Need Help Cleaning Vundo or Virtumundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by 10dulkar, Dec 9, 2008.

  1. 10dulkar

    10dulkar Private E-2

    Hello All,

    My computer is infected with the Vundo Trojan. I tried using the WinXP cleanup procedure listed here but it was completely removed (as far as I can tell one registery key cannot be deleted). I am attaching the log files as requested.

    (Running MGTools did not create the zip file so I a manually added them to a zip file).

    Hopefully this is all you need.

    Thank you for your help!
     
    Last edited by a moderator: Dec 23, 2008
  2. 10dulkar

    10dulkar Private E-2

    Here are the remaining attachments
     
    Last edited by a moderator: Dec 23, 2008
  3. 10dulkar

    10dulkar Private E-2

    ZoneAlarm AntiSpyware Scan did the trick of deleting the last known registry. All scans since have returned negative so I am assuming all is safe.

    Mods kindly close/delete the thread.

    Thank you for the informative posts!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are still badly infected!!!

    First you must only have one antivirus program installed as stated in the READ & RUN ME. You have at least 3 that I noticed. AVG, Norton, and Trend Micro. You MUST uninstall all but one of these immediately and then reboot your PC. Your PC must be running very slow with all of these installed.


    What is the below folder for?
    Code:
    "C:\Documents and Settings\"
    WANGJ15       Sep 13 2007              "wangj15"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_03
    Spybot - Search & Destroy 1.4

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • On your Desktop there should be a file named Submit[Date Time].zip, where [Date Time] is the date and time it was made while running ComboFix. Please attach this ZIP file.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited by a moderator: Dec 23, 2008
  5. 10dulkar

    10dulkar Private E-2

    Chaslang,

    Thanks a lot for your help! I really appreciate it..

    Here are the answers and attachments:

    >> What is the below folder for? (....wangj15)

    It is a network account that was added to my laptop when someone logged in on two in a corporate network but I can remove them now. Kindly advise how to remove (this and two others jbecker, boys)

    >> 3 Antiviruses

    Installed for various reasons - company policy (Trend), Client Requirement (Norton), Other recommendations (AVG)

    Which one should I leave there? I might have to reinstall others during audits but for not I'd like to leave one. Please recommend?

    >> Run C:\MGtools\analyse.exe

    I dont see the 3rd entry in the list "O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript"

    I ran first two and then Malaware manually

    >> Run Combofix/CFScript

    Ran Combofix (twice) as instructed but neither time it created the Submit[DateTime].zip on the desktop

    Attached are the remaining logs

    Thanks once again for all your help!
     
    Last edited by a moderator: Dec 23, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Via Control Panel, User Accounts.

    Does not matter!!! The fact remains that you must only have one installed as you are reducing the effectiveness of each of them by doing this. (quite possibly the reason you were so badly infected). It also can cause malware to go by unnoticed and it slows a PC down tremendously.

    If your company requires Trend then you have no other choice.

    You must NEVER install a 2nd or 3rd...etc while any other is still installed. Thus if in the future you need to install a different program, you must first insure that the other is completely uninstalled first and this almost never happens cleanly with Norton especially when more then one AV is installed.


    Quite possibly because you have 3 antivirus programs running which can also make it very difficult to remove malware when you do get infected since all of these programs are falling all over themselves getting in the way of every step you take to remove malware.

    At this point we cannot continue until you remove all but 1 antivirus and then get a new MGlogs.zip file and attach it.
     
  7. 10dulkar

    10dulkar Private E-2

    Cannot find any of these accounts listed in the User Accounts in CP. Can I just delete folders in Docs & Settings or is there another way?

    Removed all but Trend Micro.

    Tried the procedure again but same result. (Removed AVG, Norton; Reboot each time; Ran CCleaner; Performed procedure). Did not find the entry for O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)]...No SubmitFile.. appeared either.

    Attaching updated MGLogs and ComboFix.txt.

    After this is cleaned up I would like to remove a bunch of programs that appear in Add/Remove Programs and/or Program Files since I am not sure what they do!

    Thanks once again for your help!
     
    Last edited by a moderator: Dec 23, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If these users no longer require access to the PC then delete their folders.


    You have some remaing stuff from Symantec. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    We do not need it anymore as ComboFix delete the files anyway since they were presumed to be bad.

    This is something you have to work thru on your own or in the Software Forum. We only have time to deal with malware issues in this forum.


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Removed attachments at request of poster.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds