malware indeed

Discussion in 'Malware Help (A Specialist Will Reply)' started by chuboy, Mar 2, 2007.

  1. chuboy

    chuboy Private E-2

    hello everyone! I have read the instructions and did all of the steps needed before using hijackthis. Can you help me on this problem.
     
    Last edited: Mar 11, 2007
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you followed all the steps, you would have attached the requested logs. Please do so now.
     
  3. chuboy

    chuboy Private E-2

    anyway thanks! Its a Vundo something like that... I already used the vundo fix. now it all gone. thanks to MajorgeekS!:p
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I seriously doubt that it fix all of your problems with Vundo. The more recent Vundo infections are depositing files all over the place and are typically not totally fixed with VundoFix. I suggest you complee the READ & RUN ME and attach all the logs so we can verify everything has been removed. Even leaving one file from it behind can cause it to respawn and it usually comes back with an even worse infection than the first time.
     
  5. chuboy

    chuboy Private E-2

    okay, so here are the files i have now. Hope you guys can help me on this. Thanks in advance. :major
     

    Attached Files:

    Last edited: Mar 11, 2007
  6. chuboy

    chuboy Private E-2

    here's the other two....
     

    Attached Files:

    Last edited: Mar 11, 2007
  7. chuboy

    chuboy Private E-2

    by the way, as for additional info, here is the log of the vundo fix that i had done earlier....
     
    Last edited: Mar 11, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are in pretty good shape as far as Vundo is concerned but we have some other things to do.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.



    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew


    Make sure you tell me how things are working now!
     
    Last edited: Mar 10, 2007
  9. chuboy

    chuboy Private E-2

    Thanks for the reply sir chalsang! Anyway, I have uninstalled both previous Java updates and installed the newer version as to what you have stated in the instructions, made the registry file and merged it. Also ran the ATF cleaner, man that was a heck of a program, it freed i think 300+ MB on the main menu when i clicked the select all button. Nice, acted like a big brother of CCleaner. :) Now here I go again posting the new .txt files.

    One thing I noticed when I'm using my computer before using the vundo fix is that, it always prompted a message, with an option if I have to Work Offline and Try Again stuff. I think that was part of Vundo's attacking mechanism. Because I was not really connected to the internet, and also another thing was when I rebooted previously to safe mode, explorer.exe won't run, I used Ctrl+Alt+Del to start a new task and ran AVG manually.

    It made me nervous because I'm doing my thesis now, and worried that all the files are saved in drive c:, and thought of not recovering them and get a hand of all the installers of the development tools I need for my thesis to work which is also used in my internship.

    Now, with the help of majorgeeks, my computer runs smoothly. I think I got that virtumonde file on a crack installer for Lavasoft Ad-Aware which I downloaded in a serials and crack website. Stupid me, didn't think that the file was small enough for a patch (something like 28kb), and Alas! I got the infection and my computer slowed down seriously. I was too excited to run the patch and/or crack, that's why I forgot to scan and to even think that it was attached with a Malware. So, this time no more downloading of cracks and serials from unsafe websites unless they are proven to be working. hahaha! (I never learn!)

    Thanks chalsang, and to the team of majorgeeks for your existence. Please don't stop the good job that you are providing people all around the world. Also continue extending your patience when helping the less-educated individuals when giving them instructions.

    Salamat! (thanks in Filipino!)
     
  10. chuboy

    chuboy Private E-2

    uhhmm I got a problem, how come I cant attach files anymore??? The manage attachments button is not visible??
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes you just need to exit the page and then re-enter the page and possibly also do a refresh. Also sometimes it helps to empty your IE cache first.

    • In IE, click Tools, Internet Options, General tab and then Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
     
  12. chuboy

    chuboy Private E-2

    Okay, done that... Thanks, here are the 2 new files that you asked for. ;)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you or do you still use a program named Folder Lock? See: http://www.newsoftwares.net/folderlock/
    I see the below file which has been associated with Folder Lock.
    Code:
    "C:\"
    sccfg.sys     Mar  5 2007          20  "sccfg.sys"
    Delete the below file
    C:\Documents and Settings\chris\Local Settings\Temp\edhtjqii.dll


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. chuboy

    chuboy Private E-2

    okay, ill follow those steps. Btw, Im not using Folder Lock anymore, i didn't like it. Is there any file associated with it that I need to delete? If yes, what file(s) and how? :cool
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the file I listed should be deleted. That is C:\sccfg.sys
     
  16. chuboy

    chuboy Private E-2

    Okay, thanks chalsang! My PC is malware-free again :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds