumn.dll (file missing)
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\program files\common files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 3252 bytes

I searched through the registry for the CLSID ({7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}) and here were my results:

HKEY_CLASSES_ROOT\Nhatveib\CLSID
HKEY_CLASSES_ROOT\CLSID\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Nhatveib\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pxtqvhgj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sqjjqprm\Parameters

After trying all of my tools in my toolbox (HJT, Combofix, process manager, undll, vundo remover(?) ect.) with no success, I removed the file via the recovery console, which obviously was successful. Combofix was able to remove the O20 part.

However, cleanup to remove the dead strings and dead registry keys was not fun, until I stumbled across this .dat file: C:\WINDOWS\system32\drivers\nyobucwi.dat

Further looking into the .dat file, I came across it in the registry, under HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi

Jackpot! Contained in this key, is all of the instructions for the corresponding strings for the virus. One of the values for group is "boot bus extender" which explains why it cannot be deleted in safemode and why programs like unlocker cannot delete it during boot.

Code:
Key Name:          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi
Class Name:        <NO CLASS>
Last Write Time:   5/23/2008 - 10:33 PM
Value 0
  Name:            ImagePath
  Type:            REG_EXPAND_SZ
  Data:            system32\drivers\nyobucwi.dat

Value 1
  Name:            ErrorControl
  Type:            REG_DWORD
  Data:            0x1

Value 2
  Name:            File
  Type:            REG_EXPAND_SZ
  Data:            \nyobucwi

Value 3
  Name:            0
  Type:            REG_DWORD
  Data:            0x80577925

Value 4
  Name:            7
  Type:            REG_DWORD
  Data:            0x80582294

Value 5
  Name:            9
  Type:            REG_DWORD
  Data:            0x80586c43

Value 6
  Name:            10
  Type:            REG_DWORD
  Data:            0x805a8f96

Value 7
  Name:            5
  Type:            REG_DWORD
  Data:            0x805e218f

Value 8
  Name:            4
  Type:            REG_DWORD
  Data:            0x8056faf2

Value 9
  Name:            8
  Type:            REG_DWORD
  Data:            0x80572bfc

Value 10
  Name:            Group
  Type:            REG_SZ
  Data:            Boot Bus Extender

Value 11
  Name:            Type
  Type:            REG_DWORD
  Data:            0x1

Value 12
  Name:            Name
  Type:            REG_SZ
  Data:            \nyobucwi

Value 13
  Name:            Start
  Type:            REG_DWORD
  Data:            0x0

Value 14
  Name:            R1
  Type:            REG_BINARY
  Data:           
00000000   5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00  \.r.e.g.i.s.t.r.
00000010   79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00  y.\.m.a.c.h.i.n.
00000020   65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00  e.\.s.o.f.t.w.a.
00000030   72 00 65 00 5c 00 6d 00 - 69 00 63 00 72 00 6f 00  r.e.\.m.i.c.r.o.
00000040   73 00 6f 00 66 00 74 00 - 5c 00 77 00 69 00 6e 00  s.o.f.t.\.w.i.n.
00000050   64 00 6f 00 77 00 73 00 - 5c 00 63 00 75 00 72 00  d.o.w.s.\.c.u.r.
00000060   72 00 65 00 6e 00 74 00 - 76 00 65 00 72 00 73 00  r.e.n.t.v.e.r.s.
00000070   69 00 6f 00 6e 00 5c 00 - 65 00 78 00 70 00 6c 00  i.o.n.\.e.x.p.l.
00000080   6f 00 72 00 65 00 72 00 - 5c 00 62 00 72 00 6f 00  o.r.e.r.\.b.r.o.
00000090   77 00 73 00 65 00 72 00 - 20 00 68 00 65 00 6c 00  w.s.e.r. .h.e.l.
000000a0   70 00 65 00 72 00 20 00 - 6f 00 62 00 6a 00 65 00  p.e.r. .o.b.j.e.
000000b0   63 00 74 00 73 00 5c 00 - 7b 00 37 00 32 00 37 00  c.t.s.\.{.7.2.7.
000000c0   38 00 63 00 39 00 63 00 - 61 00 2d 00 38 00 31 00  8.c.9.c.a.-.8.1.
000000d0   31 00 38 00 2d 00 34 00 - 66 00 38 00 61 00 2d 00  1.8.-.4.f.8.a.-.
000000e0   38 00 30 00 64 00 35 00 - 2d 00 64 00 30 00 62 00  8.0.d.5.-.d.0.b.
000000f0   65 00 36 00 35 00 31 00 - 36 00 66 00 37 00 66 00  e.6.5.1.6.f.7.f.
00000100   32 00 7d 00 00 00                                  2.}...

Value 15
  Name:            R2
  Type:            REG_BINARY
  Data:           
00000000   5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00  \.r.e.g.i.s.t.r.
00000010   79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00  y.\.m.a.c.h.i.n.
00000020   65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00  e.\.s.o.f.t.w.a.
00000030   72 00 65 00 5c 00 63 00 - 6c 00 61 00 73 00 73 00  r.e.\.c.l.a.s.s.
00000040   65 00 73 00 5c 00 6e 00 - 68 00 61 00 74 00 76 00  e.s.\.n.h.a.t.v.
00000050   65 00 69 00 62 00 00 00 -                          e.i.b...

Value 16
  Name:            R3
  Type:            REG_BINARY
  Data:           
00000000   5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00  \.r.e.g.i.s.t.r.
00000010   79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00  y.\.m.a.c.h.i.n.
00000020   65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00  e.\.s.o.f.t.w.a.
00000030   72 00 65 00 5c 00 63 00 - 6c 00 61 00 73 00 73 00  r.e.\.c.l.a.s.s.
00000040   65 00 73 00 5c 00 63 00 - 6c 00 73 00 69 00 64 00  e.s.\.c.l.s.i.d.
00000050   5c 00 7b 00 37 00 32 00 - 37 00 38 00 63 00 39 00  \.{.7.2.7.8.c.9.
00000060   63 00 61 00 2d 00 38 00 - 31 00 31 00 38 00 2d 00  c.a.-.8.1.1.8.-.
00000070   34 00 66 00 38 00 61 00 - 2d 00 38 00 30 00 64 00  4.f.8.a.-.8.0.d.
00000080   35 00 2d 00 64 00 30 00 - 62 00 65 00 36 00 35 00  5.-.d.0.b.e.6.5.
00000090   31 00 36 00 66 00 37 00 - 66 00 32 00 7d 00 5c 00  1.6.f.7.f.2.}.\.
000000a0   69 00 6e 00 70 00 72 00 - 6f 00 63 00 73 00 65 00  i.n.p.r.o.c.s.e.
000000b0   72 00 76 00 65 00 72 00 - 33 00 32 00 00 00        r.v.e.r.3.2...

Value 17
  Name:            R4
  Type:            REG_BINARY
  Data:           
00000000   5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00  \.r.e.g.i.s.t.r.
00000010   79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00  y.\.m.a.c.h.i.n.
00000020   65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00  e.\.s.o.f.t.w.a.
00000030   72 00 65 00 5c 00 6d 00 - 69 00 63 00 72 00 6f 00  r.e.\.m.i.c.r.o.
00000040   73 00 6f 00 66 00 74 00 - 5c 00 77 00 69 00 6e 00  s.o.f.t.\.w.i.n.
00000050   64 00 6f 00 77 00 73 00 - 20 00 6e 00 74 00 5c 00  d.o.w.s. .n.t.\.
00000060   63 00 75 00 72 00 72 00 - 65 00 6e 00 74 00 76 00  c.u.r.r.e.n.t.v.
00000070   65 00 72 00 73 00 69 00 - 6f 00 6e 00 5c 00 77 00  e.r.s.i.o.n.\.w.
00000080   69 00 6e 00 6c 00 6f 00 - 67 00 6f 00 6e 00 5c 00  i.n.l.o.g.o.n.\.
00000090   6e 00 6f 00 74 00 69 00 - 66 00 79 00 5c 00 70 00  n.o.t.i.f.y.\.p.
000000a0   78 00 74 00 71 00 76 00 - 68 00 67 00 6a 00 00 00  x.t.q.v.h.g.j...


Value 18
  Name:            F1
  Type:            REG_BINARY
  Data:           
00000000   5c 00 73 00 79 00 73 00 - 74 00 65 00 6d 00 33 00  \.s.y.s.t.e.m.3.
00000010   32 00 5c 00 64 00 65 00 - 76 00 65 00 6e 00 75 00  2.\.d.e.v.e.n.u.
00000020   6d 00 6e 00 2e 00 64 00 - 6c 00 6c 00 00 00        m.n...d.l.l...


Key Name:          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi\Enum
Class Name:        <NO CLASS>
Last Write Time:   5/23/2008 - 10:33 PM
Value 0
  Name:            0
  Type:            REG_SZ
  Data:            Root\LEGACY_NYOBUCWI\0000

Value 1
  Name:            Count
  Type:            REG_DWORD
  Data:            0x1

Value 2
  Name:            NextInstance
  Type:            REG_DWORD
  Data:            0x1


Hope this helps, if you have any questions feel free to shoot me a pm or reply to this thread, I'll keep notifications on if a reply is posted! Wink

Back to top
View users profile Send private message
NHutch

Cadet
Cadet


Joined: May 25, 2008
Posts: 2
Location: USA

PostPosted: Sun May 25, 2008 1:05 pm    Post subject:
Reply with quote

P.S Combofix was able to delete the nybocwi.dat file manually using a CFscript txt file.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5869

MIRT Premium

PostPosted: Sun May 25, 2008 5:32 pm    Post subject:
Reply with quote

Thanks for uploading the file, I'll add it to the malware listserv.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer