Feeling a little suspicious

Discussion in 'Malware Help (A Specialist Will Reply)' started by Strider29, Oct 7, 2005.

  1. Strider29

    Strider29 Private E-2

    Everything has been going well since you guys helped me out about a week ago. But today, I saw the IE window (the blue highlight at the top for active windows) flicker a few times and later, it froze up. I tried to shut it down from task manager but the screen still wouldn't return to normal and the only thing running was task manager. I had to log off. I did a HJT scan and the log is attached below.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You now have a Virtumundo infection! Note the same rules always apply about running the READ ME FIRST and not posting HJT logs unless they are requested!

    Try following the steps in this Generic guide for fixing Virtumundo:

    Virtumonde aka Trojan Vundo Fix w/ Tool

    If you have any problems following it, let me know.
     
  3. Strider29

    Strider29 Private E-2

    Couple problems with that. Safe Mode didn't work right for me. It loads but then it's just a black screen. I don't have access to any folders, my desktop, or the Start menu.

    And the instructions for the Vundo Fix said to enter the filename for the infected files (02, 20, etc) from the HTJ log, but I don't know which ones are bad.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try reading the Vundo Fix thread again and see if you can identify your O2 and O20 lines now. The thread was modified a little while ago (we are trying to refine it so people like you can follow it. So this is useful feedback.) If you cannot ID the two important lines now, just tell me what is confusing you.

    Also when you get into safe mode with the empty Desktop, try the below.

    Press CTRL-SHIFT-ESC at the same time to bring up Task Manager. If that works, do the below.
    Click File, New Task (Run...) and enter explorer.exe in the box and click okay. See if either your Desktop appears or a Windows Explorer window opens up. If either of these occur, you should now be able to navigate your way to the KillVundo.bat file to run it.

    Let me know what happens.
     
  5. Strider29

    Strider29 Private E-2

    I have three O2 (BHO) listed in the log and two O20 (Winlogin Notify). But I know one of the BHOs is for Acrobat reader. The other 2 look funny - not sure if I'm allowed to post the names in the post though. And I don't know what Winlogin does.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The two lines of concern are:

    O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\awvvu.dll
    O20 - Winlogon Notify: awvvu - C:\WINDOWS\system32\awvvu.dll

    If you cannot follow the procedure now please let me know and I will post a full procedure for you.
     
  7. Strider29

    Strider29 Private E-2

    OK. I think I can follow the rest. Thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! When finished post the HJT log as an attachment and we will make sure you are clean.
     
  9. Strider29

    Strider29 Private E-2

    Here it is.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. Strider29

    Strider29 Private E-2

    I downloaded a program about a week ago called "Paltalk Messenger". It starts up when Windows starts. That could be it so I checked inside the folder but the exe for Paltalk is "paltalk.exe", not palstart. So I don't know. But I was a little uneasy when I first downloaded it because it put a couple icons on my desktop: "eFax" and "Lower Your Phone Bill".

    I haven't even used the messenger so I'd have no problem getting rid of it. What should I do?

    * Sorry for breaking the rules. I had read that page before when I first had the Vundo problem. I had already downloaded the programs it suggested but I figured I'd need help diagnosing what was wrong this time.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would uninstall the program and see if that line goes away. Some people seem to think it could be malware.

    One of the problems is that you never ran the online scanners. Reading & even downlaoding the tools on the page is not the same thing as following the instructions given on it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds