Stubborn Trojan.Vundo (supposedly)

Discussion in 'Malware Help (A Specialist Will Reply)' started by milindsmart, Apr 24, 2009.

  1. milindsmart

    milindsmart Private E-2

    Hello, I hope you can help me solve this rather sticky trojan problem:

    This computer was infected about a month ago (not sure... I wasn't here when it happened). It had Kaspersky Internet Security but stopped working after a while... the first indications that there was something wrong... Slowly followed by task manager and regedit disabling. Reenabling them again was a no-go as the virus managed to disable it again in a few seconds. I have some experience fiddling with systems, so I managed to delete all autorun.inf files and other suspicious bat files, but was unable to read the contents of any of them. I also found a file named
    which i deleted. I also terminated a process that had the same name as my computer name. The Command line tool Tasklist shows a reasonably clean set of files. No odd services either. Online scans detected a virus or two repeatedly but it never solved the root problem. So at this time all the shaky bits were removed and only the stubborn parts remained. At this stage I started following the steps in this beautiful site. Problems faced are as under:

    1) CCleaner installs. It runs but abruptly quits in less than 5 seconds. Guess the virus is at work. I was unable to run it. Same goes for task manager in the brief time that it is enabled.

    2) ComboFix says the usual "combo fix has encountered a problem... "

    Along with the next instructions, I would also like to know how to deal with infections with no suspicious processes or services.

    Milindsmart
     

    Attached Files:

  2. milindsmart

    milindsmart Private E-2

    Also

    I managed to run Combofix by redownloading it... Also I'm unable to disable Kaspersky and so I ran it anyway (KIS doesn't work). Hereafter MGTools was also run. Attached are the logs.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thankyou for your patience during this time.

    Kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    With regards to Kaspersky, It may need to be uninstalled and reinstalled to get it fixed.

    And did you once used to run Symantec/Norton's and have since uninstalled it? If so you still have leftover's from this and it will require running the Norton Removal Tool to completely rid us of it.

    I need to find out if anything else from Symantec is still installed before we run the tool so could you please let me know?



    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): (But you're not running any correct?)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:



    After clicking Fix exit HJT.


    2. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    Driver::
    gmtznr
    
    File::
    C:\Documents and Settings\Ravindranath\Local Settings\temp\0007F47F_Rar
    C:\Documents and Settings\Ravindranath\My Documents\~WRL0904.tmp
    D:\a2h2.com
    E:\a2h2.com
    F:\a2h2.com
    G:\a2h2.com
    M:\invwft2h.com
    
    Fcopy::
    c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe|c:\windows\explorer.exe
    
    DirLook::
    c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
    
    Folder::
    c:\windows\system32\waste
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51e98442-41a1-11dd-8d28-0019d1ae814f}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"=-
    "DisableRegistryTools"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    3. Run Ccleaner!

    4. Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds