Virus from WMP codec - Vundo.gen!P

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lachy123, Aug 9, 2008.

  1. Lachy123

    Lachy123 Private E-2

    Heya I'm new to here and jumped on because I saw that many had this problem.

    I acquired a large amount of music from a friend of mine the other day and when indexing it in Windows Media Player library one of the files opened a blank webpage with a download box for a codec. Assuming (wrongly) it was because of different filetypes I accepted the download and no sooner had it downloaded but the file called codec.exe just vanished from the folder, followed Windows Defender going haywire with 'Trojan:Win32/Vundo.gen!P. The hard drive also became very active and computer performance took quite a beating.

    AVG didn't find anything which was strange. Then I read some posts on here and on other forums that say this is apparently quite an ugly infection.

    The first infected file was:
    C:\Users\LACHLAN\AppData\Local\Temp\nNETKBUo.dll

    ...and then 10 minutes later this one appeared:
    C:\Users\LACHLAN\AppData\Local\Temp\awtqoOGV.dll

    Both were hidden when I searched for them, so I tried deleting both files with Command Prompt. As expected it said it was in use so couldn't delete. After that my plan was to start up in DOS rather than windows and delete them then, but bless ole Gates and his company because Vista can't do that! (Referring back to the backbone, DOS, was always my safety in these situations. Why did they get rid of it!?!).

    I went into regedit and deleted this key associated with the second infected file:
    HKEY_CURRENT_USER\S-1-5-21-1204348373-3972926690-4038675117-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MSServer\(filename with *awtqoOGV.dll in its name)
    sorry I forgot the exact name but it had the suspect file so I figured it is better off deleted and it was also the same registry entry that Windows Defender indicated. However, I haven't found any entries regarding the first file, nNETKBUo.dll

    I also terminated a process related to AVG in Windows Task Manager because the filename didn't look familiar. When I did that hard drive activity abruptly stopped, so that might have been it. I then repeated my steps in Command Prompt and tried to delete both nNETKBUo.dll and awtqoOGV.dll but this time command prompt said these files don't exist. I am not sure if that means the computer is clean though...


    Now I read the READ & RUM ME FIRST document, but I am wary of disabling system restore because I just found out that half the restore points are located on the external HDD with all the important personal files etc. and I disconnected it the moment the virus came on. I am guessing I will have to reconnect if I want to flush out all the restore points, but just wondering if there is another way first?

    Cheers,
    Lachy.

    PS. Computer is Vista Home Premium SP1 32bit
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read it again. Unlike many websites and major antivirus companies, we do not make the mistake of disabling system restore before starting cleaning procedures. Our procedure only has you disable system restore once we have determined that all of your malware has been remove. And we will tell you when to do this after we have gone thru all of your logs and performed any manual cleaning that is required. So attach the requested logs from the READ & RUN ME and we will tell you what to do next.
     
  3. Lachy123

    Lachy123 Private E-2

    Heya I'm back. Sorry for the long gap in time.

    Just some interesting points. I accidentally ran MGTools before ComboFix but then wen't back and did them in order. So far all the logs (attached; I included the Spybot one for good measure) look completely fine with nothing reported. I think I might have deleted it earlier when I wiped the registry (hopefully, otherwise generation P is a sneakly lil bugger).
    Also when running the MGTools scan the program 'SteelWerX WhoAmI' stopped responding and had to close. Given the name of the program I am wondering if it is indeed a legitimate process or not...

    Cheers,
    Lachy.
     

    Attached Files:

  4. Lachy123

    Lachy123 Private E-2

    (Other two attachments)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is legit. It is used by one of the processes embedded in MGtools.

    Looks like you are in pretty good shape. We just have some finishing touches and then final instructions including toggling system restore. Obviously you should have your external drive connected when you toggle system restore and make sure you disable system restore on all drives.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now search for the below file on your hard disk and also on the external drive and if found, delete it.
    tmf3w3g0.com


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. Lachy123

    Lachy123 Private E-2

    Thank you very much.

    System is all clean and I did get the Success message when merging the registry.

    Now off to read 'How to Protect yourself from Malware' ;).

    Thanks again,
    Lachy.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds