TR/Vundo and others trojans - no task list mgr

Discussion in 'Malware Help (A Specialist Will Reply)' started by joycerv, Apr 28, 2008.

  1. joycerv

    joycerv Private E-2

    Computer infected with unknown trojans etc. Kaspersky claimed to have removed a trojan and virus but to no avail. Error states troj/pushdo_gen and TR/Vundo. Boot computer and after 2 minutes, all icons disappear and task list manager "has been disabled by administrator". Can boot in safe mode using the command prompt only. Tried following instructions in readme first and copied SuperAntiSpyware to computer and tried to install from cmd prompt. Could not do so - "Administrator has disabled rights" HELP any suggestions for working from the cmd prompt?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see if you can get MGtools onto the PC and run it. It should have no problem running from the command prompt in safe boot mode. If it runs, attach the MGlogs.zip file as requested in the READ & RUN ME.
     
  3. joycerv

    joycerv Private E-2

    Here is the zip file from MGTools. A little more information, prior to asking for help, I had ran spybot, stinger, anti trojan elite and fix vundo. I then came here and read your advice about not throwing everything at the problem and I have tried to uninstall as many as I could from the dos prompt. Next time I have a problem, I'll start here first.

    Thanks in advance for the help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=explorer.exe
    O2 - BHO: (no name) - {24D38583-4768-4321-93D2-BA0B54B4290B} - C:\WINDOWS\system32\jkkKefET.dll
    O2 - BHO: DVA Gate - {7A6FD945-14B0-41F8-84FB-74DEF17528BB} - C:\WINDOWS\qnmargolxgn.dll
    O2 - BHO: (no name) - {D2376FB3-3D0D-414D-83AA-3AD6AD6B111F} - C:\WINDOWS\system32\urqQJAtu.dll
    O3 - Toolbar: dpevflbg - {B21EAD36-EC0C-4B82-B102-1AB20B481977} - C:\WINDOWS\dpevflbg.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVP] "C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_27.04.2008_18-25.exe"
    O20 - Winlogon Notify: urqQJAtu - C:\WINDOWS\SYSTEM32\urqQJAtu.dll
    O21 - SSODL: vadokmxt - {FAF747A3-4741-4596-A273-2C205EBB3559} - C:\WINDOWS\vadokmxt.dll
    O21 - SSODL: wdpoefan - {5F86E711-5267-439F-A5BE-50F18C7C321E} - C:\WINDOWS\wdpoefan.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    If you can boot in normal mode now then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java(TM) 6 Update 2
    Viewpoint Media Player

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. joycerv

    joycerv Private E-2

    Followed all the instructions to the letter and I can now get into the computer. The Task List manager still seems to be hit or miss as to whether or not it has been disabled by the administrator. I cannot access the internet on the computer which seems strange since it is the host for my wireless network and the network is still up. Anyway, here are the files you asked for.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below still running which I requested that it be removed in the previous fix.

    C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_27.04.2008_18-25.exe

    Let's remove the service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to setup_7.0.0.180_27.04.2008_18-25
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    It looks like some of the items I asked you to fix did not get fix and also something new spppears in the HJT log:
    O4 - HKCU\..\Run: [VirusIsolator.exe] C:\Program Files\VirusIsolator\VirusIsolator.exe

    It appears that you did not Remove Windows Messenger as requested. Please run the tool again and remove Windows Messenger. Do not use disable.

    Please make sure that you are only running my instructions and nothing else. Do not install or run anything unless I ask you to.

    Your AntiVir antivirus program appears to be broken or was not uninstalled completely. Did you uninstall it since starting this thread?


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A39D834F-0A45-4E58-A550-9D4C7990E776} - C:\WINDOWS\system32\jkkKefET.dll (file missing)
    O2 - BHO: (no name) - {D2376FB3-3D0D-414D-83AA-3AD6AD6B111F} - C:\WINDOWS\system32\urqQJAtu.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKCU\..\Run: [VirusIsolator.exe] C:\Program Files\VirusIsolator\VirusIsolator.exe
    O8 - Extra context menu item: &Search - ?p=ZC

    After clicking Fix, exit HJT.

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. joycerv

    joycerv Private E-2

    Here are the logs from my last attempt. Avenger could not delete the VirusIsolator.exe I used regedit and looked in the registry and did not see the key and I didn't change anything.

    I did try to delete the AntiVir antivirus program through the control panel before the last time because it was a totally ineffective tool. When the machine was being infected, it told me about the infection but didn't do anything to stop it.

    I still cannot get into the internet, but the machine boots o.k.
     

    Attached Files:

  8. joycerv

    joycerv Private E-2

    One additional question - as I stated AntiVir was useless - what is the best antivirus tool that I can use on a computer with two kids on it?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AntiVir is a good program. You will even see it listed with several other free tools in our How to protect yourself from malware sticky thread. You need to remember that it is an antivirus program not a antispyware program which the infections you had really better classified under. However, even as such no programs out there properly detect and remove all of these infections which is why forums like this exist. The first and most important line of defense is a properly educated user which the below final instructions steps should help to do.

    However first, one more left over from AntiVir needs to be removed.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

    After clicking Fix, exit HJT.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds