Malware/Infection remains after cleanup?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Orbitboy, Dec 31, 2008.

  1. Orbitboy

    Orbitboy Private E-2

    All --

    I recently found my machine infected with Vundo and Smitfraud. Using the cleanup proceedures posted here was an extremely valuable resource and at first look, seemed to eradicate the infections! However, something remains that gives 1 of the 4 users a rundll error upon logging in and the cleanup proceedures have left a windows messenger popup when I log in. I fear the cleanup is incomplete and am looking for help. Three of four requested logs attached below, fourth will be attached to second message.

    I'd appreciate any assistance you could give!

    On a second note - is there anyway to trace when these infections come from? With multiple users it gets difficult to know where they have been and where infections are being picked up, but with that knowledge we might avoid going to the sites they hide in....

    Thank you!

    -- OrbitboyBob
     

    Attached Files:

    Last edited: Dec 31, 2008
  2. Orbitboy

    Orbitboy Private E-2

    Fourth requested log.

    Thank You.
     

    Attached Files:

    Last edited: Dec 31, 2008
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    **CAUTION: Using P2P programs and torrent downloads can be dangerous,
    as they by-pass your firewall and may contain malware.



    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    c:\windows\Tasks\djdrlmfh.job
    c:\windows\Tasks\iiouskff.job
    c:\windows\Tasks\jgvavulm.job
    c:\windows\Tasks\obnrcagy.job
    c:\windows\system32\x32uwmak.dll

    Reboot and make sure those items are gone.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. Orbitboy

    Orbitboy Private E-2

    All proceedures performed as instructed and completed.

    Log attached.

    (Thank You, Thank You, THANK YOU!!!)

    -- OrbitboyBob
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. Orbitboy

    Orbitboy Private E-2

    TimW --

    Thanks soo much for the good news!

    I have not begun the clean up process as yet because of one last item and I don't know what to call it... A Rundll error???

    Everytime my wife logs onto her user account, she gets a window on her desktop that is labled RUNDLL, which contains the following:
    "Error loading C:|Windows\System32\bdbdanmr.dll
    The specified module could not be found."

    Do you have any idea where this would have come from or what it is? Is it associated with the recent viral infection or it's removal? It did occur when the infection was present and remains now that it is cleared up. Please advise!

    Thanks Again!!!!!

    OrbitboyBob
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then we need to run the scans on her account ( as well as the other accounts).

    Please run SAS, MBAM and the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file. on her account. Label them so I know who's is what.

    The run SAS and MBAM on the other accounts and attach any logs that show malware finds again labeling them.
     
  8. Orbitboy

    Orbitboy Private E-2


    TimW --

    Scans performed and logs generated attached. Please note there will be 3 consecutive posts, each will contain the logs for 1 individual User in the order they were generated (1Mom), (2Annie), (3Kate). Logs look good now and behavior regarding RunDll has stopped. However, scanning software was inadvertly NOT turned off during 3rd User SAS scan (AVG scheduled scan) and AVG generated a report of a Trojan, which I will try to post as well. (AVG probably turned on as a result of rebooting somewhere...) Also, I should note: Administrator User Account was never scanned, I have lost the password and need to find out how to recover it. Logs below.

    Thanks!

    -- OrbitboyBob
     

    Attached Files:

  9. Orbitboy

    Orbitboy Private E-2

    TimW --

    Second user logs
    SAS was clean, no log generated
     

    Attached Files:

  10. Orbitboy

    Orbitboy Private E-2


    TimW --

    Third User Logs, SAS also clean, no log generated
    Includes GIF of AVG Scan

    Thanks Again!

    -- OrbitboyBob
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you are an administrator, you can go to user accounts and change the password for the admin account.

    Are you still having any issues?
     
  12. Orbitboy

    Orbitboy Private E-2


    No, no apparent issues. Do you believe it to be clean? What of the AVG
    report? I'll re-run that scan tonight and report.

    The Administrator Account is the one that you don't have access to without the password, even if you are a listed administrator. This user account has not been scanned/cleaned. I need some sort of software to retrieve the password that won't require a reload of the operating system or result in the loss of other passwords and personal settings. Any suggestions?

    Thanks!!!!!

    -- OrbitboyBob
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes I think you are clean.....but you will have to post in the software section to get assistance with the Admin log in password.

    If/when you can access that account, you can check it and always come back to this thread if you find any problems.
     
  14. Orbitboy

    Orbitboy Private E-2


    TimW --

    I'm still having a problem...
    Seems like the machine is clean but could the proceedure(s) have messed up my printer settings? Seems like I am the only one that can print. All other users both Limited and Administrator now get an error sending documents to the Network Printer (an HP Network printer connected to the "HP Standard TCP/IP Port") and can't connect to it. Other compters on the LAN can print it is only the users on the previously infected machine affected.

    Any Recommendations?

    Thanks!!!

    -- OrbitboyBob
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of the scans removed your printer from other users. You may have to temporarily make those users admins and then install the printers on those accounts. Then after reboots, return them to limited users.

    If you have problems with this, do post in software to pursue this. :)
     
  16. Orbitboy

    Orbitboy Private E-2

    TimW --

    Thank you so very much for all your help!
    Setting the other users as Administrators has solved the immediate printing problem. The printer is installed on each account but the inablity to print returns when they are switched to Limited Users. For the time being, I'm satisfied that they can print as Administrators and will work on that problem independently, knowing now it is not from a virus or any of the proceedures performed. Thank YOU!!!

    On a second note, since the clean up and following all the proceedures here, under my wifes account, she has been receiving notifications of undelivered mail to recipients we have no idea who they are. I fear there is something that has gotten control of her email somehow. Is this possible? Is there a way to check on this or determine where the behavior is coming from???

    Thank You Again!

    -- Orbitboy
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will probably have to set the printer permissions for all accouts...something to pursue in software.

    The email issue will probably entail you going into her email account and deleting any with attachments or links.

    You can also log into her account and do a Bitdefender scan:

    This procedure explains how to get to the BitDefender Online Scan sites and how to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version it current. Get Sun Java here: Sun Java Runtime EnvironmentBefore installing the current version, you should uninstall all previous versions first!!!!

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    To start the online scan go here: Bitdefender

    • Agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • And then in the File name box enter bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html. If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

    • Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    • If you run BitDefender Online scan and have previously run PandaActive scan, the below false detection may be seen in BitDefender:

      C:\WINDOWS\system32\ActiveScan\pskahk.dll
      Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds