Vundo? Popups and slow computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mt616161, May 23, 2006.

  1. mt616161

    mt616161 Private E-2

    Hi there,

    Just today, I started getting a lot of popups and my computer has slowed down A LOT. I followed your steps, and it looked like the culprit was Vertrimonde. Anyway, I did the basic steps, and also did VundoFix.exe, but I'm still hearing the popup "noises" as well as popups, and my computer is ridiculously slow now. Please help! I have attached my HJT log below:
     

    Attached Files:

    • HJT.txt
      File size:
      3.2 KB
      Views:
      2
    Last edited by a moderator: May 23, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have not followed ALL the steps in the READ ME!

    You have no protection software installed on this PC. This is a very dangerous way to run.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. mt616161

    mt616161 Private E-2

    I have followed the steps, and attached are the logs.
    Now, no popups seem to appear, but I still hear the 'clicking' noise as if the popups were appearing. Also, my comp is still running slow. Thanks in advance.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you tell CounterSpy to ignore Kazaa and WeatherBug? I don't have to much of a problem with ignoring WeatherBug since it is only a mild form form of adware, but Kazaa is just downright dangerous and contains bundled malware. It could be the root of all your problems especially since you are not running and antivirus, an antispyware, or a firewall to protect you. And even worse than that is the fact that you have a totally out of date Windows OS and IE running!!!!

    You need to run the below and attach the requested Look2Me destroyer log:

    Look2Me VX2 Removal


    After running the above procedure, click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Service

    If you receive any error messages (or cannot find the service name mentioned) just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to but reboot into safe mode.

    While in safe mode, delete the below file:
    C:\WINDOWS\System32\Service.exe <--- only delete service.exe if found. DO NOT delete services.exe

    Now reboot into normal mode and attach a new HJT log and the Look2Me-Destroyer log.
     
    Last edited: May 23, 2006
  5. mt616161

    mt616161 Private E-2

    Here are the new log files attached. And yes, I will definitely be upgrading my OS and installing some virus protection.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the steps to remove the Service?

    I still see the O23 line in your log. Did you have any problems running those steps? Did you fnd the file and delete it?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's continue with other fixes! Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.
    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of cfbwphrg.dll once and then click the kill button. After you have killed all of the cfbwphrg.dll under winlogon click ok. (If you do not find the dll, just continue on with the steps.)

    Now repeat the above in the winlogon.exe process but look for hdfpcvex.dll
    Now repeat the above in the winlogon.exe process but look for sdkbfwrt.dll
    Now repeat the above in the winlogon.exe process but look for wvjgkglf.dll

    Next double click on explorer.exe and again click once on each instance of cfbwphrg.dll and kill it. (If you do not find the dll, just continue on with the steps.)

    Now repeat the above in the explorer.exe process but look for hdfpcvex.dll
    Now repeat the above in the explorer.exe process but look for sdkbfwrt.dll
    Now repeat the above in the explorer.exe process but look for wvjgkglf.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: cfbwphrg - C:\WINDOWS\SYSTEM32\cfbwphrg.dll
    O20 - Winlogon Notify: hdfpcvex - C:\WINDOWS\SYSTEM32\hdfpcvex.dll
    O20 - Winlogon Notify: sdkbfwrt - C:\WINDOWS\SYSTEM32\sdkbfwrt.dll
    O20 - Winlogon Notify: wvjgkglf - C:\WINDOWS\SYSTEM32\wvjgkglf.dll
    O21 - SSODL: IEFilter - {9E25D9D8-B021-4DF6-AB69-8EB91A7B1E74} - C:\WINDOWS\system32\IEFilter.dll
    O21 - SSODL: SysTray.Exgr - {5368D1FC-4F5C-4f1b-B134-E67214FC78E9} - C:\WINDOWS\System32\pjmjpngc.dll (file missing)
    O23 - Service: Service - Unknown owner - C:\WINDOWS\System32\Service.exe



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\cfbwphrg.dll
    C:\WINDOWS\SYSTEM32\hdfpcvex.dll
    C:\WINDOWS\SYSTEM32\sdkbfwrt.dll
    C:\WINDOWS\SYSTEM32\wvjgkglf.dll
    C:\WINDOWS\system32\IEFilter.dll
    C:\WINDOWS\System32\pjmjpngc.dll
    C:\WINDOWS\System32\Service.exe <--- make sure you spell this correctly!!!!



    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.
     
  8. mt616161

    mt616161 Private E-2

    Here is the new log. I was able to complete the steps (although when using Process Explorer, none of the .dll were found)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! That procedure is a Generic process I use to remove DLLs like this because they quite often are hooked into winlogon.exe and explorer.exe. However, sometime they are not hooked (like you observed).


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (this will help you get updated and better protected):

    How to Protect yourself from malware!
     
  10. mt616161

    mt616161 Private E-2

    Awesome! Thank you so much for the help!!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds