Vundo (Trojan) Preventing Access to Internet Explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by redkty, May 1, 2009.

  1. redkty

    redkty Private E-2

    Since the download of one document online, I have been unable to access Internet Explorer (t's been like a week). I have McAfee Security Center and it has identified the following but does not remove it. I have followed your procedures online to try to remove it and have attached the logs. The only way I can access the internet is via AOL.

    Some of the things I've seen on McAfee:

    uhivamnn.dll
    vundo (trojan)

    File: C:\windows\system32\uhivamnn.dll

    Process: C:\Program Files\Internet Exploreer\iexplore.exe

    Process Description: Internet Explorer


    File: C:\Windows\system32\nqstv.ini

    File: C:\windows\system32\nqstv.bak1

    PLEAAASE HEEEELP!!

    -Crystal
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:

    First use windows explorer to find:
    C:\Qoobox\Quarantine\C\Program Files\ThinkPad\ConnectUtilities\ACGina.dll.vir
    Copy and paste it ( ACGina.dll.vir ) back into the C\Program Files\ThinkPad\ConnectUtilities\ folder and remove the .vir extension.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    xeqluzhk
    
    File::
    c:\windows\system32\zcvsnwg.dll
    c:\windows\system32\179223
    c:\windows\system32\czpkllo.dll
    c:\windows\Tasks\At1.job
    c:\windows\system32\drivers\xeqluzhk.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A99E6DD-A86E-4C79-9372-C2732D14BC55}]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: May 5, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds