Vundo, and a bunch of other stuff...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sosaman, May 8, 2008.

  1. sosaman

    sosaman Sergeant Major

    ok, i haven't been on this board since i was able to post. anyway, this isn't my comp, it's my nephews laptop, and i've been working on it for almost a week now (started last friday). they just said it got polluted, and took it to geeksquad and they said @$300 usd, or so to fix it (i'm not sure if that meant backing up everything, and reinstalling os or not)? anyway, i don't know the history of this comp. they wound up buying a new laptop (they moved away, and needed something), and gave this laptop to his dad.

    what i do know (windows xp, pentium 4 - 2.66 ghz, 256 mbyte ram - which i updated to 512 mbyte 2 days ago - it didn't like the 512 stick, which would have made it 768). anyway, they had norton 360 on it, and it slowed it down alot (it took about 15-20 min or so to bootup, and get to where i could do something. when i started on it, there was all kinds of crap. i'll post links here and there to my screenshots on flickr. i'm more or less looking to see if i've missed anything, going overboard (false positives), or what?

    fyi, as of this writing, and me running the scans in " READ & RUN ME FIRST. Malware Removal Guide", i've run all kinds of scans. i've learned (me personally), that you shouldn't take to big of a bite (delete a bunch of crap at once), or you might have problems, anyway, my .02 worth. - sos

    also, i had previously removed what was found by superantispy, so it is clean.
     

    Attached Files:

  2. sosaman

    sosaman Sergeant Major

    this is what i started with in the beginning (screenshots below). if you happen to go through the folder that these pics are in, i used stopzilla, as that is what they had installed, and i eventually uninstalled it. i just used it to see if it caught different things. i found it to be a piece of crap (of course this is my opinion), as when i told it not to start up on bootup, it always did, no matter the settings.

    http://www.flickr.com/photos/10511748@N06/2476422055/
    http://www.flickr.com/photos/10511748@N06/2476422329/
    http://www.flickr.com/photos/10511748@N06/2477235842/
    http://www.flickr.com/photos/10511748@N06/2477235788/
    http://www.flickr.com/photos/10511748@N06/2477235608/
    http://www.flickr.com/photos/10511748@N06/2477235934/
    http://www.flickr.com/photos/10511748@N06/2476422675/
    http://www.flickr.com/photos/10511748@N06/2477235706/

    i also, uninstalled what i could. weatherbug, pink ribbon browser helper, stopzilla, etc, etc.

    things i've installed, and used prior to this posting. (screenshot below). and online antivirus scans i've run, bitdefender, kaspersky, mcafee, panda, symantec, trend micro. (did i miss any online scans?).


    things that might be helpful (screenshots below)??

    http://www.flickr.com/photos/10511748@N06/2477236986/
    http://www.flickr.com/photos/10511748@N06/2477237398/
    http://www.flickr.com/photos/10511748@N06/2476423813/
    http://www.flickr.com/photos/10511748@N06/2476424109/
    http://www.flickr.com/photos/10511748@N06/2477237950/
    http://www.flickr.com/photos/10511748@N06/2477238522/
    http://www.flickr.com/photos/10511748@N06/2477238598/

    most of everything that i've posted i've deleted? but i guess the more scans i run, the more i find, anyway, thx - sos

    also, i don't know if it really has alot left, but it's been very sluggish, even before it gets to the windows logon screen. but once it's logged on it's not that bad (although it seemed to have more pep prior to running combofix). ;)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: The READ ME is supposed to be run in normal boot mode not safe mode.

    You said you uninstall Norton 360 but I still see it in your uninstall programs list. You should run the below and then reboot and then run it one more time:

    Norton Removal Tool (SymNRT)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {C3F50901-871A-4650-85D8-9D53E2534A3B} - (no file)
    R3 - URLSearchHook: (no name) - - (no file)
    O2 - BHO: (no name) - {3240E9B7-0577-58DB-061A-5F00C9B28D90} - (no file)
    O2 - BHO: (no name) - {6B9848CE-5813-453D-A975-7211B6953BC8} - (no file)
    O2 - BHO: (no name) - {fc6f76c2-1dd1-11b2-8e9c-9fdfb2ca8fdc} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O15 - Trusted Zone: *.finefind.nettraffic2cash.biz

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. sosaman

    sosaman Sergeant Major

    sorry, about that. i'm used to doing most scans in safe mode. also, i had already run the norton removal 3 times prior (rebooting in between). anyway, i ran it 2 more times as you requested. also, i was not able to upload mglogs.zip (as you requested). i posted a screenshot below, of the error. even if i were to rename the file mglogs-2.zip, i still get the same error. :confused thx, sos

    edit: well, it still seems sluggish, but i don't know what the comp was like prior to all of this. my compaq presario laptop (amd athlon 64, 797 mhz, 512 mbyte ram), is alot snippier (sp) than this dell laptop (pentium 4, 2.66 ghz, 512 ram). it seems fine once it's started up and running, but it's just slow during a reboot, and starting up.
     

    Attached Files:

    Last edited: May 9, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means that you did not follow the instructions to get a new log. You need to run the GetLogs.bat file as requested to create a new log.


    Then it is most likely just due to the applications that need to get loaded/hooked in to your OS when Windows starts up. Avast, Ad-Aware 200, A-squared, ZoneAlarm....etc all take time to load up. Ad-Aware 2007 I would just uninstall since it is a waste of system resources to always have the service running and not get any protection from it and it is slowing down startup. You are better off with Malwarebytes Anti-Malware which only runs when you run it and it will find and remove many more real malware issues than Ad-Aware.
     
  6. sosaman

    sosaman Sergeant Major

    sorry, i missed that part.


    i'll try the malwarebytes, but i thought ad-aware, and a-squared, were only using resources when i use the scanner (i don't have the realtime scanner enabled)? anyway, i still don't understand the sluggishness, as i have this software on my laptop as well. - thx, sos
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! Look at your last HijackThis log that is inside of the MGlogs.zip file and you will see the below.

    These processes are running:
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\a-squared Free\a2service.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe


    And the below is how they load everytime you start your PC:
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    Anything you run requires resources and time to load. Some require more than others. ;)

    You can uninstall SUPERAntispyware now since we are finished with it. This will help improve startup time since it trys to look for updates and does things at startup.

    Your logs are clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. sosaman

    sosaman Sergeant Major

    thx, chaslang!! :wave - sos

    i'm off to the s/w forum...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds