Vundo/combofix problems / Win2000 Pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by ammendol, Feb 12, 2008.

  1. ammendol

    ammendol Private E-2

    Hi Major Geeks,
    I am in the middle of trying to rid my computer of a virus called Vundo and would like to enlist your services.

    I have read numerous other forums and following your cleaning advice in READ & RUN FIRST and was downloading the software tools in the Win 2000 Cleaning Procedures.

    So I have gotten to the point of running ComboFix.exe
    It went through its processing and make me reboot my computer...it got to the point in the reboot about to show my desktop with the traditional blue back screen provided by Windows and then...

    ...A Windows error box came up with a little circle with a red X in it. The headline read: C:\WINNT\system32\home:=\Combobatch.bat
    The message with in it read: Cannot find the file 'C:\WINNT\system32\home:=\Combobatch.bat' (or one of its components). Make sure the path and filename are correct and that all required libraries are available.

    It had an OK button at the bottom which I went ahead and pushed allowing my desktop to load. I'm also wondering if upon reboot my antivirus software was turned back on and played a role in the error?

    So I went into my C drive directory to find the combofix.txt file that should have been generated. When I open it up it said this:

    ComboFix 08-02.11.1 - Administrator 2008-02-12 13:38:25.3 - NTFSx86
    Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.98 [GMT -8:00]
    Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    PLEASE let me know what its telling me? Also, it hasn't changed my clock back to normal, hours are still going up to 23 (example 1pm is 13). Please advise me on my next move.
    Would you like me to run Hijack This and give you its log in my next post?
     
  2. ammendol

    ammendol Private E-2

    Attached is my MGTools log (MGlogs.zip)
     

    Attached Files:

  3. ammendol

    ammendol Private E-2

    Also here is my VundoFix.txt file
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not sure why ComboFix would not run properly for you. Yes it is possible that some protection software caused a problem. Let's ignore it for now and see if we can resolve any malware problems you have without ComboFix.

    It is not telling you anything at this point other than the fact that it never finished running. Whic is also the reason for your clock being changed to military time. Here is a fix for that:

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    No we do not want you to run HijackThis because it is already part of MGtools.

    I see you copied MSconfig from another Windows OS to your Windows 2000 system which does not normally have MSconfig; however you ignore the instructions in step 1 of the READ ME that specified that MSconfig must not be used to control startups and you are using it to control both normal startup processes and also a bunch of services. You must not use MSconfig like this. It was only meant to be used as a temporary debugging tool. See this link: Dealing with Startup Processes


    We only have a little malware remnants to cleanup.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {80C1BE10-F9C8-4E53-A106-90683FC52A57} - C:\WINNT\system32\vturp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [combofix] C:\WINNT\system32\kmd.exe /c C:\ComboFix\Combobatch.bat
    O20 - Winlogon Notify: fccaxwx - fccaxwx.dll (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. ammendol

    ammendol Private E-2

    Thank you for your help.

    You mention I am using MSConfig upon startup on my Win2000 machine but I am not sure on how to remove it. Do I simply delete the file C:/WINNT/msconfig.exe ? Nothing I was reading tells me what to do to remedy this. I am not moving forward on your directions until I am sure about how to remove MSConfig.
     
  6. ammendol

    ammendol Private E-2

    I renamed the msconfig.exe file to msconfig1.exe -- Hopefully that will work.

    Also attached are my log files you wanted.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!! This actually makes things worse and does not remove all the items stuck in the MSconfig registry keys. Rename it back to msconfig.exe and follow the steps below. Basically you just need to run MSconfig and select Normal Startup then reboot.

    The below is a direct quote from step 1 of the READ ME. Normally it does not apply to Windows 2000, but since you put a copy of MSconfig on your Windows 2000 PC it does apply to you.

    • You should be able to follow the instructions for Windows 98, 98SE, ME and XP Users

    How are things currently working? Any problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds