Malware shutsdown Counterspy

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Billyfromthehill, Apr 12, 2007.

  1. Billyfromthehill

    Billyfromthehill Private E-2

    Posting Logs Quick -

    3rd attempt - won't let me UPLOAD - think its the Malware blocking upload.

    I will send in short post reply with more info after logs ...
     

    Attached Files:

  2. Billyfromthehill

    Billyfromthehill Private E-2

    Symptoms...

    Qwest DSL Modem


    At Comp start up -

    MSN Mess and Windows Mess access internet (previously these were disabled to be used only if clicked on purposely)

    REALPLAYER starts and tries to access internet.

    Pop Ups appear when not logged into IE explorer

    When Logging into IE -
    MSN money 2002 startup and tries to access net

    When logged on to internet...

    Pop up galore -
    Error - IE must shut down sorry for the inconvienience...

    Streaming audio comes on - sounds like radio and voices talking...

    Will post another reply with Bit Defender info...
     
  3. Billyfromthehill

    Billyfromthehill Private E-2

    Bit defender -

    Shut down with IE error message each time I ran it.

    Here is the final scan - found MUCH less junk the final run.
    I could only get these few lines before shut down - there were more that were supposedly DELETED.

    C:\Doc & Settings Trojan.Downloader.Agent.AMN
    C:\Windows\System32\etobp.dll infected with Trojan.Vqten.AMN
    C:\Windows\System32\JGSDIT.dll infected with Trojan.Vqten.AMN

    I will post a HIJACK THIS log next reply ...

    New Developement
    Now the pop ups have all turned to Porn type dating services...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you running steps in the READ ME in the correct order?

    Based on things I see in your current logs, you need to run this Virtumonde aka Trojan Vundo Removal and then attach the requested log from VundoFix.

    Also you still need to attach the below logs from the READ & RUN ME.

    Panda Scan - from step 6
    HijackThis
     
  5. Billyfromthehill

    Billyfromthehill Private E-2

    Ok on Friday 4/13 Ran this......Virtumonde aka Trojan Vundo Removal

    Bad things occured- CounterSpy wanted to block it saying it was installing a trojan ie_updater.

    Now IE is completely incapacitated (I am on work computer loaned out).

    I will try to move a hijackthis Log to post here and try the Panda item you mentioned.

    What about dumping IE and starting over with Firefox?
    Would the infection/virus affect firefox?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Infections are less likely but not impossible for FireFox. The Vundo infection is typically more of a problem for IE. Not that VundoFIx is not an ieupdater infection. So either CounterSpy was wrong or it was just a coincidence that the other infection was manifesting itself while cleaning Vundo. I would suspect that it was the later.

    Try installing FireFox if possible. Also try to get me the VundoFix and HJT logs at a minimum!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds