vundo trojan help PLEASE!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by agof78, Oct 9, 2005.

  1. agof78

    agof78 Private E-2

    I hope someone will help me get rid of the Vundo trojan. I have followed all the instructions in the "How to:Spyware, Trojan And Virus Removal" by Major Attitude. (One exception was that I could not run "about:Buster" because I kept getting a run-time error '5' msg.) I got the message from many of the scans that my system was clean, but Norton AntiVirus continues to give me the virus alert: C:\Windows\system32\pmkjk.dll is infected with Trojan.Vundo, and that it was unable to repair the file. Access denied. I cannot disable Norton Internet Security because I keep getting a message that I do not have those permissions.
    Before following your instructions I also tried to delete the file, then to rename and delete it, all with no luck. I think tried to do a System Restore, but that, too, was unsuccessful.
    My final step last night was to download HiJack This, and that proved to be a problem also. Everytime I would try to download it from your website, I was redirected to something called Spyware Doctor. I finally downloaded the file onto my laptop and transferred it to the infected machine. I have unzipped it as instructed, but have not yet run it.
    This morning when I logged onto that computer I had an error message from CWShredder saying it had encountered an error and had to close. When I clicked on the Internet Explorer icon, I got a message from a-squared saying that a program appeared to be sending info secretly. I opted to "terminate", then was able to get onto IE.
    I then received another from a-squared saying that "Filename C:\Program Files\Dell Support\DSAgent.exe Diagnosis Found a possible trojan or spyware downloader." I again opted to Terminate. This time when I went to see if I could get to the HiJack This download from your site, I was able to.
    The only other weird thing I noticed was a seemingly empty file folder called MSConfig that was created on September 30 probably about the time I turned the computer on that day. I don't remember creating that folder.
    Not sure if you need it but here's info about our set up. We have two desktops and one laptop with XP Professional. We are set up for file sharing of selected files. The laptop is most often run wirelessly on a WPA encrypted network. We have a Netgear router and Linksys Access Point.
    I would really appreciate any help I can get in fixing this problem. I don't mind hiring someone to do it for me, but I've found that those folks often create more problems and then I haven't learned anything either!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the generic cleaning procedure for Virtumunde. It is the last link in this sticky: Special Removal Procedures

    Let me know if you have any problems following that guide.
     
  3. agof78

    agof78 Private E-2

    I am in Safe mode on my desktop (typing this on the laptop) and I've started the vundofix.exe and have a question:
    Where I'm supposed to type in a file path, I'm not sure what to put there since it says in the instructions "as instructed by the forum staff". Should I put the file that Norton says is infected?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As per that procedure. Find the line in your HJT log that looks similar to:

    O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\Fonts\badfile.dll

    Obviously the file name can/will be different but in the above line, the full filename path is: C:\WINDOWS\Fonts\badfile.dll

    Yours may be (based on your message) C:\Windows\system32\pmkjk.dll but it should show in your HJT log O2 line (and also on an O20 line).
     
  5. agof78

    agof78 Private E-2

    Okay, I got to the point where I entered the file name backwards, pressed Enter, F6, Enter and my Norton AV popped up "Malicious script detected" Your computer is halted and needs to do something about this script.
    Object Windows Script Host Shell Object
    Activity Run
    Do I select the option that says to "Authorize this script?"
     
  6. agof78

    agof78 Private E-2

    Nevermind about my last question. I got brave and proceeded. It looks like we've gotten rid of my Norton popup about the virus. Do I need to do anything further? I will run another HJT log to see if the infected files are still there.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. agof78

    agof78 Private E-2

    I have done all of those steps. Here is my HJT log. I am not aware of any other malware issues.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Virtumunde is gone but let's address a few other items.

    Now click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and then reboot if it asks you to do so. Then continue with below.

    You should run the steps in the below link from Dell to remove MyWaySA that they installed on your PC.

    http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=42328

    The run HJT and have it fix any of the below that still remain:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.sbc.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)


    After doing that do this: How to Reset Web Settings

    Then post a new HJT log attachment.
     
  10. agof78

    agof78 Private E-2

    I am currently in the MyWay Removal instructions in the Registry Editor. I have gone into My Computer, clicked Edit- Find, typed MyWay. It has shown me 25 entries, only 1 of which actually says "MyWay." Do I go ahead and delete them all? Since this is dealing with the Registry, I would really rather be safe than sorry.
    Also, at start up this morning, I again received warnings from a-squared Guard Alert concerning Real Player and Symantec. How can I get rid of those warnings, or am I getting ahead of myself?
    Thanks so much for your help this far!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let me ask about MyWay. Did you try using Add/Remove programs to uninstall it first?
    Did you run Windows Installer Cleanup after uninstalling?
    Do not delete anything in the registry without being 100% positive on what you are deleting.

    You're right! Don't jump ahead! Let's fix the other items first.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a manual search tool!

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    MyWay

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread.

    Also repeat the search (just to be sure) using: MyWaySA
     
  13. agof78

    agof78 Private E-2

    Yes, I did the Add/Remove, then ran Windows Installer CleanUp Utility. The Myway Search ASsistant was not there.
    Then I started the secondary instructions fro myway removal. The MsiExec.exe string was not there so I went to step 4.
    I did step four where I searched the Local Hard Drive for MyWay. I deleted those files.
    That's when I went to regedit. I have only deleted the one that referenced MyWay.

    Also, when I run HJT again, do I need to delete the RO - HKCU.....www.yahoo.sbc.com? That is my home page.
     
  14. agof78

    agof78 Private E-2

    Here's that search log.
     

    Attached Files:

  15. agof78

    agof78 Private E-2

    In doing the search for MyWaySA this is the list returned.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. agof78

    agof78 Private E-2

    I have not completed that step since I got stuck in the Dell forum steps (the regedit) for removing MyWay. I am attempting to be very methodical in following your instructions, so I didn't do anything else at the time. I have also not run HJT to fix those things in #9 either. Should I do both now? And should I delete the line that refers to my home page (SBC Yahoo)?
     
  18. agof78

    agof78 Private E-2

    I complete the steps in #9, including running HJT (deleting any of the remaining files on your list). Then I went thru the steps in How to Reset Web Settings. Here are the new Registry search logs.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me see a current HJT log too. So we can figure out what else needs to be done. Don't worry about your SBC Yahoo home page (if it was cleared by the Reset of Web Settings). You can put it back in later.
     
  20. agof78

    agof78 Private E-2

    Here's the new HJT log.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! Why is Microsoft Installer Cleanup Utility still running?

    C:\Documents and Settings\Becky\Desktop\msicuu2.exe

    Have you rebooted since running it? It should not remain running?

    Your log is clean but let's clean the registry of MyWay.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixMW.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixMW.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    Then you can set your home page back to whatever you like.

    Are you still having other problems?
     
  22. agof78

    agof78 Private E-2

    I must have missed the instructions to reboot after running Microsoft Installer Cleanup. I restarted, ran another HJT log, and it is no longer showing.

    My other issues are with a-squared Guard alert. It keeps giving me alerts on Real Player and on Symantec. As I'm typing this, it just popped up with an alert that says:
    File Name: C:\Program Files\Dell Support\DSAgnt.exe
    Diagnosis: Found a possible trojan or spyware downloader.
    That is worrisome to me. I don't know what option to choose---My tendency would be to select "Terminate program". But why is it trying to run?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean by "Real Player and on Symantec". Real Player and Symantec have nothing to do with each other. Or did you mean that both A-squared and Symantec are giving you reports about Real Player? If so what do they say exactly?


    DSAgnt.exe is from Dell and has nothing to do with Real Player or Symantec See: http://www.liutilities.com/products/wintaskspro/processlibrary/dsagnt/

    You probably do not need it but that is up to you.

    You can have HJT fix the below items as they are not necessary.
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Then reboot and see what reports you get.
     
  24. agof78

    agof78 Private E-2

    I fixed the two lines you suggested and then rebooted. When I clicked on the Internet Explorer icon, a-squared gave me this:
    c:\programs\....\ie\explore.exe
    Diagnosis: Found a possible LAN bypass backdoor or spyware.

    I got two warnings from a-squared earlier today:
    The first was the one concerning "possible trojan or spyware" associated with Real Player.
    The same warning was also given concerning Symantec -- I guess since I have Norton run when the machine starts. (?)

    JUST NOW a-squared gave me a warning again about the Dell Support\DSAgnt.exe.

    I don't want to have to keep dealing with all their warnings, so should I uninstall the program, or just select the option "Always allow program" if I know what the program is???
     
  25. agof78

    agof78 Private E-2

    Another a-squared just popped up saying that the DSAgnt.exe is trying to install a service or device driver. I am not selecting an option on any of these open warning windows until I hear back from you.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can go to Add/Remove programs and look for the Dell Support program and uninstall it. Or you can do the below which does not uninstall it but does stop it from running at boot up.


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Dell Support\DSAgnt.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup

    After clicking Fix, exit HJT.


    Now reboot in normal mode and post a new HJT log. See if you get any more error messages.

    Are you still getting messages about RealPlayer after doing what I gave you previously.

    Do you have your WinXP CD? Or look for a c:\i386 folder on your drive. We may need to replace Iexplorer.exe?
     
  27. agof78

    agof78 Private E-2

    I have not received any more msgs regarding Real Player.
    I went ahead and uninstalled Dell Support.

    I do have my WinXP CD.

    Here's the HJT log.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot to ask previously. Is you WinXP CD for SP2 or did you upgrade to SP2 from an older version?

    Are you still getting a message about Iexplore being infected?
     
  29. agof78

    agof78 Private E-2

    I do have the Window XP Pro SP2 disk. My machine is only a couple months old.
    I'm not getting any more warnings from a-squared, so maybe you've fixed everything!

    Do I need to uninstall any of the programs I've downloaded to take care of all these problems, or should I leave them in case I need them again?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like we do not need your disk then!

    No you don't really have to uninstall them. Most are not using very much diskspace and do not use system resources except when scanning. They are good to have around.

    You should however get a real firewall. The one in WinXP SP2 is not adequate. See the steps in the below (which are all recommended anyway). Some steps you have already completed:

    How to Protect yourself from malware!
     
  31. agof78

    agof78 Private E-2

    What firewalls are the best to use with a home network? I had to disable the one in Norton or I couldn't get to files on various computers.
    I will re-read the article you suggested.
    Thanks so VERY VERY much for all of your great help! I think I've learned some things, and I really feel like I've accomplished something!
    I'm going to go to work now on our other two machines, so you guys will hear from me again soon.
    THANKS AGAIN!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Any of the ones in the link I gave to you are fine for a home network. Be aware that you have to configure any firewall properly or you can have problems trying to communicate between PCs on your home network. You could even cause problems getting to the Internet. This is the purpose of having the firewall (i.e., to block unauthorized connections).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds