Evil evil Vundo - Can't get through Read & Run Me

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Echo6, Sep 17, 2009.

  1. Echo6

    Echo6 Private E-2

    Hey,

    I'm infected with a Vundo variant and can't get rid of it. I've gone through the Read Me First steps and I can't even get SAS, Malwarebytes, or any of the other to run to get a log. I've been in safe mode, normal mode, etc., so I'm totally stuck!

    I can see the yabivisu.dll in my start-up, but can't kill it.

    Any suggestions? I think my GF was silly and followed a bad link, or so she says :)

    Thank you!
     
  2. Echo6

    Echo6 Private E-2

    More info:

    It's as if the virus is killing the program processes, as the program window just disappears and you can't see it in Task Manager anymore. Thats for like MGTools, HJT, ComboFix. With Malwarebytes and SAS, the comp says "Windows cannot access specified drive, file, or path. You may not have the appropriate permissions to access them." But I am the Admin...

    It seems totally weird that I can't get a log file for ANY of these??
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did MGtools run long enought to create the C:\MGtools folder? If yes, click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below command in this window each followed by the enter key.

    cd c:\MGtools
    ShowNew.bat

    Tell me what happens. Note there is a space after the cd


    Also please try the below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r
     
  4. Echo6

    Echo6 Private E-2

    Thanks for the reply Chaslang.

    MGTools did install to C: but when I use ShowNew.bat, I see the black cmd prompt box appear for less than a second and then it disappears, kind of like the the other progs being shut down prematurely.

    I got Win32kDiag to run, here's the log.

    Major thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start=> Run and copy and paste the below command into the run box and then click OK. This will run quickly.

    cmd /c copy C:\Windows\System32\logevent.dll C:\logevent.dll /y > C:\log.txt

    Now continue on with the below instructions.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now let's run Win32kDiag again:
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • the Win32kDiag.txt log
    • C:\MGlogs.zip
    Now see if you can run any other tools like SUPERAntiSpyware, Malwarebytes, and ComboFix. If you can run any of them, attach the logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds