Trojan Horse Dropper and Vundo

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BillRat9, Jan 15, 2008.

  1. BillRat9

    BillRat9 Private E-2

    While looking for some information yesterday, I went into a site that automatically started a download of "SpyGuard Pro" or something like that. I was unable to stop the download and it has apparently infected my system with Vundo and Trojan Horse Dropper Agents GIT and DGO. I have followed the Read and Run me first instructions but there still seems to be problems. AVG A-V doesn't start at startup among others (it seems).

    I think I have gotten rid of the Vundo, but I'm not much of an expert at these things so I'm not sure.

    When I ran the AVG A-S, I selected "Automatically generate report after every scan" and Un-selected "Only if threats were found" but it did not generate a report. :eek: I have attached the other two logs.

    Any help would be greatly appreciated.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, it looks like ComboFix removed the last of your infections.

    You just need to do the below.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Are you still having problems with AVG Antivirus? If so, uninstall, reboot, and then reinstall. How are things now?
     
  3. BillRat9

    BillRat9 Private E-2

    Thanks so much for getting back to me. It must be the height of the "Cold and Flu" season for computers out there. I was beginning to think that I was going to get shut out....and you all are the only guys I trust.

    I had actually already uninstalled the viewpoint programs after I posted, I usually do that every few weeks. My question is, is there any way to stop Viewpoint from getting on the system? It always seems to come back.

    I think it was my anti-virus that cleaned up most of the infection with a big help from ComboFix. It looks like the virus infected a bunch of program files making them unhealable and they ended up getting deleted. I'm going to have to repair or reinstall a BUNCH of software (it seemed to especially hate Adobe and HP products, but also knocked out the AVG Control Center, AIM, and some others).

    Now all of those files that were infected are re-named with numbers and letters added to the file name and a .pf extension and are in a folder called "prefetch. Should those all be deleted?

    Thanks SO Much For Your Help!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The easiest way is to never use anything from AOL (that includes AIM). You could also try using this:ViewpointKiller

    No those are normal.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  5. BillRat9

    BillRat9 Private E-2

    Thank you for all your help. Unfortunately there were too many system files that were damaged and I'm going to have to reformat.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear that. While you did have signs have a previous Vundo infection and ComboFix removed the last of it. You did not show any signs of the more recent version of Vundo that does infect installed startup programs. It may be that you only need to reinstall a few programs and they would be the ones that put processes into your Startup list. Adobe and HP would be two of those.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds