MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.

Reply
 
Thread Tools Display Modes
  #1  
Old 09-27-06, 17:02
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default WinAntiVirus - FixVundo solution

Hi
I have religiously copied instructions on this site to remove the amaena.com/securityworm which causes the Winantivirus pop-ups to appear.
After downloading the FixVunda tool from Symantec ; turned off System restore, run Fixvunda tool and restarted XP system. Chkdsk then took over an hour to complete before PC booted up again. I ran the tool again and the tool stated that it had removed the problem.
I re-enabled the system restore, and re-connected the DSL and after about 1/2 hour surfing, the same pop-ups are coming back.

Can you please help me eradicate this?

Steve
Reply With Quote
Sponsored links
  #2  
Old 09-27-06, 21:29
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Welcome to Majorgeeks!

Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
  • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
  • Make sure you check version numbers and get all updates.
  • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
  • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
Downloading, Installing, and Running HijackThis

Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


  • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #3  
Old 09-28-06, 06:42
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Thanks Chaslang,
In desperation I failed to read the **READ & RUN ME FIRST**, apologies for time wasting.
I shall follow the instructions and get back on my findings. Thank you for your support.

HH
Reply With Quote
  #4  
Old 09-28-06, 14:24
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Hi chaslang
I have carried out your instructions - Could not run scans in Safe mode, had to do in Normal Mode., Problems encountered with Window defender: (unable to complete the update:0x80240016). Tried again and hit scan but unable to get updates. I ran the scan anyway and a Virus Alert cameup on screen : Object name - C:\WINDOWS\System32\pmkhghg.dll. No other threats came up.
Virus name: Trojan Horse Action: Unable to repair.
This also came up while running Malicious Software Removal Tool.
In Bitdefender, 2 files detected via pop-up alert:- C:\DOCUME~1\LOCAL..\tmp0, TROJAN HORSE, Unable to repair. C:\WINDOWS\System32\pmkhghg.dll, TROJAN HORSE, Unable to repair.
I have attached the Bit Defender log ,runkeys.txt and newfiles.txt.
I have NOT run the Hijack this file, as I want to make sure I read the instructions first.
Anything that you can help me with so far?
Many Thanks
Steve

Last edited by Grumbles; 07-07-07 at 17:07..
Reply With Quote
  #5  
Old 09-28-06, 14:41
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Attached is the Hijack - this log. I have followed instruction to rename hijack file to analyse.exe as instructed.
I HAVE NOT done anything else while in this program, just closed the window after the log appeared.
I look forward to hearing from you
Steve

Last edited by Grumbles; 07-07-07 at 17:07..
Reply With Quote
Sponsored links
  #6  
Old 09-29-06, 11:57
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Re- running 'fix programs' and giving you more information on trying to fix problems:
- I am running XP, and use 2 user accounts. My wife's does not have Internet access, but I do. When booting in to Safe Mode the Administrator user comes up on screen, but I never use this; no IE access or ability to get to CCleaner,Defender or any other tools. This is why I did the checks in normal Mode.

Steve
Reply With Quote
  #7  
Old 09-29-06, 15:21
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Hi again,
I am using Dell Dimension 3000
Processor: Intel(R) Celeron(R) CPU 3.06Ghz
Processor Speed: 2.99Ghz
Memory: 1024Mb
Operating System: Microsoft Windows XP Home edition 5.12600
ADSL connection 589.8 Kbps
Hope this info helps more?
Ran Windows Defender again in Normal Mode, picking up the same 2 Trojans as reported before, and still getting Pop-ups with "Drivecleaner or WinAntiVirus"
Steve
Reply With Quote
  #8  
Old 09-30-06, 14:18
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Quote:
Originally Posted by happyhibby
- I am running XP, and use 2 user accounts. My wife's does not have Internet access, but I do. When booting in to Safe Mode the Administrator user comes up on screen, but I never use this; no IE access or ability to get to CCleaner,Defender or any other tools. This is why I did the checks in normal Mode.
Let's focus on one user account at a time. The Administrator account is a valid account and only shows in safe mode. If your account and your wife's accounts do not have administrator priviledges, then they will not show in safe mode. If that was the case, you should have use the Administrator account. Make sure you password protect the Administrator account because by default it is not password protected.



Uninstall the below software:
Java 2 Runtime Environment, SE v1.4.2_03
Viewpoint Media Player

Now install the current version of Sun Java from: Sun Java Runtime Environment

Continue by downloading two tools we will need

- Process Explorer

- Pocket KillBox

Extract them to their own folder somewhere that you will be able to locate them later.

IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

Do the above before continuing! Okay unplug your cable now.

Make sure you have rebooted in Normal Mode (do not open any other processes)

- Run Process Explorer

In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of mdhext.dll once and then click the kill button. After you have killed all of the mdhext.dll under winlogon click ok. (If you do not find the dll, just continue on.)

Now repeat the above step for the below DLLs(If you do not find the dll, just continue on):
pmkhghg.dll

Next double click on explorer.exe and again click once on each instance of mdhext.dll and kill it. (If you do not find the dll, just continue on.)

Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
pmkhghg.dll

Now just exit Process Explorer.

Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
C:\WINDOWS\system32\asrupdate.exe

After killing all the above processes, click Back.
Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
O2 - BHO: (no name) - {96297172-21FF-4E62-9CA0-0A4E3B77F292} - C:\WINDOWS\system32\mdhext.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKCU\..\Run: [asrupdate.exe] C:\WINDOWS\system32\asrupdate.exe
O20 - Winlogon Notify: mdhext - C:\WINDOWS\SYSTEM32\mdhext.dll

After clicking Fix, exit HJT.

Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
Be sure the "Save as" type is set to "all files"
Once you have saved it double click it and allow it to merge with the registry.
Quote:
REGEDIT4

[-hkey_local_machine\software\classes\appid\CheckProduct2_1.DLL]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhghg]


[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhext]
Now run Pocket Killbox by doubleclicking on killbox.exe
Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
Then after it deletes the files click the Exit (Save Settings) button.
NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

Select:
  • Delete on Reboot
  • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\SYSTEM32\mdhext.dll
C:\WINDOWS\system32\ddabb.exe
C:\WINDOWS\system32\pmkhghg.dll
C:\WINDOWS\system32\asrupdate.exe
  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
If Killbox does not reboot just reboot your PC yourself.

Now attach a new HJT log and tell me how the steps went.
Also attach a new log from ShowNew.
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #9  
Old 10-01-06, 16:41
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Hi Chaslang
Thank you for your help.
I could not install Sun Java (I already have this version installed)
Downloaded Process Explorer and Pocket Killbox. Turned off Firewall and NAV as instructed then unplugged cable.

Ran Process explorer extracting all files. winlogon.exe - Clicked on mdhext.dll and killed 2 lines and O kills for pmkhghg.dll.
explorer.exe - mdhext.dll 4 kills and 0 kills for pmkhghg.dll.
Ran HJT and killed C:\WINDOWS\system32\asrupdate.exe. then ran a scan and Fixed R1 to O20 lines.
Copied the REGEDIT4 and saved as fixme.reg to desktop.
Ran Pocket Killbox and followed your instructions. Was only able to copy and paste badfiles C:|WINDOWS\System32\mdhext.dll,ddabb.exe,pmkhghg.dll,asrupdate.exe one at a time. Tried to copy and past all files a few times. I pressed the RED CROSS box after selecting each file and delete on reboot though.
I received a PendingFileRenameOperations prompt also and clicked OK.
Attached files for HJT(hijackthisOct01.log) and Shownew(newfiles4.txt) as requested.
I noticed that !Killbox including the bad files is located on Local Disk C:\ after using explore to upload files.
I look forward to hearing from you. Thank you.
Steve

Last edited by Grumbles; 07-07-07 at 17:07..
Reply With Quote
  #10  
Old 10-01-06, 23:36
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Quote:
Originally Posted by happyhibby
I could not install Sun Java (I already have this version installed)
No you do not! You are still using Java 2 Runtime Environment, SE v1.4.2_03 which is WAY out of date. Click the link I gave you and installe the 5.0 update 9 version. Then uninstall the old version. You also did not Uninstall Viewpoint Media Player as I requested. Are you misreading the directions???

Complete the above steps now! And attach a new ShowNew log afterwards!

Downloaded Process Explorer and Pocket Killbox.

Quote:
Originally Posted by happyhibby
Turned off Firewall and NAV as instructed then unplugged cable.
While it does not matter at this point, the directions did not say anything about turning of your firewall and shutting down your antivirus application.


How is everything working now?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
Sponsored links
  #11  
Old 10-02-06, 15:12
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

SORRY for wasting your time - i did mis-read the instructions.
I have installes Sun Java 5.0 update 9 version and un-installed SE v1.4.2 and Viewpoint Media Player.
I have attached new Shownew log.
Thanks

Last edited by Grumbles; 07-07-07 at 17:07..
Reply With Quote
  #12  
Old 10-03-06, 14:17
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

You forgot to tell me how are things working now?

Run Pocket Killbox and select File, Cleanup, Delete All Backups!

Also delete the C:\fixme.reg registry patch file.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #13  
Old 10-03-06, 15:24
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

I have only been using the Internet to check your site previously so haven't had a chance to surf any sites.
I have now deleted fixme.reg and run Pocket Killbox, this came up with the Trojan Horse problem, and I clicked OK and did tools;clean up back-up files again and it was gone.
What should I do now? Can I turn System restore back on yet?
Steve
Reply With Quote
  #14  
Old 10-04-06, 11:47
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Quote:
Originally Posted by happyhibby
What should I do now? Can I turn System restore back on yet?
It should not have been off yet!

If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

After that, you should work thru the below link:

How to Protect yourself from malware!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #15  
Old 10-05-06, 09:52
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Ok will carry out these steps. My Internet connection has failed, cannot access at the moment. Contacting you through work PC, and will update you on progress asap. Please bear with me.
Thanks
Steve
Reply With Quote
Sponsored links
  #16  
Old 10-05-06, 10:52
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Quote:
Originally Posted by happyhibby
My Internet connection has failed, cannot access at the moment. Contacting you through work PC, and will update you on progress asap.
Is this a new problem? I thought things were working! Do you have new malware issues or is this a phyiscal problem with your ISP?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #17  
Old 10-09-06, 07:57
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Hi I am still unable to access IE at home - Local Exchange/ISP technical fault. I will be on-line again soon. (Using Work PC just now)
Norton AV did its weekly scan and found 6 registry errors, should I OK NAV to repair them? Or is this the changes that you made when deleting the virus?
Steve
Reply With Quote
  #18  
Old 10-10-06, 02:42
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 62,523   (View Stats)
Thanks: 36
Thanked 3,318 Times in 1,268 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Quote:
Originally Posted by happyhibby
Norton AV did its weekly scan and found 6 registry errors, should I OK NAV to repair them? Or is this the changes that you made when deleting the virus?
I have no idea. You would have to give me a log of what it is finding and what we did would not be registry errors.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."
Reply With Quote
  #19  
Old 10-10-06, 08:31
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

There is a Local Exchange problem where ISP/telephone company have been doing cable work and has knocked out my connection. ISP are doing their best to connect me.
When I get back on-line at home, I will attach whatever log you want to check registry 'problems' that NAV is identifying?
PC seems to be performing ok, but haven't been able to check Internet as yet.

Thanks for your patience and help.
Steve
Reply With Quote
  #20  
Old 10-10-06, 13:05
Grumbles's Avatar
Grumbles Grumbles is offline
Bamboozled Geek
 
Join Date: Sep 2006
Location: Mickey Mouse Clubhouse
Posts: 1,781   (View Stats)
Thanks: 30
Thanked 6 Times in 6 Posts
Not Ranked  0 score     
Default Re: WinAntiVirus - FixVundo solution

Thats me back online again, no sign of WinAntiVirus or pop-ups.
What can i send u regarding Registry?
Steve
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 14:26.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Ad Management by RedTyger