Please help. Vundo and SmitFraud fight back

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tarpon, Feb 2, 2009.

  1. Tarpon

    Tarpon Private E-2

    I've been battling Virtumonde, SmithFraud and Vundo since maybe Dec. 20, 2008. I've been able to remove most traces of them but SuperAntispyware detected adware.vundo.variant a few days ago, prompting me to run the tools again and found a few more traces. I still see a bad rundll.exe on Procexp with the properties of "C:\WINDOWS.000\system32\rundll32.exe "C:\WINDOWS.000\system32\fccyaXoN.dll",ShellPath." I'm convinced that something isn't fully cleaned.

    I could only run combofix in safe mode. In regular mode, it just hung or rebooted XP. I saw none of the stages.

    I'm attaching the most recent logs that show the situation. Please let me know what to do next to fully remove these beasts.

    Thanks.
     

    Attached Files:

  2. Tarpon

    Tarpon Private E-2

    Here's the zip from MGTOOLS.EXE.

    I followed the guide for how to remove SmithFraud a few weeks ago which seemed to work nicely. I have the earlier logs if that would be helpful for you.

    Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Deelet the below files
    C:\WINDOWS.000\SYSTEM32\rn.tmp
    c:\windows.000\Tasks\vesivqag.job

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC.
    After reboot, run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Tarpon

    Tarpon Private E-2

    Thank you for these instructions. The fixme.reg successfully updated the registry.

    So far, everything seems to be running fine. I haven't seen that bad rundll32 yet, but will keep looking and let you know if it recurs.

    I've attached the zip that you requested.

    Please let me know if anything else needs to be done.

    Thanks again.

    Majorgeeks ROCKS!
    :major:dancer:major:dancer
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. Tarpon

    Tarpon Private E-2

    Wow. I got some more malware today. Mostly Vundo. It looks like I had an infected restore point. If I have 3 user profiles on the machine, do I have to toggle System Restore for each one to flush the bad restore point? Or did a new infection get in?

    Thanks in advance.
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If it was just an infected restore point then toggle system restore on an account with Admin privileges and it will address the issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds