Pesky Vundo Infection, need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by princey28, Mar 11, 2009.

  1. princey28

    princey28 Private E-2

    We recently found a rather nasty vundo infection on my wife's computer that seems to come back after the computer restarts. We've run several different anti-spyware programs, including one we purchased, and each found Vundo in different locations and reported that they deleted them. I've done all of the steps in the read on run first topic. Logs are attached.
     

    Attached Files:

  2. princey28

    princey28 Private E-2

    And here is my MGlogs.zip.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you as soon as possible. Thanks for your patience during this time.

    Whilst I am going over them, please uninstall the out of date version of Malware Bytes that you have. Reboot your machine > use ccleaner and install the most current version available Malwarebytes Anti-Malware 1.34

    kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    1) Please go to Add or Remove Programs and uninstall the following softwares:

    • Spyware Doctor 6.0 <--- only uninstall if it is a free trial--if paid for, then leave it alone.
    • Ad-Aware SE Personal <--- outdated.
    • Viewpoint Media Player <--- uninstall this as per requested in step 1 of the R&R
    • avast! Antivirus <--- Uninstall this if you intend on keeping Rising Anti-Virus

    2) Now we need to use ComboFix to remove a bunch of malware files and get shot of a leftover AVG7 directory.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DeQuarantine::
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    
    File::
    c:\windows\SYSTEM32\akisafaw.tmp
    c:\windows\SYSTEM32\sapoviri.dll
    c:\windows\SYSTEM32\sekavido    
    c:\documents and settings\default\zguicfgw.dat
    
    Folder::
    c:\documents and settings\All Users\Application Data\Avg7
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "AVG7_CC"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3) Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    4) Run Ccleaner!

    5) Run the new MGTools.exe and attach the log it generates and also the log from ComboFix. Also attach the new log from MBAM

    6) Let me know how things are running!


    Thanks
    Kes
     
  5. princey28

    princey28 Private E-2

    First, I want to thank you for taking the time to look through the logs. I appreciate the help.

    Spyware Doctor is paid for, so that's staying.

    I get the following RunDLL error when trying to remove Avast:

    Error loading C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll

    The specified module could not be found.

    Avast is listed in the Add/Remove programs, but it has no size.

    Logs from ComboFix, MBAM and MGTools are attached. I'm hopeful we might have gotten it. I have IE open on the computer that was infected and I'm not getting any popups. It also seems to be restarting faster as well. I'm going to run Spyware Doctor to see if it doesn't catch it.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome. :)

    Glad to hear it, I'm not seeing any more malware in your logs. Let me know how you get on.

    Try the below:

    If the program was installed using Windows Installer, then you may use Windows Installer Cleanup Utility to remove the installer information for that program, and also the corresponding entry in Add or Remove programs.


    Add/Remove program Cleaner is a free and useful program that allows you to clean up the Add/Remove programs list in the control panel. It should only be used to remove entries that are broken and cannot be removed by running the uninstall program.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:


    Thanks
    kestrel
     
  7. princey28

    princey28 Private E-2

    Spyware Doctor found a couple cookies, but that's it. The other scans didn't find anything. I'm pretty confident it is gone. She has been on Internet Explorer for awhile on it and has received no pop-ups.

    Thanks for the help.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Very welcome-safe surfing :wave
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds