Persistent Vundo.B Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by SliceDiamond, Aug 3, 2008.

  1. SliceDiamond

    SliceDiamond Private E-2

    Hi,

    I've been infected with what appears to be the Vundo/VundoB/Virtumonde/Juan trojan for about two weeks. I've tried everything I can think of to get rid of this bug, but I can't seem to wipe the system completely. I'm assuming, from what I've read online, that it has infected my core system files, but none of the removal methods suggested have worked for me (including using Process Explorer in safe mode to suspend explorer.exe and winlogon.exe while 'debugging'). My various anti-spyware/malware programs find varying infections (and levels of infection), though my Avast seems to be the most consistent. I've run numerous programs numerous times over the course of the last two weeks, so I'm not sure how I can get my system any cleaner without some kind of intervention :-/

    Even though I seem to have gotten rid of the majority of the problem (popups and the like), my Spyzooka still sees it when I try to open a newly created image or text file (.doc files are fine). I get the following error message: "SpyGuard detected a known threat attempting to run: Name: Win32.Trojan.Vundo.B...", and my TrendSecure (I've been using TransactionGuard to avoid keylogging) occasionally catches malware attempting to phone the mothership. Unfortunately Spyzooka/Blue Penguin hasn't provided any support, even though I paid for the software. (grrr...) I did use both of the Symantec tools (for Vundo and VundoB) with no luck. I also used the VirtumondeBeGone and ComboFix last week, which seemed to weaken it. I did also try a couple of the specific VundoFix programs, but my Avast went completely bananas at those - it seems that most, if not all, of the Vundo-specific fixes are actually the virus itself (sneaky!).

    I went through the entire "Read & Run Me First Process" (including uninstalling old versions and reinstalling from scratch). SAS and Spybot didn't find anything, and MB found just the regular ol' Vundo. Can someone help me figure out how to get rid of the remains of this bug? At this point, I'm not even sure I'd know when my system is clean - it seems to be gone, but keeps popping back up when I least expect it.

    Thank you so SO much. I really appreciate any help or suggestions!

    I'm attaching the SAS/S&D/MB logs to this thread and will post the MGTools log to the next.
     

    Attached Files:

  2. SliceDiamond

    SliceDiamond Private E-2

    Persistent Vundo.B Infection logs part 2

    ...and the MGTools logs.

    Thanks!!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you purchase Spyware Doctor and does it include their antivirus or is it just the antispyware program?

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! If you still have detection, you need to attach alog the shows exactly what is being detected and where. If it is just in System Volume Information it is not a problem because that is System Restore and will be cleanup during final instructions.
     
  4. SliceDiamond

    SliceDiamond Private E-2

    Hi,

    I didn't buy Spyware Doctor...I just have the free download (anti-spyware only).

    I went through the process you listed (thank you!) and everything appeared to run smoothly - the programs ran exactly as they should and the .reg file was added successfully (I did get a success message).

    Some infection seems to remain though - I still get the SpyZooka alert for new .txt and image files (a SpyZooka scan doesn't turn anything up though), and I'm still getting pinged periodically by TrendSecure. I did some quick scans - the full scans take forever - and most came up clean, though a SpywareDoctor IntelliScan turned up a miscellaneous trojan and several registry bits that it identified as malware, labeled NirCmd. I saved that log (from today only) to text and attached it as well as the ComboFix and MGTools logs.

    I'm not sure what it is that the SpyZooka alert is catching - is there a way to find out where the remnants of the infection are? I'm afraid the SZ logs probably won't be very informative, since the scans were clean...I only get the log when I actively try to open a newly created file (so it's user-initiated). As far as the System Volume Information goes, I have System Restore disabled so there shouldn't be anything cached there.

    Thanks so much!!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then uninstall it as it is of no use to you and it is wasting system resources. Plus it is not detecting any real problems. Those are just from ComboFix.


    What???? New text and image files from what? As I said in my last message
    But since you say the logs come up clean then there is nothing to worry about. It is probably just wasting your time with unnecessary information about files that you are creating. Each time you run our scans .txt files will be created. There is nothing wrong with having new .txt files or image files which could just be things from browsing. I suggest that you dump SpyZooka too as it is not high on my list of applications worth using.

    What do you mean TrendSecure? You have Avast installed. Are you referring to an online scan? Online scans only run when you run them thus they would not be "pinging" you. You don't have anything from Trend Micro showing as being installed. If you did, I would be telling you that you need to uninstall either it or Avast.

    Your logs are clean!
     
  6. SliceDiamond

    SliceDiamond Private E-2

    Hi,

    Ok, I uninstalled both SpywareDoctor and Spyzooka (I only bought it originally for the guarantee, which they didn't make good on anyway).

    With the "new" files -- I was only having trouble (alerts) when I right-clicked on the desktop and created a new file from the 'new' context menu. Opening the program proper and just saving the file wasn't a problem. But now that I uninstalled SpyZooka I don't get any alerts, of course :) The TrendSecure isn't the full program, just the little fragment that it installs when you run TransactionGuard from their website (I was using it for billpaying because I'd read that Vundo included a keylogger). It only runs during the browser session in which I initiated the TransactionGuard. * shrug *

    (I wish I'd had Avast from the beginning - I was running AVG, but it not only let the virus through but then also remained blissfully unaware that there was a problem even when the virus was at its most active. Oy.)

    If you say the system is clean then I believe you :) Thank you so much for your help!! I really appreciate your time and effort!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Vundo is not a keylogger.

    Avast does no more to stop Vundo infections or remove them than AVG does. We get people here everyday with Vundo infections and it does not matter which antivirus program they are using. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  8. SliceDiamond

    SliceDiamond Private E-2

    Awesome...what a huge relief to have a clean system!

    Again, thanks so much for all the help - and the program recommendations and tips for future prevention (incredibly informative). I'll be sure to share them and hopefully decrease the number of frantic threads you may receive in the future :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds