remove the 2chkdsk virus/spyware/malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by peptorres, Mar 14, 2007.

  1. peptorres

    peptorres Private E-2

    I've named it the 2chkdsk as it's the word i get most info when searching google.

    it's pretty easy to spot.. but rather difficult to remove. It has busted my brains for a while.

    I'll try to describe the steps as easy as possible and I believe not everyone will follow. It's a rather 'primitive' way of doing so.

    The virus itself replicates through dll files that attach to explorer.exe or iexplore.exe... so making it difficult to delete (as file is locked). i do have a copy inf unlocker assistant which allows you to 'unlock' files and kill processess (useful for deleting jammed files).

    to find out dll files, run msconfig and recognise the rundll which will tell you the dll to delete. you will be able to delete this one.,, but on every restart.. a new one will appear.

    to find the root dll files... i did run hijackthis and did discover which ones. also discovered it 'leeches' onto winlogon.

    to delete the source files, remove all cookies and temp folders (manually). locate from %systemroot%\system32\ the dll's. they are hidden.. so will be easy to locate and have a generic name which stand out from other dll's.

    mine were: ljjkigh.dll, ddcyw.dll, gebywwx.dll. these were all hidden dll's.

    if oyu boot from safe mode.. you will still not be able to delete these as they are 'leeched' onto winlogon, explorer and maybe another app.. so... this is the killer:

    remove the hhd and connect to another computer. simply navigate into system32 foilder and process to delete all the hidden dll's.
    of course you will need to enable viewing hidden files and folders.

    easy peasy japanese...

    run hijack this and regedit following to the RUN key to find out 2chkdsk is no longer loaded. whit hijack this.. clean up the unnecessary keys (file not found) and clean up.
    \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    What you are describing is Virtumonde also called Vundo and we have tools and procedures to remove this. You do not need to remove the hard disk from your system to fix this. Our fixes are rather easy.

    Based on what you described you may still have some other hidden files related to it on your PC. You should run our standard cleaning procedure ( the READ & RUN ME sticky thread) which will show us whether you still have files from the infection on your PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds