Did WinXP Cleaning, not sure if removed Vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by soccerplato, Apr 30, 2008.

  1. soccerplato

    soccerplato Private E-2

    Dear MG's,

    Two weeks ago, 4/16, I became infected with Vundo/Virtumonde. I've been trying to shake it ever since, but my NOD32 scans were still showing problems. In particular, the following two items would show up in quarantine, but could not be deleted.

    H:\I386\apps\APP15968\src\CompaqPresario_Spring06.exe
    H:\I386\apps\APP15968\src\HPPavillion_Spring06.exe

    NOD32 was describing it as an Adware.Virtumonde variant. Anyway, after several other scans with AVG 7.5, AVG Anti-Spyware, Spybot, I was still not coming completely clean.

    I found your READ ME FIRST Malware guide last night and am very grateful. I did everything you suggested, in order listed. The only thing that went wrong was, this morning, when I got to ComboFix step, when I was supposed to click Start/Run/"%userprofile%\desktop\cf.exe" /killall, I inadvertently clicked on the cf.exe desktop icon and started ComboFix autoscan. It stalled after 1/2 hour or so (Not Responding) and I had to reboot computer by holding down the power button.

    I then restored my registry (with ERUNT) to what it was this morning, before running ComboFix.

    Assuming that restoring the old registry, it would be reinfected, I repeated the Windows XP Cleaning Procedure again, all the way through. It went well, except for a couple of error messages when I ran MGTools.

    My question is, I'm not sure if I'm clean or not, as your guide says not to run the READ ME again. I'm not sure Vundo is gone, or that my registry is ok, or that it's ok to Toggle SysRestore yet. What should I do at this point?

    I'm attaching the logs from the latest cleaning run. Do you need the logs from the first cleaning run too?
    This is my first post. Thank you for your patience with me.
    Thanks so much for your malware guide. You're lifesavers!
     

    Attached Files:

  2. soccerplato

    soccerplato Private E-2

    Here's the MGlogs.zip file
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually you look pretty good...just two items to deal with:

    If you haven't already, please disable the guest account.

    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Tell if you are having any other problems?
     
  4. soccerplato

    soccerplato Private E-2

    Thanks a lot, Tim.

    During reboot, the avenger log came up, and on top of it, the following error box:
    _______________________________________________________________
    ERROR: WINDOWS - NO DISK (red circle with x in it)
    Exception Processing Message c0000013Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c

    Cancel Try Again Continue
    _________________________________________________________________

    At the same time, the computer repeatedly made that dinging sound it makes when you insert or remove a usb device.

    I clicked Continue about 5 times and the error box went away.

    Is this a problem? It made me nervous :confused

    This was the same kind of error box I got when I ran MGTools.

    Avenger log says everything is ok.

    Also, how can I confirm Virtumonde/Vundo is gone for good? Should I toggle SysRestore yet? Do I need to enable it if I already have ERUNT?

    Should I keep SAS Free and ditch AVG Anti-Spyware (free)? Sorry for all the questions. Thanks again for your help.
     
    Last edited: Apr 30, 2008
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where did you download these to? Are you trying to run them from a disc or thumb drive?
     
  6. soccerplato

    soccerplato Private E-2

    No, not at all.

    I downloaded MGTools.exe to the C drive, where windows folder is. It's in
    C:\MGtools.exe

    I downloaded avenger.zip to desktop and extracted avenger.exe to desktop. I ran avenger.exe from the desktop. It's in C:\Documents and Settings\Compaq_Administrator\Desktop

    There are no external drives in my usb slots.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I am not sure why they would be trying to access those drives....as to the two files in quarantine:
    H:\I386\apps\APP15968\src\CompaqPresario_Spring06.exe
    H:\I386\apps\APP15968\src\HPPavillion_Spring06.exe

    They are stuff that came with the preinstall of the computer and are not needed.

    Are you having any other malware issues?
     
  8. soccerplato

    soccerplato Private E-2

    Hi Tim,

    After your last post, I did a complete scan with SuperAntiSpyware again. Again, it showed Adware.Vundo Variant. Log is attached. It quarantined the items. I went into Quarantine and deleted the entries. Why does it keep reappearing? I thought I'd be clean by now.

    Log is attached.

    Also, the Windows-No Disk error came up twice during the SAS scan. It is not on a thumb or usb drive. What does this error mean?
    Thanks again for all your help.

    I rebooted and am scanning again with SAS. Same infection is appearing.
     

    Attached Files:

    Last edited: Apr 30, 2008
  9. soccerplato

    soccerplato Private E-2

    I'm sorry, it's only my 2nd day on MajorGeeks. I don't mean to bump or double post, but I don't want to keep a thread open if there's no hope for my problem either.

    It looks like I'm still infected, maybe even more so.
    My Virtumonde/Vundo infection keeps coming up on subsequent SAS scans this a.m. Can't delete them on reboot. Keep showing up.

    Got 2 new NOD32 threats detected today: Win32/PrcView viruses detected in Docs&Settings folder and System Volume restore file. Nod32 can't remove.

    Is there any way to clean my system at this point, or should I seriously consider totally reformatting and restoring my computer to factory condition (ugh) and thus closing this thread ?
    Sorry to bother you. Thanks again for your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  11. soccerplato

    soccerplato Private E-2

    Please forgive delay. Attached MGlogs.zip file.

    When I scanned with SAS last night and today, the same XXYYRHFC.dll file in win/sys32 and the same 5 CLSID's keep returning, even though after previous scans, SAS was supposed to remove them upon reboot. I've also tried removing them in quarantine, to no avail. Also got the same "No disk - error" twice during SAS scan today.

    I can't remove the two spring06.exe files in H:\I386, since it's a recovery partition and locked. NOD32 keeps saying they're variant of Win32/Adinstaller application. Don't know if these are infected or false positives. They never came up before the Virtumonde infection.

    Thanks again.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do not worry about the spring files....tell nod to ignore them.

    What is this:
    C:\Documents and Settings\Compaq_Administrator\Application Data\AIGNES

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\system32\mpahrqss.ini
    
    DirLook::
    C:\Drivers
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  13. soccerplato

    soccerplato Private E-2

    OK, here's the combofix.txt log.

    When Combofix finished and notepad opened with it, on top of it was an error box:
    ______________________________
    Windows-Fatal Application Exit

    Kerio Personal Firewall Driver: AppendFragmentToLongPath: GetLongFilename error: C000000F, File: CF45.exe
    __________________________________
    I clicked on "OK" and it disappeared.

    Also, AIGNES is a folder apparently left over from when I installed/uninstalled AM Deadlink. Aignes is the software company.
     

    Attached Files:

    Last edited: May 1, 2008
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me the exact path of these:
    because I am not seeing them.

    Are you still having problems?
     
  15. soccerplato

    soccerplato Private E-2

    The registry entries and dll I mentioned are all listed in the attached SAS logfiles. They keep reappearing. Only 1 item from 4/30/08 (attached for comparison) is gone.

    I tried fixing/removing the C:\windows\system32\XXYYRHFC.dll file with NOD32's UNDLL tool, but I can't even find the file in the system32 folder.

    I just ran a second SAS scan and they still showed up, even after SAS said it will remove them upon reboot. They keep reappearing scan after scan. Same thing with a similar CLSID in MBAM scans (log posted earlier in thread).

    That is my main problem;I can't get clean scans. Vundo/Virtumonde stuff keeps coming up. I'm just worried that if I leave it there, it could get worse, especially with every reboot.

    I really appreciate your help with this.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to disable your anti-virus, anti-spyware and your firewall while we do this:

    we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  17. soccerplato

    soccerplato Private E-2

    Ok, here's combofix log.

    I'll run another set of scans from the READ ME FIRST-WinXP cleaning procedure tonight and tomorrow and see what happens. Is that ok? Any other suggestions for verifying my machine is clean?

    Thanks a mil!
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.....please do and let me know if something comes up ...attach the new logs and while you are at it.....this appears to be empty so I wonder if it is something you need:
    C:\Documents and Settings\Guest.FAMILY\WINDOWS
    If not, delete it or rename it if it is a folder you want to store files or data.
     
  19. soccerplato

    soccerplato Private E-2

    I ran the combofix script from yesterday. Logs attached here and in next message.

    I then ran the following scans this a.m.
    NOD32 - OK
    SAS - same 6 threats as yesterday's logs
    AVG7 - OK
    AVG-AntiSpy - OK
    Spybot - OK
    MbAM - Vundo (same registry item as listed in SAS log)
    ComboFix - see log
    MGTools - see log

    I don't get it. Are these things reinstalling themselves on reboot? Why would they keep reappearing? Nasty little things! I could just kick myself for not being more careful. Trusted my cousin in Europe who urged me to try BitTorrent and try a new program. I had no idea what I was getting into. Honestly, never heard of torrents and P2P sharing until after I got infected. Let your guard down, get sucker-punched!

    Anyway, I really appreciate whatever you can do to help. Is it time to (gasp) dust off the HP Recovery disks? Say it ain't so!
     

    Attached Files:

  20. soccerplato

    soccerplato Private E-2

    C:\MGlogs.zip attached.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...SAS reports it as adware, so I think it is some relatively benign item associated with a program or toolbar...however, Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  22. soccerplato

    soccerplato Private E-2

    BitDefender log attached.

    It found and deleted some other Vundo stuff.

    Good old SAS still shows the same 6 Vundo items, though.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download VundoFix by Atribune to your desktop.

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt log.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.
     
  24. soccerplato

    soccerplato Private E-2

    Vundofix found nothing. Log attached.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There was nothing for VundoFix to find. You did not have any real infection. All BitDefender found was the Quarantine files from running ComboFix and these are not problems.

    Why does this PC still have multiple antivirus programs installed?
     
  26. soccerplato

    soccerplato Private E-2

    Before the infection, all I ever had was NOD32, Spybot S&D, and Kerio PF. Never had a problem.

    After this infection 2 weeks ago, I downloaded AVG and AVG-AS to try and get rid of this Vundo/Virtumonde thing that NOD32 caught. I added SAS & MbAM from the READ ME FIRST cleaning procedures.

    I'd love to get rid of everything, once I know I've got a clean machine. I don't understand why Vundo keeps showing up in my SAS & Mbam scans. I even tried a free Spyware Doctor scan and it found stuff the others didn't, including some high risk Trojan.FakeAlert in a couple of screensavers I've had for years. Are these all false positives? How do I know my machine is clean when these scans are showing infections?

    I really do appreciate everyone's help here. I don't want to prolong the agony much longer for everyone. You've got plenty of others to help and I don't want to take any more of your time up. Thanks so much for taking the time to help me. Could you tell me how to uninstall combofix and if there's anything else I can do to wind this down?

    Again, many thanks.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not a problem...if you have questions or concerns or issues that are still occurring (you noticed that doing different scans will catch different things - which is how we can sometimes catch things that our normal protection does not) please feel free to ask. I believe that you are clean and what you are finding is just normal - adware from either a toolbar or a program.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  28. soccerplato

    soccerplato Private E-2

    Thanks, Tim.

    One quick question. My combofix.exe file is still renamed cf.exe. Do I need to rename it to the original combofix.exe name for the uninstall \u command to work?

    Also, should I uninstall all the other antivirus/antispyware stuff and only keep my original NOD32, SpybotS&D, and KerioPF?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    type cf /u in the runbox and click OK. ...note the space.

    Yes you can remove all but those programs that you want to keep ....I keep Malwarebytes as a backup to run on occasions when I think something is amiss.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That will not work! The proper instructions are.

    If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\cf" /u
      • Notes: The space between the cf" and the /u, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    • Delete the C:\cf folder from combofix.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That will teach me not to update my thumb drive ....Thanks, Chas. :eek:
     
  32. soccerplato

    soccerplato Private E-2

    Well, that will teach me not to react so fast. I followed Tim's command line and just manually deleted the rest. I hope that was ok.

    One last question. Can I somehow manually remove the registry key that shows up as infected with Vundo in both SAS and MbAM scans:

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{c14e6230-757d-4246-81ce-b34e2940c722} (Trojan.Vundo) -> Delete on reboot.

    Neither program seems to remove it upon reboot. I'm leery of messing with the registry, but I'd love to get rid of it, if it's ok.

    What do you think?

    Again, many thanks.
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can manually delete it ...we have done the reg patch to remove it as well as the programs to remove it ...but as you say, it keeps coming back ...classified as adaware and I think it has to do with a toolbar or program ..but give it a shot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds