Vundo woes

Discussion in 'Malware Help (A Specialist Will Reply)' started by rewn, Dec 11, 2008.

  1. rewn

    rewn Private E-2

    Ok,

    Using Firefox after a while killed my internet via web, i could still use MSN and ping etc, but couldn't surf through Chrome or IE ( or FireFox )

    I started cleaning numerous times with SUPERAntiSpyware Professional and Malwarebytes' Anti-Malware but that infected files just came back.

    So i googled, and here i am.

    Following are the files from the scans i followed from the above sticky.

    I'm not even sure if it's fixed. I scanned again and it found an infected file %$(*#%(*#

    HKEY_CLASSES_ROOT\CLSID\{bf0ca4fc-6378-4062-b546-3cde8a28b1e0}

    always needed a reboot to get rid of it, always came back.

    Anyways, i followed the instructions up above perfectly and here are the results.
     

    Attached Files:

  2. rewn

    rewn Private E-2

    And the 4th log as attached.

    Any input would be appreciated, i've been banging my head for 4 days now :(
     

    Attached Files:

  3. rewn

    rewn Private E-2

    So i just tried Firefox, and after a few minutes, BOOM, lost all web browsing through any browser

    :(
     
  4. rewn

    rewn Private E-2

    As an update, it's not Firefox :( Was using Chrome last night and boom !
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You really should read ALL the stickies in the forum. Especially the below one:

    Don't Bump! It Only Hurts You!!!

    All the additional posts are bumps and the last one alone cost you a few days of additional waiting time.


    I suggest that you uninstall FireFox and Chrome and then reboot your PC. Then after reboot delete the Mozilla Firefox folder and all folders related to Chrome.

    Please attach the below logs from SAS and MBAM which obviously show more info than the ones you attached. This is why the READ & RUN ME requests to only run scans once and attach the logs. We need to see what is initially found.
    Code:
     
    "C:\Users\z\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log  10 Dec 2008       55432  "SUPERAntiSpyware Scan Log - 12-10-2008 - 04-22-04.log"
    supera~2.log  10 Dec 2008       52095  "SUPERAntiSpyware Scan Log - 12-10-2008 - 19-05-49.log"
     
    "C:\Users\z\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt  10 Dec 2008        1401  "mbam-log-2008-12-10 (19-33-05).txt"
    mbam-l~3.txt  11 Dec 2008        1138  "mbam-log-2008-12-11 (07-07-45).txt" 

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    If everything is working OK, you can reinstall FireFox and Chrome.
     
    Last edited: Dec 14, 2008
  6. rewn

    rewn Private E-2

    Ok,

    After going through the torment of working out I had to uninstall Online-Armor in safe mode I finally made some progress.

    I can't attach the requested older log files from Malwarebytes' Anti-Malware and SUPERAntiSpyware Professional as they aren't available in the log list anymore.

    I followed your instructions as per uninstalling Firefox and Chrome and running ComboFix and CFscript.txt

    I got sopme sort of GREP error when it was compiling the logs. Program error that I had to click on a windows generated screen to accept.

    I ran CCleaner.

    Also got a HijackThis error ( see attached file ) when running GetLogs.bat

    I lost my DNS Gateway settings for my wireless and network connections so couldn't connect to the internet afterwards, which I added back in to fix it.

    Unfortunately I still get the virus errors when running SUPERAntiSpyware Professional. I have included the log file of that as well as the other two requested log files, ComboFix.txt and MGlogs.zip ( and the image of the HijackThis error )
     

    Attached Files:

  7. rewn

    rewn Private E-2

    And the SAS log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can. Just attach the files that I listed. They are still on your PC.

    Run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log.
    Then reboot and run another scan with SUPERAniSpyware to see if it comes back clean or still has detections.

    What is the below new folder?
    Code:
    2008-12-12 21:32 . 2008-12-15 22:05 <DIR> d-------- c:\users\z\{6652914d-ae8f-4a9b-8ac9-3a15eae386ed}
     
    Last edited: Dec 18, 2008
  9. rewn

    rewn Private E-2

    Na, I ran the tool a dozen more times and they were overwritten :)

    The new folder was for Online Armour de-installation.

    OMG yes, it worked !! :)

    See two logs attached, first one found trojans, second one clean.

    Now i shall re-install Online-Armor and pay for full version.

    And upgrade to SUPERAntiSpyware for real time protection.

    I have SpywareBlaster for non real time scanner ?

    And of course I have AVAST anti virus running.

    Will this do ?

    BTW THANKS heaps.

    I'd like you to private message me so i can paypal you enough for a case of beer !! :D
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They are still there as I already stated. It does not overwrite the logs. Each time they run, a new log is created using the current date and time stamp.;)



    If you are not having any other malware problems, it is time to do our final steps which should also address your concerns about protection:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds