Explorer.exe being killed by vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by Random_Anomaly, Jun 23, 2007.

  1. Random_Anomaly

    Random_Anomaly Private E-2

    I have been banging my head against this trojan for 14hrs now, and im at my ropes end, i have downloaded every trojan remover, adaware remover, and anti spam tool i can think of and still no dice, i am able to kill the virus for about 15-20 minutes with trojan remover, and have use of my desktop for that long before it takes over again. trend-micro does detect the action, but is unable to stop it. please help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Give the below procedure a run:

    Virtumonde aka Trojan Vundo Removal

    Did that help? You may want to consider running the READ & RUN ME sticky procedure. Vundo often comes with other baggage.
     
  3. Random_Anomaly

    Random_Anomaly Private E-2

    Have run it in normal mode and safe mode, about 2-3 times in each, it finds the virus, and says it cleans it, but it comes back about 10-20minutes after. Have run the following programs in a attempt to clean up: Spybot, Adaware, Trendmicro, Trojan remover, Trojan hunter, Vundofix, and hyjackthis.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach your Vundo log here! See: HOW TO: Attach Items To Your Post

    Then as recommended in my last message, you need to do the below. Make sure all steps are followed in the order written and that when you get to step 7, be sure to install and rename HijackThis as requested. This is critical for Vundo infections.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. Random_Anomaly

    Random_Anomaly Private E-2

    heres the logs from the programs i could do. wasnt able to do online scan, it would not complete, and counter spy would not DL either, having some ISP issues atm too =(. Well, unable to post the logs atm, will try to get to the point where i can.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post them when you can. There is not much we can do about your ISP issues. ;)
     
  7. Random_Anomaly

    Random_Anomaly Private E-2

    ok, here are the hyjack and run key files, the scans are not completing still, AT&T is supposed to be here tomorrow to fix the dsl. If you can work with these 2 great, if not, ill try to get the others to you tomorrow.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I cannot work from just those two. It will be insufficient to remove all of the Vundo infection and it will just come back and could come back even worse. One of the worst things to do with Vundo is a partial removal.
     
  9. Random_Anomaly

    Random_Anomaly Private E-2

    heres the rest of the scans reports. Bitedefender refuses to work at all still. by the way, thanks again for helping :)
     

    Attached Files:

  10. Random_Anomaly

    Random_Anomaly Private E-2

    heres todays version of the other 2
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    pmkhh.dll
    pmnkljk.dll
    pmnoooo.dll
    vtuvwvu.dll
    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    pmkhh.dll
    pmnkljk.dll
    pmnoooo.dll
    vtuvwvu.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    pmkhh.dll
    pmnkljk.dll
    pmnoooo.dll
    vtuvwvu.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now back at the main Process Explorer window look for the below processes and if found right click on them and select Kill Process.
    C:\Program Files\Common Files\{5CCBDF4D-06C1-1033-0106-050602200002}\Update.exe
    C:\Program Files\Ipwindows\ipwins.exe

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {066A2CDC-319E-4460-BA45-C24562CD51AA} - C:\WINDOWS\system32\pmnkljk.dll
    O2 - BHO: (no name) - {8C375ED1-4756-435B-8E8E-CF642EC1D166} - C:\WINDOWS\system32\pmkhh.dll
    O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O20 - Winlogon Notify: pmkhh - C:\WINDOWS\system32\pmkhh.dll
    O20 - Winlogon Notify: pmnkljk - C:\WINDOWS\SYSTEM32\pmnkljk.dll
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. Random_Anomaly

    Random_Anomaly Private E-2

    Things are looking much better so far. heres the log files below. Many many thanks for your help O wise one. Much honor to you and yours.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That looks better but your forgot to attach the new log from ShowNew.

    You can also uninstall the CounterSpy trial now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds