Vundo just won't die!

Discussion in 'Malware Help (A Specialist Will Reply)' started by JohnSais, Nov 23, 2007.

  1. JohnSais

    JohnSais Private E-2

    Hello
    I would greatly appreciate your help with this nightmare virus! I first detected it using AVG AV and Spybot S&D. On checking this forum I discovered VundoFix and ran that, which seemed to help for a day then it was back. Since then the system seems to clear itself every day on virus check, then by the next day there are on average 7 viruses back in. Spybot can only ever find Vundo, which it heals each time.
    I have followed the directions in Read and Run Me first slavishly, the only thing which doesn't seem to work for me is running in safe mode with internet access, so had to run the last checks in Normal.
    The various programs have thrown up all sorts of different problems, so I'm not quite sure now what infections I have! I hope you can help. BTW, the GetRUnKey program would not generate a runkeys.txt file, only a bunch of XRKey.txt files, I tried it 3 times with the same result.
    I really hope you can help - one moment of inattention has brought all of this upon my head and having read all the posts I've got a lot of work to do if this bug is fixed to get the computer safe again!
    Many thanks
    John
     
    Last edited: Nov 27, 2007
  2. JohnSais

    JohnSais Private E-2

    Here is the NewFiles.txt file, not sure what to do about the RUnKey files, there are 10 of them...

    Thanks
     
    Last edited: Nov 27, 2007
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see the following for the empty logs:
    Using ShowNew
    Using GetRunKey
    Note the possible errors and their fixes.

    Now:
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  4. JohnSais

    JohnSais Private E-2

    Hello, and many many thanks for your quick response and excellent help.

    I've run all the steps as per instructions, however even with the fixes I do not get an error message for GetRunKeys and still don't get any txt file, except for the 10 XRKey.txt files in c\. I've even done a file search in case it got put somewhere else, no joy. I've searched the forums here but can't find anyone else who has had this problem? So not sure what to do now.

    However, here are the
    ShowNew
    HJT
    Avenger

    log files, and as for the GetRunKeys file, don't know what to do?

    Thanks again
    John
     

    Attached Files:

    Last edited: Nov 27, 2007
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run HJT and have it fix this item:
    O20 - Winlogon Notify: winwim32 - winwim32.dll (file missing)



    Download the attached GetRunKeys.zip file into the same folder as you downloaded them before. Extract the GetRunKey.bat file from the ZIP file into that same folder thus overwriting the current version that is there.

    Now run the GetRunKeys.bat file by double clicking on it. Then attach the newGetRUnKeys.txtfile that will be created by running this.
    Attached Files http://forums.majorgeeks.com/images/attach/zip.gif GetRunKey.zip (11.2 KB, 2 views)
     
  6. JohnSais

    JohnSais Private E-2

    Hello and thanks

    Reran HJT and fixed that line entry.

    Tried again as instructed with GetRunFiles but with exactly the same result. No GetRunKey.txt file in the root directory at all. Can't think what's wrong with it?

    John
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall the tools (ShowNew. GetRunKeys, HJT) ....then download this: Using MGtools
     
  8. JohnSais

    JohnSais Private E-2

    Hello & thanks

    Do you mean just delete these, as there is no uninstall information? Sorry to seem stupid but I want to do this right! HJT won't uninstall from Add/Remove programs, says it may have been uninstalled already?

    John
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the folders and choose delete ..... I think we have some of the major stuff handled but I want to see those two logs.
     
  10. JohnSais

    JohnSais Private E-2

    MGTools doesn't work either - creates the MGTools folder in the root directory, MG.exe in the root dir but no MGLogs.zip files, or any of the other .txt files.

    The DOS window opens but closes too quickly to see if there is an error message there. I tried Fix 1 on the list, but don't want to try Fix2 unless certain as don't want to play around with the registry if it's not that...

    Is this me being really dumb here?

    John
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you double click the exe file to get it to run?
     
  12. JohnSais

    JohnSais Private E-2

    Yes, no logs generated in c:\ or the mgtools folder either

    Gonna give up now & go to bed - 2am here in UK!

    Thanks
    John
     
  13. JohnSais

    JohnSais Private E-2

    I managed to Pause the c:\windows\system32\cmd.exe screen and there are no error messages at all, only the guide 'blurb' at the top of the screen (see pasted info below). Under that it is just blank, no log files are generated and no error messages appear. The msdos box just disappears straight away.

    ******************************************************************************
    * GetLogs.Bat - (c) 10/02/2006 By Chaslang *
    * This small batch file is just used to automatically run GetRunKey.bat and *
    * ShowNew.bat. It is normally just called after installation of the two *
    * programs into the C:\MGtools folder but it can be run at anytime. *
    * Mods: 07/26/2007 Version 2.00 beta *
    * Mods: 09/14/2007 Version 2.01 beta - add auto HJT log *
    * Mods: 10/16/2007 Version 2.02 beta - add auto ProcessDLL log *
    * Mods: 10/24/2007 Version 2.03 beta - silent HJT *
    * Mods: 10/24/2007 Version 2.04 change order of scans that run since *
    * sometimes HJT log or GetUnKey log was missed due to slow PC. *
    * Also remove Win9x and ME support from this version. *
    * Mods: 10/27/2007 Version 2.05 Remove Win9x and ME support *
    ******************************************************************************

    That's all there is, nothing else at all.

    Confused and fed up, only good thing is the PC is running well and I have not encountered any more popups and AVG is coming up clean, as is asquared, give or take the odd medium risk entries which I have quarantined.

    Hope we can resolve this so that I can put this nightmare behind me at last!

    Thanks
    JOhn
     
  14. JohnSais

    JohnSais Private E-2

    Hello again, just another update

    Just run Spybot S&D, came up with 2 more entries:

    MediaPlex (SBI $4CDCC3D5) Tracking cookie Internet Explorer cookie:john@mediaplex.com/

    Virtumonde: [SBI $1F8EC695] Settings (Registry key, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR

    MediaPlex: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: John) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.5 (build: 20070830) ---

    2007-08-31 blindman.exe (1.0.0.6)
    2007-08-31 SDMain.exe (1.0.0.4)
    2007-08-31 SDUpdate.exe (1.0.6.4)
    2007-08-31 SDWinSec.exe (1.0.0.8)
    2007-08-31 SpybotSD.exe (1.5.1.15)
    2007-08-31 TeaTimer.exe (1.5.0.9)
    2007-11-22 unins000.exe (51.46.0.0)
    2007-08-31 Update.exe (1.4.0.5)
    2007-08-31 advcheck.dll (1.5.3.0)
    2007-04-02 aports.dll (2.1.0.0)
    2007-04-02 DelZip179.dll (1.79.5.3)
    2007-08-31 SDHelper.dll (1.5.0.8)
    2007-08-31 Tools.dll (2.1.2.0)
    2007-11-21 Includes\Cookies.sbi (*)
    2007-10-31 Includes\Dialer.sbi (*)
    2007-11-21 Includes\DialerC.sbi (*)
    2007-11-07 Includes\Hijackers.sbi (*)
    2007-11-21 Includes\HijackersC.sbi (*)
    2007-10-04 Includes\Keyloggers.sbi (*)
    2007-11-21 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2007-11-07 Includes\Malware.sbi (*)
    2007-11-21 Includes\MalwareC.sbi (*)
    2007-10-24 Includes\PUPS.sbi (*)
    2007-11-21 Includes\PUPSC.sbi (*)
    2007-11-21 Includes\Revision.sbi (*)
    2007-05-30 Includes\Security.sbi (*)
    2007-11-21 Includes\SecurityC.sbi (*)
    2007-11-07 Includes\Spybots.sbi (*)
    2007-11-21 Includes\SpybotsC.sbi (*)
    2007-11-06 Includes\Tracks.uti
    2007-11-14 Includes\Trojans.sbi (*)
    2007-11-21 Includes\TrojansC.sbi (*)
    2008-12-24 Plugins\TCPIPAddress.dll


    Spybot fixed the problems but this Virtumonde keeps coming up in almost every S&D I run, I think I'll never be rid of it! Is it a major problem as long as Spybot can remove it?

    Thanks for your help
    John
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you turn off Teatimer as directed in the Read and Run FIrst? It very well could be stopping the scans......and it is probably in your system 32 files as well as your reg keys that we need to see and remove....
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It seems like your PC could be having a problem with a couple of built in DOS commands that are part of Windows. It could be having an issue with the one of the below two commands:

    ver
    find

    Or it could be having an issue with what is referred to a the "pipe" command. A "pipe" is when the about of one command is forwarded to another command. This is what GetLogs.bat, GetRunKey.bat and ShowNew.bat all make use of when the check for the Windows version and then "pipe" the output to a "find" command to match a particular string. This string will tell us the Windows version. Try the below.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt. Enter the below commands in bold black at the command prompt and follow each by the enter key. I give you in bold purple what the output from the command should be.

    ver
    Microsoft Windows XP [Version 5.1.2600]

    find
    FIND: Parameter format not correct


    Are those two purple lines what you get?


    Also download the attached OStest.zip file and extract the Ostest.bat file from it. You can put it anywhere but I suggest you put it into the C:\MGtools folder if it exists. Then run the Ostest.bat file and tell me what you get for output. If is works properly, you should see something like below in the command prompt window:
    Code:
    Your Windows OS is Windows XP
     
    write down what you see for your OS before hitting a key.
    Press any key to continue . . . 
     

    Attached Files:

    Last edited: Nov 25, 2007
  17. JohnSais

    JohnSais Private E-2

    Hello again

    Firstly, for TimW, yes, I actually uninstalled and reinstalled Spybot with the Resident unticked so Teatimer is not running any more. Currently AVG AntiSpyWare Trial is running (until I can get Comodo installed), maybe this is the problem? Thanks for all your help by the way.

    Secondly for ChasLang, I got the purple lines as you quoted in response to the 2 DOS commands (good news). However, on the OSTest.bat file, running it only creates a blank cmd window and no text whatsoever (I paused it to make sure).

    Strange things are afoot!

    John
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It just confirms my suspicion about where the problem lies. Your PC cannot do pipes (also called redirection - which you can read about here: http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/redirection.mspx?mfr=true ) for some reason. This is problem within the Windows OS. This is not a malware related issue as far as I know and at this time I have no idea what a possible fix for it would be. The OStest.bat file is a very simple batch file that should easily run on all Windows PCs. There is nothing very complex in it.
     
  19. JohnSais

    JohnSais Private E-2

    Hello and thanks for all your help.

    I really don't know where to go from here. I've been running this PC for about 4 years now with no problems so don't understand why this 'pipe' issue has not shown up before? Just hope it hasn't been destroyed by a virus....

    If I run the ostest.bat file in cmd I get this:

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\John>cd c:\mgtools

    C:\MGtools>ostest.bat
    The system cannot find the file specified.

    C:\MGtools>


    although in Explorer I can clearly see the file in this folder and can run it, albeit without any result.

    I've hunted online for any clues to this 'pipe' problem but must confess to be scratching around in the dark. If you can direct me to anyone who might have an idea about it I would be very grateful. I'd like to know that this malware problem is fixed once and for all so that I can start using my computer safely again!

    Thanks
    John
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you probably never run any DOS type commands like this.

    I doubt it.


    This does not come from running ostest.bat. This comes from just opening the command prompt window.

    I wonder if it is saying it cannot find ostest.bat or if that message is due to when it tries to run something in the batch file. Try running this modfied version that I named OsTest2.bat that is in the attached ZIP file. Do you still get the same output? Are you sure you put ostest.bat and ostest2.bat into the C:\MGtools folder? Did you extract them from the ZIP file? Do the below at the command prompt while you are in the MGtools folder.

    dir > c:\filelist.txt


    Attach the c:\filelist.txt file to your next message.


    I have no idea at this point. I'm not sure what the exact cause is. All I can tell is that it looks like you cannot use the pipe form of redirection.

    Your malware is gone! We are just trying to figure out why you cannot run batch files properly.
     

    Attached Files:

  21. JohnSais

    JohnSais Private E-2

    Hello ChasLang and thanks for your help, I didn't mean to seem rude in my reply, I'm just so confused as to why I should be having so many problems!

    I have run OSTest2.bat and all I get is the following (on Pausing the command):

    Point 0
    Point 1

    and then the window closes (have to be quick with that Pause button!)

    Yes, the files are definitely extracted into the c:\mgtools folder, and I attach the filelist.txt file as requested.

    I used to run a lot of DOS commands in the 'good old days', in the days before hard disks were built in and everything was run in DOS, so it's odd that some commands will run OK and others not?

    Thanks again for your help
    John
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! ;) No offense was taken. :)


    Again this double confirms my suspicion. The OStest.bat file is failing as soon as it gets to the below lines:
    This is the first test in a series to determine the Window OS version. You are failing on the ver | find "Windows 2000">NUL
    which is the pipe command that I have been referring to.

    If you enter the below at the command prompt, what happens.

    ver | find "Windows XP"
     
    Last edited: Nov 26, 2007
  23. JohnSais

    JohnSais Private E-2

    You're a star! Glad I didn't offend, don't want to upset anyone here as you're all great guys!

    OK, ran ver|find "Windows XP" and got this:

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\John>ver|find "Windows XP"
    Microsoft Windows XP [Version 5.1.2600]

    C:\Documents and Settings\John>

    So looks like the | is doing nothing, right?

    (Putting a large boot on....!)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes from the command prompt, but maybe not from within a batch file.

    What happens if you enter the below from a command prompt:

    ver | find "Windows XP" > nul


    Do you just get a prompt back with no output? That is what should happen.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the OStest3.bat file from the command prompt after extracting it from the attached ZIP file


    What do get?
     

    Attached Files:

  26. JohnSais

    JohnSais Private E-2

    Hello

    Running ver | find "Windows XP" > nul just comes up with 'The system cannot find the file specified.

    Running OStest3.bat after unzipping gave this response:

    Point 0
    Point 1
    Point 2
    Microsoft Windows XP [Version 5.1.2600]
    Your Windows OS is Windows XP


    write down what you see for your OS before hitting a key.

    Press any key to continue . . .


    Hope that means something!

    John
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes John it does and thanks for helping us work thru this to determine what is really going on. Based on this last result form Ostest3.bat, it would seem that the problem is not really in the pipe form of redirection. The problem is in the redirection of standard output to a particular filename. On your PC (and not on literally thousands of others) the system does not understand the nul filename. Each test for Windows OS version redirects the standard output to a nul file by using the > nul at the end of the line. This was evident in the line I had you run:

    ver | find "Windows XP" > nul

    This is supposed just prevent the normal out from the ver | find "Windows XP" command from being seen when you don't want it to be seen (usually because it is not necessary and/or could cause confusion ). So this problem is fairly unique to your PC. I say fairly because thinking back, we may have run into a couple other cases overtime where a problem like this occurred but we were not able to work thru the details with the user to find out why. Which I again thank you for helping us to work this out.

    I can now give you a modified version of MGtools.exe to download that I want you to try running. Just download from this blue line to your C:\ folder and then double click on the MGtools.exe file to begin the installation and automatic running of all the scans. If this runs properly, you should end up with text like below on the last 7 lines in the command prompt window.
    Then attach the C:\MGlogs.zip that should result if all works well.
     
  28. JohnSais

    JohnSais Private E-2

    Hello again!

    Looks like you cracked it, never thought that you would be grateful for my problem, that must be unique!! Hey, I'm happy to help, I'll bring you all my problems if you want!

    This time it definitely worked, and attached is the mglogs.zip file as requested. Let's hope they all come up clean. PC is running fine so that's a good sign.

    Many many thanks for all your time taken to solve this, it's been a tricky one but one thing's for sure, I've learned a lot from this experience and now I'm fully protected as per the Malware prevention page on this forum so hopefully it won't be so easy to infect again.

    Fingers crossed for a clean scan!

    Thanks
    John
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :D Yes it is very helpful to us when we can get a user like yourself to work thru and find a solution to making our tools run better. We cannot debug a problem that we cannot create. Thus getting you to run steps to help us find the problem is the only way we can get to the bottom of the issue. Once I determined where the problem was actually coming from, I modified our tools to work around the issue that seems to exist on your PC (and maybe a few others we have seen). So it is sometimes a two way street where you can help us to help you better. ;) Thanks again! And the new tools were already officially posted since I was sure that this would work. ;)

    Not quite clean! We have some left overs from Vundo and Winlogonhook to cleanup and a few performance related things to remove with HijackThis.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  30. JohnSais

    JohnSais Private E-2

    ChasLang,

    You are da man! Everything seemed to go OK and the scripts ran and ran, they are attached for your info.

    I'm real glad to be of assistance, makes a change for a problem to actually be welcomed instead of dismissed as 'just another same old boring easy fix', and if this can help others then hey, I'm even happier! Your tools are excellent, although I'm sure you'd understand if I say that I hope I never have to use them again!! I'm now running Comodo firewall, Comodo BO AntiSpyware, AVG antivirus (had that before), Spybot S&D (running more regularly now) and asquared. Followed all the advice on the How to Protect Yourself page, so let's hope I can keep this from happening again.

    Immense thanks again, here are the logs, hope we're cooking now...!

    John
     
  31. JohnSais

    JohnSais Private E-2

    Guys.

    can't seem to attach the files - I've lost the attachments button!

    Little help please...?

    Thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome John!

    Empty your browser cache and then click refresh a couple of times. That usually fixes this. Let us know.


    Flusing the Internet Explorer Cache
    1. Run Internet Explorer
    2. Click Tools and select Internet Options
    3. Now on the General tab, click Delete Files and select Delete all Offline content too on the next window, Click OK. When it finishes Click OK.
     
  33. JohnSais

    JohnSais Private E-2

    Hey, one Firefox cache clear later and it's back! Funny, as I thought ATF cleaner would have done that....

    Anyhoo, here are the long-awaited logs! Hope they make sense, and that I'm finally clear.

    BTW, does anyone on the forum know how to fix a 'Limited Connectivity' on a home network connection? My laptop has started doing it for no apparent reason?

    Thanks again
    John
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Apparently ATF-cleaner and also CCleaner are not emptying your temp folders for some reason as I can see in your newfiles.txt log. Please goto each of the below two folders and manually delete everything in those folders. Windows will block you from deleting a couple of files from the current date. The first folder has over 1000 files in it and all those winxx.tmp files are from Winlogonhook.

    C:\WINDOWS\Temp\
    C:\Documents and Settings\John\Local Settings\Temp


    Other than the above needing to be emptied, you are clean and I will repeat finally procedures below even though you have already done some of them. You do need to repeat the removal of unnecessary files and also toggling System Restore.


    Also I'm curious. Are you a friend of David's? I refer to the below in your HJT log.
    O24 - Desktop Component 0: (no name) - http://www.davidparry.co.uk/images/bg8.jpg



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  35. JohnSais

    JohnSais Private E-2

    Thanks ChasLang, I've manually deleted all those temp folders and worked through the list you sent, do I need to remove the old restore points or not? I think I may have done this a week ago when I was using VundoFix, but maybe it needs doing again now?

    No, I don't know David Parry, is he someone famous? It was a website we were looking at when we were buying our house, so dunno what it's doing in there, could be deleted really now, dunno how though!

    Next time I will be much more careful, and with all the excellent tips in this forum there is no reason to get infected again.

    Thank you once again for all your help, and much as it grieves me as I've really enjoyed our little communications I hope I won't ever have to trouble you again with another problem like this. However if you want any more help with nul entries you know where to come!

    All the best
    Thanks again
    John
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was part of what I gave you in my last message. Notice step 10?

    No not famous. It just matches the name of someone I know in England. And I was curious. You can fix those lines as they are not important nor are they malware.


    You're welcome and thank you again too for helping us improve our tools. :)
     
  37. JohnSais

    JohnSais Private E-2

    Hello

    Sorry, I misread your last post, thought it said you do NOT need to toggle System Restore, my eyesight, getting old, etc....anyway, all files deleted and System Restore now back on.

    I guess to fix that rogue davidparry line I'll have to run hijackthis again, or is there another way?

    Anyway, thanks very much again (betcha sick of hearing that now!) and I'm going to be much more careful in future.

    All the best
    john
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that would be the easiest way to remove that.

    Never! ;) You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds