|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
NHutch
Cadet

 Joined: May 25, 2008 Posts: 2 Location: USA
|
Posted: Sun May 25, 2008 12:35 pm Post subject: Solved new undetected Vundo Variant, BHO O2, O20 |
|
|
Filename: C:\WINDOWS\system32\devenumn.dll
Here was a HJT log from some point between pre-removal and removal:
O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: (no name) - {7278C9CA-8118-4F8A-80D5-D0BE6516F7F2} - c:\windows\system32\devenumn.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\program files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - Winlogon Notify: pxtqvhgj - devenumn.dll (file missing)
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\program files\common files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 3252 bytes
I searched through the registry for the CLSID ({7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}) and here were my results:
HKEY_CLASSES_ROOT\Nhatveib\CLSID
HKEY_CLASSES_ROOT\CLSID\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Nhatveib\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7278C9CA-8118-4F8A-80D5-D0BE6516F7F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pxtqvhgj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sqjjqprm\Parameters
After trying all of my tools in my toolbox (HJT, Combofix, process manager, undll, vundo remover(?) ect.) with no success, I removed the file via the recovery console, which obviously was successful. Combofix was able to remove the O20 part.
However, cleanup to remove the dead strings and dead registry keys was not fun, until I stumbled across this .dat file: C:\WINDOWS\system32\drivers\nyobucwi.dat
Further looking into the .dat file, I came across it in the registry, under HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi
Jackpot! Contained in this key, is all of the instructions for the corresponding strings for the virus. One of the values for group is "boot bus extender" which explains why it cannot be deleted in safemode and why programs like unlocker cannot delete it during boot.
| Code: | Key Name: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi
Class Name: <NO CLASS>
Last Write Time: 5/23/2008 - 10:33 PM
Value 0
Name: ImagePath
Type: REG_EXPAND_SZ
Data: system32\drivers\nyobucwi.dat
Value 1
Name: ErrorControl
Type: REG_DWORD
Data: 0x1
Value 2
Name: File
Type: REG_EXPAND_SZ
Data: \nyobucwi
Value 3
Name: 0
Type: REG_DWORD
Data: 0x80577925
Value 4
Name: 7
Type: REG_DWORD
Data: 0x80582294
Value 5
Name: 9
Type: REG_DWORD
Data: 0x80586c43
Value 6
Name: 10
Type: REG_DWORD
Data: 0x805a8f96
Value 7
Name: 5
Type: REG_DWORD
Data: 0x805e218f
Value 8
Name: 4
Type: REG_DWORD
Data: 0x8056faf2
Value 9
Name: 8
Type: REG_DWORD
Data: 0x80572bfc
Value 10
Name: Group
Type: REG_SZ
Data: Boot Bus Extender
Value 11
Name: Type
Type: REG_DWORD
Data: 0x1
Value 12
Name: Name
Type: REG_SZ
Data: \nyobucwi
Value 13
Name: Start
Type: REG_DWORD
Data: 0x0
Value 14
Name: R1
Type: REG_BINARY
Data:
00000000 5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00 \.r.e.g.i.s.t.r.
00000010 79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00 y.\.m.a.c.h.i.n.
00000020 65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00 e.\.s.o.f.t.w.a.
00000030 72 00 65 00 5c 00 6d 00 - 69 00 63 00 72 00 6f 00 r.e.\.m.i.c.r.o.
00000040 73 00 6f 00 66 00 74 00 - 5c 00 77 00 69 00 6e 00 s.o.f.t.\.w.i.n.
00000050 64 00 6f 00 77 00 73 00 - 5c 00 63 00 75 00 72 00 d.o.w.s.\.c.u.r.
00000060 72 00 65 00 6e 00 74 00 - 76 00 65 00 72 00 73 00 r.e.n.t.v.e.r.s.
00000070 69 00 6f 00 6e 00 5c 00 - 65 00 78 00 70 00 6c 00 i.o.n.\.e.x.p.l.
00000080 6f 00 72 00 65 00 72 00 - 5c 00 62 00 72 00 6f 00 o.r.e.r.\.b.r.o.
00000090 77 00 73 00 65 00 72 00 - 20 00 68 00 65 00 6c 00 w.s.e.r. .h.e.l.
000000a0 70 00 65 00 72 00 20 00 - 6f 00 62 00 6a 00 65 00 p.e.r. .o.b.j.e.
000000b0 63 00 74 00 73 00 5c 00 - 7b 00 37 00 32 00 37 00 c.t.s.\.{.7.2.7.
000000c0 38 00 63 00 39 00 63 00 - 61 00 2d 00 38 00 31 00 8.c.9.c.a.-.8.1.
000000d0 31 00 38 00 2d 00 34 00 - 66 00 38 00 61 00 2d 00 1.8.-.4.f.8.a.-.
000000e0 38 00 30 00 64 00 35 00 - 2d 00 64 00 30 00 62 00 8.0.d.5.-.d.0.b.
000000f0 65 00 36 00 35 00 31 00 - 36 00 66 00 37 00 66 00 e.6.5.1.6.f.7.f.
00000100 32 00 7d 00 00 00 2.}...
Value 15
Name: R2
Type: REG_BINARY
Data:
00000000 5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00 \.r.e.g.i.s.t.r.
00000010 79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00 y.\.m.a.c.h.i.n.
00000020 65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00 e.\.s.o.f.t.w.a.
00000030 72 00 65 00 5c 00 63 00 - 6c 00 61 00 73 00 73 00 r.e.\.c.l.a.s.s.
00000040 65 00 73 00 5c 00 6e 00 - 68 00 61 00 74 00 76 00 e.s.\.n.h.a.t.v.
00000050 65 00 69 00 62 00 00 00 - e.i.b...
Value 16
Name: R3
Type: REG_BINARY
Data:
00000000 5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00 \.r.e.g.i.s.t.r.
00000010 79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00 y.\.m.a.c.h.i.n.
00000020 65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00 e.\.s.o.f.t.w.a.
00000030 72 00 65 00 5c 00 63 00 - 6c 00 61 00 73 00 73 00 r.e.\.c.l.a.s.s.
00000040 65 00 73 00 5c 00 63 00 - 6c 00 73 00 69 00 64 00 e.s.\.c.l.s.i.d.
00000050 5c 00 7b 00 37 00 32 00 - 37 00 38 00 63 00 39 00 \.{.7.2.7.8.c.9.
00000060 63 00 61 00 2d 00 38 00 - 31 00 31 00 38 00 2d 00 c.a.-.8.1.1.8.-.
00000070 34 00 66 00 38 00 61 00 - 2d 00 38 00 30 00 64 00 4.f.8.a.-.8.0.d.
00000080 35 00 2d 00 64 00 30 00 - 62 00 65 00 36 00 35 00 5.-.d.0.b.e.6.5.
00000090 31 00 36 00 66 00 37 00 - 66 00 32 00 7d 00 5c 00 1.6.f.7.f.2.}.\.
000000a0 69 00 6e 00 70 00 72 00 - 6f 00 63 00 73 00 65 00 i.n.p.r.o.c.s.e.
000000b0 72 00 76 00 65 00 72 00 - 33 00 32 00 00 00 r.v.e.r.3.2...
Value 17
Name: R4
Type: REG_BINARY
Data:
00000000 5c 00 72 00 65 00 67 00 - 69 00 73 00 74 00 72 00 \.r.e.g.i.s.t.r.
00000010 79 00 5c 00 6d 00 61 00 - 63 00 68 00 69 00 6e 00 y.\.m.a.c.h.i.n.
00000020 65 00 5c 00 73 00 6f 00 - 66 00 74 00 77 00 61 00 e.\.s.o.f.t.w.a.
00000030 72 00 65 00 5c 00 6d 00 - 69 00 63 00 72 00 6f 00 r.e.\.m.i.c.r.o.
00000040 73 00 6f 00 66 00 74 00 - 5c 00 77 00 69 00 6e 00 s.o.f.t.\.w.i.n.
00000050 64 00 6f 00 77 00 73 00 - 20 00 6e 00 74 00 5c 00 d.o.w.s. .n.t.\.
00000060 63 00 75 00 72 00 72 00 - 65 00 6e 00 74 00 76 00 c.u.r.r.e.n.t.v.
00000070 65 00 72 00 73 00 69 00 - 6f 00 6e 00 5c 00 77 00 e.r.s.i.o.n.\.w.
00000080 69 00 6e 00 6c 00 6f 00 - 67 00 6f 00 6e 00 5c 00 i.n.l.o.g.o.n.\.
00000090 6e 00 6f 00 74 00 69 00 - 66 00 79 00 5c 00 70 00 n.o.t.i.f.y.\.p.
000000a0 78 00 74 00 71 00 76 00 - 68 00 67 00 6a 00 00 00 x.t.q.v.h.g.j...
Value 18
Name: F1
Type: REG_BINARY
Data:
00000000 5c 00 73 00 79 00 73 00 - 74 00 65 00 6d 00 33 00 \.s.y.s.t.e.m.3.
00000010 32 00 5c 00 64 00 65 00 - 76 00 65 00 6e 00 75 00 2.\.d.e.v.e.n.u.
00000020 6d 00 6e 00 2e 00 64 00 - 6c 00 6c 00 00 00 m.n...d.l.l...
Key Name: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nyobucwi\Enum
Class Name: <NO CLASS>
Last Write Time: 5/23/2008 - 10:33 PM
Value 0
Name: 0
Type: REG_SZ
Data: Root\LEGACY_NYOBUCWI\0000
Value 1
Name: Count
Type: REG_DWORD
Data: 0x1
Value 2
Name: NextInstance
Type: REG_DWORD
Data: 0x1 |
Hope this helps, if you have any questions feel free to shoot me a pm or reply to this thread, I'll keep notifications on if a reply is posted!
|
|
| Back to top |
|
 |
NHutch
Cadet

 Joined: May 25, 2008 Posts: 2 Location: USA
|
Posted: Sun May 25, 2008 1:05 pm Post subject: |
|
|
P.S Combofix was able to delete the nybocwi.dat file manually using a CFscript txt file.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5869
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You cannot download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|