Malware - Vundo alerts from Avira

Discussion in 'Malware Help (A Specialist Will Reply)' started by ftjoe, Nov 28, 2009.

  1. ftjoe

    ftjoe Private E-2

    I've been running scans for two days. Problems started a while back on daughter's machine at school. I had to connect remotely and things seemed better. But I always get an alert in regards to a file in system32 being a vundo.gen infection. File names change. I've executed all the scans recommended for a Vista 32 bit machine. One issue is RootRepealer fails so no log for that. When I am done selecting the drives, I get a black screen with a one inch blue line across the bottom. This was noticed for the first time when the issues first started. Machine is basically dead and has to be powered off. We also notice redirects in the web browsers, not necessarily to malicious sites, could be to anywhere.

    She will be going back to school tomorrow but I should be able to connect remotely even in safe mode if necessary.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\System Defender
    C:\System Defender.lnk
    C:\WINDOWS\temp\TMP0000000CA19D388177B38680

    Reboot and run CCleaner.

    Tell me what issues you still have.
     
  3. ftjoe

    ftjoe Private E-2

    Hi - I performed the steps and rebooted. It appears we still have redirects on the browser. Seems to go off to a few select sites when we click on hotspots such as search results, etc. Not going where we expect it to. I ran a quick virus scan and nothing showed up but sometimes it takes a little while to show up in system32. Also, should I try running rootrepeal again? Thanx.
     
  4. ftjoe

    ftjoe Private E-2

    Hi - wanted to update this to add the machine was hijacked by a fake security alert so I had to run malwarebytes again to clean it up. Redirects are sill taking place and I've noticed the search entry are for google in internet explorer actually goes to something called search-gala.com. Also, vundo alert was received again.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run both ComboFix and then the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  6. ftjoe

    ftjoe Private E-2

    Logs are attached. After combofix was done running anything opened was receiving a message that it performed an illegal operation on a registry key marked for deletion. We rebooted and things seemed okay. vundo alert popped up right away, thanx for the help...
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what Avira is complaining about.....the exact path.

    Do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.sys
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.dll
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\energy.dll
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\CLSV.drv
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\cb.dll
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\std.dll
    c:\users\Caitie\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
    C:\Users\Caitie\AppData\Local\Temp\ehmsas.txt
    
    Folder::
    C:\ProgramData\4BA13E7
    C:\ProgramData\WSUGQKD_APDM
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now:

    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents in your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds