Can't Seem to Get Rid of Vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by webgyrl, Feb 7, 2007.

  1. webgyrl

    webgyrl Private E-2

    Hi,

    I've been scanning my computer for the last 48 hours, going step by step using the guide here for removal of the crap I seem to have been infested with.

    I'm Running Windows XP SP2 with Avast AV and ZoneAlarm. I also have Windows Defender, Lavasoft Adaware SE and WinPatrol (WinPatrol caught the Vundo things and I denied them access to be launched at startup, but the popups started...). I thought I was safe and secure, but apparently not!

    Of course, now I have a ton of new things installed since using the guide here. I've listed all that I have installed below.

    I can't get rid of Vundo it seems. I have tried using Vundo Fix and another app called VirtumundoBegone.

    I am still getting a notice that says this virus is on my system (when I ran Ewido).

    Can anyone find what I am missing? I've been pouring over this stuff and scanning and doing whatever I can for nearly 2 days now and I am in a state of numbness!

    I am attaching the following files:
    hijackthis0207.log (9.4 KB)
    txt.gif newfiles.txt (48.4 KB)
    txt.gif runkeys.txt (16.1 KB)

    I will reply to this and attach my other logs from the other scans I did.

    I'm SO tired from all this!!!


    Thank you to anyone who is kind enough to help me.

    Also, does anyone know if I should now unistall Ewido and CounterSpy... or should I leave them?

    I currently have the following security apps installed:

    Avast Anti Virus (Free)
    ZoneAlarm (Personal)
    CounterSpy (unactivated)
    Ewido Anti Spyware (Trial)
    WinPatrol
    SmitRem
    LavaSoft Ad-Aware SE Personal
    SpyBot Search and Destroy
    Microsoft Windows Defender

    Other helpful apps installed:
    MSConfig Cleanup
    CCleaner
    Hijack This 1.99.1
    Webroot Window Washer

    Thanks so much!
     

    Attached Files:

    Last edited: Feb 7, 2007
  2. webgyrl

    webgyrl Private E-2

    More Log Files

    More Log Files..


    Activescan.txt (1.1 KB)
    bdscan.txt (21.9 KB)
    CounterSpy.txt (2.3 KB)
     

    Attached Files:

  3. webgyrl

    webgyrl Private E-2

    And one more

    This is the VirtumundoBeGone file.

    For some reason it says I am clean.

    So why is Ewido showing this virus?
     

    Attached Files:

    • VBG.TXT
      File size:
      1.2 KB
      Views:
      1
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this file - combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also attach new logs for:
    GetRun
    ShowNew
    HJT
     
  5. webgyrl

    webgyrl Private E-2

    New Logfiles

    Hi,

    I have done as you suggested. I am posting my logfiles.

    ComboFix.txt (15.9 KB)
    newfiles.txt (46.9 KB)
    runkeys.txt (18.3 KB)
     

    Attached Files:

  6. webgyrl

    webgyrl Private E-2

    Hijack This Logfile (NEW)

    Hijack This log file posted.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First uninstall Viewpoint Media Player thru Add/Remove Programs in the control panel.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please download VundoFix.exe to your desktop.

    Now run HJT and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: awtqr - C:\WINDOWS\
    O20 - Winlogon Notify: winkzs32 - winkzs32.dll (file missing)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.


    Now double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  8. webgyrl

    webgyrl Private E-2

    Combofix.exe nuked some things on my system...

    OK before I go on I wanted to let you know that after I ran Combofix.exe and tried to shut down, my computer hung at "Windows is shutting down" and I had to manually shut off the power to turn of the system.

    Also, when I came back all of my program icons were gone or showing up as generic icons.

    Is this normal?

    See screenshots...
    http://img231.imageshack.us/img231/9600/icon1ky0.th.jpg

    http://img394.imageshack.us/img394/6486/icon2rj6.th.jpg


    Should I just continue with what you said.

    Also, what about making registry backups. Should I do that before I do any of this other stuff and if so, how do I do it?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Backing up the registry is only saving what may be the problem.
    The icon change could also be part of the problem.
    Continue on....
     
  10. webgyrl

    webgyrl Private E-2

    2 Questions... icons back

    Tim,

    I just wanted you to know that I shut down again and it shut down normally. When I re-booted the icons came back. Not sure what that was all about, but it's OK now.

    I am going ahead with the procedure you outlined above.

    Just 3 questions:

    1.) After my last 'clean', I went to MSConfig and turned off some programs from starting up on boot. Should I go to NORMAL boot mode and have everything start up before I run Pocket KillBox and VundoFix.exe and then doing the Hijack This run again?

    2.) Should I be in regular boot mode as opposed to one of the Safe Modes?

    3.) I am sure that in one of my other sweeps I saved a registry entry (can't remember which program prompted me for this tho). Should I search for old registry backups and delete them? If so, how do I find the registry backups that are to be deleted?

    Thank you so very much for your help!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The Combo fix was still fixing when you had to manually reboot....

    Yes, as the read and run directs...normal msconfig.

    Do the Pocket Kill box deletions in safe mode...(sorry, should have stated that.)
    The rest in normal mode.

    Don't worry about the registry backups....for now.

    Be sure to attach the new logs!!
     
  12. webgyrl

    webgyrl Private E-2

    Ok I will do the Pocket KillBox first in Safe mode, then reboot (or do what it says) and then come back with Normal start up in regular mode to do the VundoFix.

    I will return with new logs.

    Thanks so much!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove these from the kill box list ...then continue on...

    C:\WINDOWS\system32\pndx5016.dll
    C:\WINDOWS\system32\pndx5032.dll
    C:\WINDOWS\system32\rmoc3260.dll
     
  14. webgyrl

    webgyrl Private E-2

    Latest Logs

    Hello again,

    Just ran everything as you specified and here are the results.

    vundofix.txt log:

    VundoFix V6.3.5

    Checking Java version...

    Java version is 1.5.0.8

    Java version is 1.5.0.9

    Scan started at 10:53:19 PM 2/7/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\wgbbhtrl.dll

    Beginning removal...

    Performing Repairs to the registry.
    Done!



    GRK
    SN
    HJT
    are posted as attachments.

    The Hijack This log is from before I ran any of these other things you told me. I was a bit confused about if I should run it again after I ran the Killbox and VundoFix.

    Let me know if I should post a fresh HJT log as for the system as it stands now.

    Thanks!
     

    Attached Files:

  15. webgyrl

    webgyrl Private E-2

    Hjt

    You know what, I figure it doesn't hurt to show you the very latest HJT log. So it is attached. This is after running all the steps you told me to go through.

    Thanks!
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A new HJT should have been run after all was done.

    I overlooked three items and you had aready done it...so go back to pocket Kill box and restore from the backup these items:

    C:\WINDOWS\system32\pndx5016.dll
    C:\WINDOWS\system32\pndx5032.dll
    C:\WINDOWS\system32\rmoc3260.dll

    Also we are not seeing all the hidden files so:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Did you knowingly installed Avvenu Access for remote access?

    Now attach new ShowNew and HJT logs.
     
  17. webgyrl

    webgyrl Private E-2

    Yes I installed Avvenu knowingly. I use it all the time to access my system remotely.

    OK so you want me to just run Killbox and restore the following?:
    C:\WINDOWS\system32\pndx5016.dll
    C:\WINDOWS\system32\pndx5032.dll
    C:\WINDOWS\system32\rmoc3260.dll

    Do I do this in safe mode or regular boot mode?

    Also do I fix the Registry before I run Killbox? Or after?
    Thanks!
     
  18. webgyrl

    webgyrl Private E-2

    How do I restore these files using Killbox?

    Sorry I am not clear on how to do it and I don't want to mess it up. I went to Killbox and selected
    File > Open Killbox Backups
    Then it popped open a folder and I double clicked the first one "pndx5016.dll" and it said I had to find something to open it with.

    How do I do this and what do I use?

    Thanks
     
  19. webgyrl

    webgyrl Private E-2

    Restoring DLL

    I know I sound stupid... but do I just copy those DLLs back to the system32 folder?

    I just don't want to mess something up, but I am anxious to continue with your steps.

    Thanks!
     
  20. webgyrl

    webgyrl Private E-2

    Latest Logs

    Ok I took a chance and just copied those DLL files to the System32 Folder. I left a copy in the Killbox folder though.

    Then I went and updated the Registry as you suggested.

    Then I ran ShowNew and HJT.

    Logs are attached.

    Am I clean yet?
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall thru Add/Remove Programs in the control panel:
    Panda ActiveScan
    ewido anti-spyware 4.0
    Counterspy
    Viewpoint Media Player
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 8"
    J2SE Runtime Environment 5.0 Update 9"


    Then reboot and install Java Runtime 6

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds