Adware.Vundo/Variant

Discussion in 'Malware Help (A Specialist Will Reply)' started by d.a.a, Feb 12, 2009.

  1. d.a.a

    d.a.a Private E-2

    Hi there..

    After running a SuperAntiSpyware scan, I've been informed that I'd been infected with Adware.Vundo/Variant, SAS claims to have solved the problem, but I'd like to be reassured by someone more knowledgeable than myself.

    The E:\ is my data drive, and I've recently formatted my C:\ to fix some malware issues. The E:\ contains few exe's and .dll's as it's primarily for general backups (steam, mp3's and avi's).

    Have run Ad-aware, AVG, Combofix, MBAM and SAS, none of which have detected anything after the deletion of the file with SAS. System restore was turned off after originally detecting the threat with SAS.

    Here's the HJT log:



    Any and all help appreciated!
     
    Last edited by a moderator: Feb 13, 2009
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Could you please attach the logs as opposed to posting them "inline". I would like you to attach logs from running the following: SuperAntiSpyware, MBAM, & Combofix. Also you need to run MGTools.exe which you can download from the below link:

    Using MGTools and download MGtools.exe using the black bold print link in the first sentence.Run this and also attach the log it generates, to complete all of the above will take 2 posts due to the max attachments limit being three for each post.

    Thanks
    Kestrel13!
     
  3. d.a.a

    d.a.a Private E-2

    Logs attached.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kes
     
  5. d.a.a

    d.a.a Private E-2

    Hi,

    Thanks very much. On another note; I'd like to know why ad-aware 'adwatch live' reported ntvdm.exe as a 'potential threat' after running MGtools. I'm sure it's just the nature of the program, but once again I'd like some reassurance.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a bug in Ad-Aware. ntvdm.exe is a process that belongs to the Windows 16-bit Virtual Machine. It provides an environment for a 16-bit process to execute on a 32-bit platform. It is an important part of Windows and when batch files like those used by MGtools and tens of thousands of other programs are run the ntdvm.exe process is required.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    Not much to do at all...


    1) Did you knowingly install WinPcap 3.1?

    2) Please go to Add or remove programs and uninstall the following software:

    • Java(TM) 6 Update 11


    3) Next...please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix exit HJT.

    4) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5) Also delete the below left over file from ComboFix:
    C:\WINDOWS\system32\CF14740.exe

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    ---! Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks,
    Kes.
     
  8. d.a.a

    d.a.a Private E-2

    Yes, I knowingly installed WinPcap, it is bundled with a program called "WC3Banlist". Is that a problem?

    I'd also be very interested to know what was done with the BHO file, what exactly was that?

    Do you think the 'vundo/variant' on my data drive (e:/) was actually active, considering it was in 'system volume information'?

    I've installed the new version of Java.

    System performance was never really an issue, I'm just a little paranoid, haha.

    Log has been attached.

    Thanks a lot for your help once again, very much appreicated.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No.

    Click-to-Call BHO relating to windows live messenger. The entry was dead so we cleared it's leftovers.


    I'll check it over after lunch and get back to you as soon as I can.

    You're very welcome :)

    Kes
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) You uninstalled an older version of Java but neglected to install the new version. Use post #7 step #4 to link to and grab it from there.

    2) Please navigate to the below and delete the old Avast directory:

    • c:\program files\Alwil Software
    3) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Dan\Local Settings\TEMP

    Your logs are clean...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. d.a.a

    d.a.a Private E-2

    All done -- thanks for your assistance once again!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome, safe surfing :)
     
  13. d.a.a

    d.a.a Private E-2

    Just quickly -- is there any free real-time anti-spyware that you personally recommend?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds