Another Vundo Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by spivey, Oct 7, 2005.

  1. spivey

    spivey Private E-2

    I read the earlier thread on this page about the person with the Vundo problem. I'm experiencing the same issue as he is. Basically, it's put a .dll file on my computer that is running from the start and denying my access to delete it. I also have used both vundo removal tools that were listed in that thread. Neither even recognized the Vundo virus to be on my computer.

    The file is attached. I do not know much about computers, so I didn't want to just follow the instructions he was given, in case our individual cases are different.

    Thanks a ton in advance for the help.
    -Michael
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then it also must be installed and run properly but normally only after running standard cleaning procedures as given below.

    Please run the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note you do have more problems than just Virtumundo. I would also get rid of MyWay stuff from Dell although some think it is not spyware.
     
    Last edited: Oct 7, 2005
  4. spivey

    spivey Private E-2

    I ran all the stuff suggested in the sticky. Vundo is still there, though I did get rid of some other stuff. I have tried the 2 vundo fixes that were listed in the other thread (I think both are from symantec). Any help would be greatly appreciated. I didn't attach the new log, as it says to wait until it is requested. So someone request to see it! :)

    -Michael
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you ran ALL of the READ ME then complete the remain part of my previous message.
     
  6. spivey

    spivey Private E-2

    I assume you're talking about discussing the results? All that was found was a dozen tracking cookies on Ad-Aware SE (and Look2Me). None of the other programs (including the online scans) found any viruses or trojans, including the Vundo trojan. None of these other programs are anti-virus, are they? I assume that's why they didn't notice the Vundo trojan. I updated the definitions on all the programs, so that shouldn't be a problem.

    Let me know what you think.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well yes and no! There is still a remaining part:
     
  8. spivey

    spivey Private E-2

    I'm not exactly sure what to say about that. I downloaded it, unzipped it into C:/Program Files, and ran it from there. I've looked over the tutorial to get an idea of what the problems likely are (O20 is the .dll file the trojan created), but quite frankly I trust you more than I trust myself!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your missing the point! You need to post a new log now after following all the directions. In your first post you had not run the READ ME and HJT was not installed and run properly. You ran it from the ZIP file:

    C:\DOCUME~1\Michael\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
     
  10. spivey

    spivey Private E-2

    Wasn't sure you wanted it yet. Well, here is it. Enjoy!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should first go to the below link and get rid of the MyWay crap Dell put on your PC.

    http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=42328

    Then continue with the below.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so. We will reboot later in my next message.
     
  13. spivey

    spivey Private E-2

    Ok. I was playing a video game between posts, but I'll stay on now. I'll let you know when I'm done with your instructions.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing my previous steps, continue with the below. Hopefully the MyWay stuff is gone but I'm leaving in some removal for it below too.

    Please make sure System Restore is OFF and the How to view hidden, system files & folders! is Enabled as per the tutorial.

    Please print these instructions out for use in Safe Mode with no networking and DO NOT RUN any browsers while doing these steps.

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\system32\pmnlj.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\system32\jlnmp.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\pmnlj.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: pmnlj - C:\WINDOWS\system32\pmnlj.dll

    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Now after reboot, use Windows Explorer to delete the below folder if found:

    C:\Program Files\MyWaySA
    Now we need to Reset Web Settings:

    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now please attach a new HJT log from normal mode.
     
    Last edited: Oct 8, 2005
  15. spivey

    spivey Private E-2

    I have what might be a serious problem. I followed your instructions step for step. Yet my 'blue screen of death' did not go away. I'm not sure how to make it go away, and I'm not going to do anything until I get work back from you. Am I supposed to power off my PC? Or was this supposed to go away by itself? If so, what do I do now?

    Ah!
     
  16. spivey

    spivey Private E-2

    I'm on my roommate's computer, so that's how I'm posting.
     
  17. spivey

    spivey Private E-2

    Looks like I just missed you before you got off. After doing a little research online, i saw there were warm boots and cold boots. Since CTRL+ALT+DEL wasn't working, I went ahead and just cold booted it. It worked though, and the Vundo file is gone.

    Nerds. Is there anything they *can't* do?

    Seriously though, thanks a ton. And I'm a nerd too, just not a computer one.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but you should post the follow up HJT log I requested.
     
  19. spivey

    spivey Private E-2

    Here's my new log.

    -Michael
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  21. spivey

    spivey Private E-2

    How do you disable the firewall that's on Windows XP Special pack 2?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds