Please help me remove vundo and its evil friends from my system (1 of 2)

Discussion in 'Malware Help (A Specialist Will Reply)' started by steveneedshelp, Dec 10, 2008.

  1. steveneedshelp

    steveneedshelp Private E-2

    I've run the complete "READ me FIRST" procedure from start to finish and have attached logs to this and the following message. Thanks in advance for any advice you can give me! This malware infection is stubborn..
     

    Attached Files:

  2. steveneedshelp

    steveneedshelp Private E-2

    Please help me remove vundo and its evil friends from my system (2 of 2)

    here are other logs the procedure gave me...
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks, steve

    Just a short post to let you know I'm looking over your logs.. please be patient.

    Thanks!
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, steve

    *Your desktop needs a clean-up! An un-organized & messy desktop provides a perfect hiding place for malware.

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Step 1:
    If you have not already done so, please disable the Guest account in User accounts.

    Step 2:
    There are remnants of Norton on your machine. Run the below tool, re-boot, then run it again.

    Norton Removal Tool (SymNRT)


    Step 3:
    Look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.

    Step 4:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 5:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    symlcsvc
    
    Registry::
    
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 6:
    Now - reboot your PC

    Next - run Ccleaner


    Step 7:
    Now install the latest Sun Java Runtime Environment


    Step 8:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
    dr.m
     
  5. steveneedshelp

    steveneedshelp Private E-2

    Ok, so I followed your instructions and nothing went wrong. Attached are the two logs. I'll rerun the cleanup procedure to see if anything pops up this time around and update you sometime tomorrow.

    Thanks for your help so far!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    steve -

    You'll re-run what "cleanup procedure"?
     
  7. steveneedshelp

    steveneedshelp Private E-2

    Sorry for the ambiguity. Should I wait for you to review the recent logs before running the "Windows XP Cleanup Procedure?"
    (superantispyware, malwarebytes, etc.)
     
  8. steveneedshelp

    steveneedshelp Private E-2

    I've rerun superantispyware and malwarebytes and decided to stop there, because I don't want to be doing things to change my computer while you're reviewing my logs.

    I've attached the logs of infections from both of these programs, and will await further instruction.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are items in your logs that are not getting removed!

    Run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log. Do the exact same with Malwarebytes.

    Then reboot and run another scan with SUPERAniSpyware and Malwarebytes to see if they come back clean or still has detections. Let us know.
     
  10. steveneedshelp

    steveneedshelp Private E-2

    Okay, I ran reset.cmd like you told me too, rebooted, and both spyware programs after that, rebooted again. And then I reran the superantispyware and malware bytes.. and trojan.vundo is still there.

    Here are my logs from the most recent scans of those programs.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  12. steveneedshelp

    steveneedshelp Private E-2

    WHEW!

    Finally I have a clean scan.. That latest SAS did the trick. Here are my logs. Are there any further scans I should run to look for other trojans, etc?

    I'm resetting my firewall's program permissions (Comodo) so however the trojans got in is hopefully closed..
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Glad to hear the good news, steve.

    If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  14. steveneedshelp

    steveneedshelp Private E-2

    Just wanted to follow up and say that everything on my computer is fine. Thanks so much for your help in December!
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds