Malware-Vundo, Virtumondo

Discussion in 'Malware Help (A Specialist Will Reply)' started by donnie39, Mar 24, 2008.

  1. donnie39

    donnie39 Private E-2

    Having a problem with Vundo & Virtumondo. I have run Superantispyware,
    Spybot S&D (will not fix problems, it freezes )
    ComboFix and MGtools The main problem now is that Internet Explorer is
    really slow, it can take up to a minute to load a page. I have done as much
    as I can from the info in your forums and I could use some help
    MGlogs.zip is uploaded. Thanks......Don
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the other two logs that were requested. That is the below logs
    • SUPERAntiSpyware
    • ComboFix
    Also your logs look like you have been experimenting on your own! You appear to have removed all of your startup items which is a bad idea since you are defeating the purpose of your protection software and other necessary items that need to run at startup. Thus I have to ask, what have you been doing on your own or at another forum before you came here? I see tons of backups for HijackThis in your C:\MGtools\backups folder but you are a first time poster here and many of the dates on these backups are very old (as far back as 2006). MGtools was not even around in 2006. Did you move older versions of backups from your using HijackThis into this folder??? Whatever you fixed with HijackThis or Mar 22, 2008 should all be restored from the backups. And it may be a good idea to even restore all items from 2008.

    I also see SpySweeper and Spyware Doctor installed. Are these paid versions or free trials?
     
  3. donnie39

    donnie39 Private E-2

    I have attached the files as requested
    Yes I did try to get rid of the problem before I found your forum site,
    I ran Vundofix, Spyware Doctor, and scans from Symantec and Mcafee.
    I cant explain all the backups for Hijack as I have only had this problem since
    March 20 or 21-2008 I did as you asked & restored the backups for March
    22-2008 and all the rest seem to be gone?
    Spysweeper is paid for ( an older version )
    Spyware Doctor is a trial ( it will find problems but not fix )
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay please rename: C:\Documents and Settings\Don & Lin\desktop\cc.exe

    to C:\Documents and Settings\Don & Lin\desktop\cf.exe

    as requested in the READ ME.

    The uninstall Spyware Doctor right now before continuing.

    Okay then I will need a new log now from MGtools. You can get this by doing the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
  5. donnie39

    donnie39 Private E-2

    Okay please rename: C:\Documents and Settings\Don & Lin\desktop\cc.exe
    to C:\Documents and Settings\Don & Lin\desktop\cf.exe ( Done )

    Then uninstall Spyware Doctor right now before continuing (Done )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. ( Done )

    Then attach the below log:
    C:\MGlogs.zip
    ( Done )
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have System Mechanic Pro installed. Does it include an antivirus program?


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Boonty Games
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {0C75ACF4-21E0-45A3-80C7-82E13448AB56} - (no file)
    O2 - BHO: (no name) - {25E041C4-46ED-4A30-99C2-0F8D335362B6} - (no file)
    O2 - BHO: (no name) - {297EFD4B-B291-4939-85C3-89E44F2A0CB7} - (no file)
    O2 - BHO: (no name) - {594D87DA-625C-4D56-8E5D-AE3C19C61F9E} - (no file)
    O2 - BHO: (no name) - {5BE86863-E6C4-407A-A775-B0AD328DB322} - (no file)
    O2 - BHO: (no name) - {6DBE99D8-3BCA-4034-B81D-E049F056BC9A} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8135B50F-2E40-4E24-A5E7-8A36B40FCB7E} - (no file)
    O2 - BHO: (no name) - {88C07ADE-4C96-4DFA-9C55-2EEB747730BD} - (no file)
    O2 - BHO: (no name) - {8DD9D658-9FD2-40F9-9116-3862A421FD2D} - (no file)
    O2 - BHO: {0fab9b26-73cc-f8fb-ec34-91fa978fe049} - {940ef879-af19-43ce-bf8f-cc3762b9baf0} - (no file)
    O2 - BHO: (no name) - {A18C2F24-8FD5-4067-9D74-93904D0B4087} - (no file)
    O2 - BHO: (no name) - {C35F97C7-D178-413B-BA3C-0E3DF83640F9} - (no file)
    O2 - BHO: (no name) - {EDE4241C-BA98-4BD9-A16C-C9A38D91C320} - (no file)
    O2 - BHO: (no name) - {F48461B8-ECC7-42C5-805A-678021D40873} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k to continue.

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Don & Lin\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. donnie39

    donnie39 Private E-2

    *You have System Mechanic Pro installed. Does it include an antivirus program

    Yes, it does have antivirus, but it is Version 5 and a bit out of date.
    I am using McAfee now.

    *Run C:\MGtools\analyse.exe
    These three lines did not show in the scan:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {A18C2F24-8FD5-4067-9D74-93904D0B4087} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k to continue

    *C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
    (done)
    My PC is working better, no more persistant pop-ups and internet explorer worked fine for a few minutes after I ran the last list of fixes from you,then it became slow loading pages again. This may be unrelated to the Malware problem although it seemed to start around the same time. Spybot only shows one item now, Win32.tiny.abk it will fix it but it shows up again on the next run. Anyway Thanks so much for all your time and help with this problem ......
     

    Attached Files:

    Last edited: Mar 27, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The you need to uninstall the antivirus part of System Mechanic. If that is not possible, uninstall all of System Mechanic. You must not have more than one antivirus installed.


    That is correct. It is not malware. It may be McAfee or the combination of McAfee, System Mechanic and the things Symantec is loading. It may also be due to the updating to SP3 that you did around Feb 12. However these are not issues for the malware forum.


    Attach a log from Spybot that shows what it is finding. Your other logs are clean.
     
  9. donnie39

    donnie39 Private E-2

    *The you need to uninstall the antivirus part of System Mechanic.
    My mistake, it was not installed!
    *Attach a log from Spybot
    (Uploaded) I have also zipped the win32.tiny.abk file. It is created in C:\windows\temp folder.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back at the end of message # 5, I asked you to manually delete all files in those two Temp folders. Did you do that when requested? Did they come back (I'm guessing yes)?

    If so, does C:\WINDOWS\Temp\7CF28762C38CA0D4.tmp still exist now?
    If so, can you delete it?

    There may be more than one file like this and that is why I had ask you to delete all files in the folder in message # 5. I had seen the below:
    Code:
    "C:\WINDOWS\Temp\"
    745c6e~1.tmp  Mar 25 2008      262144  "745C6E9ECB8F4863.tmp"
    7cf287~1.tmp  Mar 25 2008      182609  "7CF28762C38CA0D4.tmp"
    8af12a~1.tmp  Mar 25 2008      262144  "8AF12AB59DCE7145.tmp"
    ae8ab4~1.tmp  Mar 25 2008       70007  "AE8AB41F91F72503.tmp"
    And all of these need to be deleted.

    These may or may not even be problems. They could just be temp files from something you run; however things in these folders are not required (i.e., they are temp files) and we can delete them. If they return, something that is being run on the PC is creating them.

    Questions have been asked over at Spybot's Forum but no one ever addresed it: http://forums.spybot.info/showthread.php?t=23627

    Let's dig deeper. Please run this Running GMER to detect rootkits and attach the log. Perhaps we have a rootkit.
     
    Last edited: Mar 28, 2008
  11. donnie39

    donnie39 Private E-2

    *Back at the end of message # 5, I asked you to manually delete all files in those two Temp folders. Did you do that when requested? Did they come back (I'm guessing yes)?
    Yes, they were deleted and they did come back, in fact I deleted them a few minutes ago add they reappeared while I was looking at the folder! Thats when my PC went back into slow mode.

    *If so, does C:\WINDOWS\Temp\7CF28762C38CA0D4.tmp still exist now?
    If so, can you delete it?

    Yes it will delete but is one of the ones that come back.

    *Let's dig deeper. Please run this Running GMER to detect rootkits and attach the log. Perhaps we have a rootkit.

    Looks like you may be on to something! The log shows 4 bad entries.
    (log attached)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Run GMER again
    • Click the tab called Processes and click the Safe... button.
    • Your computer will reboot and the Gmer screen will open.
    • Click Files... and browse to the following file:
      C:\WINDOWS\system32\ras\slipmenu1.scp
    • Now click Delete
    • Now click the Services tab.
    • Click the entries in red one by one with your right mouse button and then click Delete... Answer Yes to all the warning windows.
    • When you've removed all the Service entries in red, reboot your computer.
    • After Reboot run GMER again and save a new log.
    • Attach the new log.
    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now check your C:\WINDOWS\Temp folder for any of those TMP files we have been deleting and if you find any, delete all of them. Now check to see if they come back. If they do not come back right now like they used to then reboot and make sure that they do not come back after a reboot. Let me know the results.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.


    Make sure you tell me how things are working now!
     
  13. donnie39

    donnie39 Private E-2

    *Run GMER again (done)

    *Attach the new log.(done)

    *Run avenger.exe by double-clicking on it.(done)

    *Now run Ccleaner!(done)

    *Now check your C:\WINDOWS\Temp folder for any of those TMP files we *have been deleting and if you find any, delete all of them. (no, they were not there!)

    *Now check to see if they come back. (did not come back)
    If they do not come back right now like they used to then reboot and make sure that they do not come back after a reboot. (no, still not back.)

    *Now run Ccleaner!(done)

    *Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then *attach the new C:\MGlogs.zip file that will be created by running this and *also attach the log from Avenger.(done)

    SO far so good, internet explorer seems to be working at it's normal speed
    and everything else is back to normal!! Thanks Again.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    3. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds