Please help with Malware Removal Logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by billbill, Dec 2, 2009.

  1. billbill

    billbill Private E-2

    I am hoping you can help us clean this computer of Vundo and any other malware. I have followed your steps below and attached the logs. I have also summarized what we did before finding your forum. Thank you so much for any help you can offer!


    SYSTEM
    Dell Dimension desktop
    XP Home and Service Pack 3

    SYMPTOMS
    Constant pop-ups; inability to complete purchases online; printing problems.


    WHAT WE DID BEFORE FINDING YOUR FORUM
    We ran McAfee, Superantispyware, and Malwarebytes before finding this forum. I did not save the initial logs.

    Briefly, the initial Superantispyware scan found about 20 to 30 files labeled Vundo Variant and Vundo Variant-T (I think). Upon reboot after cleaning, we got an error message saying that the zesupoma.dll file was missing.

    Malwarebytes also found a few infected files, but I can't remember if they were labeled Vundo or not; we cleaned the system too quickly.

    We also rescanned everything before finding your forum. A new Malwarebytes scan was clean, but Superantispyware still reported about 6 Vundo Variant files. We could not boot into safe mode. The third scan on all three scanners was clean, but we still could not boot into safe mode. After this, we found your forum and followed your procedures.



    RESULTS AFTER FOLLOWING YOUR PROCEDURES

    All logs are attached. Briefly, results were as follows:

    Superantispyware: clean

    Malwarebytes: clean

    Combofix: deleted 3 files
    c:\windows\system32\ip39pj0.dll
    c:\windows\system32\ssprs.dll
    c:\windows\Tasks\morkduaa.job

    RootRepeal: C:\hiberfil.sys "Locked to the Windows API!"

    MGTools: Log attached

    Hijack This: Log attached


    Of note, I turned McAfee antivirus and firewall off during the Combofix, RootRepeal, and MGTools scans, but a McAfee window popped up during the process anyway and announced it had found Exploit CVE2007-2071 and removed it.

    Thank you very, very much for any help you can give.
     

    Attached Files:

  2. billbill

    billbill Private E-2

    Here are the additional two logs. Thank you!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are basically clean but I do have a little for you to do.


    You have Symantec left overs to remove. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. billbill

    billbill Private E-2

    Combofix disappeared from my desktop. I did not delete it, I swear. A search of my computer for Combofix finds only logs, text files, the "how to," and a combofix.exe prefetch file. Can I just download a new copy to the desktop and do this procedure?
     
  5. billbill

    billbill Private E-2

    Okay I think that worked. I have attached the logs.

    Thank you very, very much for your help. I am wondering if I need to do something to System Restore to make sure there is no Vundo there, or have we done that already?

    Thank you again. I don't know what we would have done without you.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. billbill

    billbill Private E-2

    Thank you for all that. I am not sure if the System Restore procedure worked or not. When I checked the box and pressed okay, it did not prompt me to reboot. Then when I opened the box back up to reenable System Restore, I did not have to re-enable it. The box to turn it off was already unchecked and the status said "monitoring." Can I be sure that it was actually turned off? I did the same thing again, and again I did not have to re-enable.

    I have two more questions:

    Since we went through the malware removal procedure, this computer makes a terrible sound when it is shut down for the night or shut down to restart. Just before shutting down, it makes a very loud and harsh sound like static on a radio station. Do you know what might possibly be causing this? It was not evident before the virus.

    Second, when you recommend Superantispyware and Malwarebytes, do you mean that we should purchase them to get real-time protection instead of just scanning occasionally? This computer is owned by someone who is visually impaired and uses a screen reader, so anything that would automate protection would be very much appreciated. However, I hesitated to recommend that to him before, because I was afraid the programs would conflict with each other or that they would conflict with McAfee Internet Security Suite, which already has an anti-spyware component.

    Would it be safe to purchase both and run them real-time to prevent reinfection, along with the McAfee?

    Thanks SO MUCH again for all your help. I hope I expressed those questions clearly.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not ask you to reboot. Here is what I suggest you try. Disable System Restore ( on all drives). Then close those windows and reboot. After reboot. Check the settings and if disabled, reenable it.

    No I don't but it does not sound like malware. Sounds more like a hard disk problem. Are you talking about a sound coming from the speakers or a sound coming from inside the PC.

    I recommend that you only purchase one and just keep the other as a backup scanner since they each can find/fix things the other does not. SUPERAntiSpyware may be a better choice for protection, however if McAfee already has an antispyware component, you should just keep the free versions of both SAS and MBAM. These scanners are much better than McAfee which really misses most malware. Whether they would conflict with McAfee that much is unknown but the performance hit you may notice could be significant especially since McAfee is a massive hog to beging with.
     
  9. billbill

    billbill Private E-2

    Thank you! Sorry for the delay in posting. I am not posting about my own computer, and it will be a day or so before I have access to it again.

    We will try disabling System Restore again. I can't remember where the sound comes from....I will pay more attention next time I hear it.

    Okay....given that he has the whole McAfee suite, I guess we will keep them as on-demand scanners for now.

    I can't thank you enough for all the help. It was a nasty infection, and it is nice to be able to hand the computer back nice and clean. You perform an amazing service here.

    Thank you so much!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds