Trojan.vun and Vundo Malware - Logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by EscapeCat, Mar 25, 2009.

  1. EscapeCat

    EscapeCat Private First Class

    Hi! I am a first time poster, and please let me know if you need anything else other than what I am posting here. :)

    First off, please know that I know virtually nothing about this stuff. I can do basic PC maintenance (updates, scans, and cache clearing), but I know nothing about viruses and such nasty, evil malware as this.

    I was visiting a website about 2 days ago called www.glitter-graphics.com to retrieve an image to use in another forum I frequent. There are banner ads on that site (and I thought maybe that's where it came from?), but I wasn't downloading anything. All I needed was the forum code, so I clicked on the image I wanted and then my computer started getting all sorts of popups and McAfee acknowledged there was a problem. (Wish it would have stopped it.) I ran a McAfee scan and it came up with nothing (just had mentioned it had blocked some trojan.vun or something like that, but they don't appear in McAfee's logs.) I also ran SpySweeper and it kept finding the vundo malware and kept removing it, but it never really left.

    I have followed your steps in the READ & RUN section of your forums and done everything except the Combofix and the toggle restore (as my system isn't clean, I don't think.) I was too afraid to try Combofix, as there are many warnings about using it, especially if you're an amateur. This is my only PC and I can't afford a new one. Also, I would like to note that I could not get my laptop to run in SAFE MODE. I tried, and it constantly froze, never progressing past loading the start button and a blank screen. Nothing else would load, and the little circle showing it's loading, was no longer spinning. I couldn't do anything, so my scans were performed in normal mode.

    I have Windows Vista Home Premium for my OS, and a Gateway PC. Attached are my logs, and I REALLY hope you can help me out. My computer is so slow. :(

    I know you guys are busy, and you are FREE helpers. So, I really appreciate your help and thank you in advance. (I loved the step by step READ & RUN instructions. Very helpful for someone who is not at all familiar with these things. :D)

    EDIT: Also, since running MGTools.exe I have to (notepad?) files on my desktop. :confused

    1st one:

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799

    2nd one:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183

    And when booting, I have error messages popping up about "big fix. :confused

    Here you go:
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. In the mean time can I ask you whether you accepted the agreement for Hijackthis? This log is missing, so could you run MGTools.exe again this time accepting the license agreement and attach the new Mglogs.zip that the running of it will create.

    Thanks

    Kestrel
     
    Last edited: Mar 29, 2009
  3. EscapeCat

    EscapeCat Private First Class

    Thank you so much for the reply, Kestrel!

    That's odd that the log wasn't correct, as I DID accept the HJT user agreement the first time 'round. Hmm. Anyway, I went ahead and did it all again and this time the User Agreement didn't even pop up for me. Otherwise, it did everything it said it would in the MGTools tutorial. (Except my PC also showed a "Restoring System Information" window (I think that's what it said it was) with a progress bar.) But it did look just like the the attached image in the tutorial with the pressing any key to close the window. So it all looked correct. I will now attach the new logs, and I hope they're correct.

    For the record, since running the READ ME & RUN FIRST, I've not noticed any more issues with my PC, nor are my anti-virus, or anti spyware programs (including the SuperAntiSpyware program I got from here) finding anything on my PC. I'm hoping that I am clean now. :)

    I hope these logs are the ones you need. :) Please let me know if I again did them wrong. I have no idea why the user agreement didn't pop up again this time.

    Again thank you so much for your reply. :)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's got it this time :) I'll check your logs as soon as possible and get back to you.
     
  5. EscapeCat

    EscapeCat Private First Class

    Oh, good. When I saw that the file was quite a bit bigger, I was hoping it worked. Thanks again. :)
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What file names are you looking at? I am guessing that you are referring to Desktop.ini which are not problems and are appearing because hidden files and folders are set to show.

    What is the exact error message? You need to give exact word for word error messages. And do you or have you ever used BigFix? If not then uninstall it because it is just bloatware that your PC manufacturer installed.


    1) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2) Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    3) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\Temp
    • C:\Users\Selena\AppData\Local\Temp

    4) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    5) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    Kes
     
  7. EscapeCat

    EscapeCat Private First Class

    Thank you, Kestrel! I am very busy with work and school today/tonight, so I will be sure to do this tomorrow night. I really appreciate your time.

    It wasn't exactly a file...just a notepad on my Desktop with the previously posted information in it. Two of them. I assume you're right as to what it is. Thanks! :)

    I apologize for not having the error for BigFix. I panicked thinking it had something to do with my malware stuff, and closed it immediately, as BigFix hadn't been running until I did the msconfig change when doing the READ ME & RUN. However, it's not happened again. I have no idea what that program even does, so I will simply uninstall it like you said.

    I'll post back here as soon as I have the new logs you requested. :)
     
  8. EscapeCat

    EscapeCat Private First Class

    Seems you are right. This is what I am seeing (circled in red):

    Unknown Notpad Items.jpg

    Nevermind my error regarding BigFix. Seems it was a one time thing, and I haven't had the problem since. I will likely uninstall it. I have no idea what it even does. :p Sorry for not posting the original error message. As I said in my post (that's in moderation at the moment), I closed the error quickly as I panicked it had something to do with my malware problem.

    I followed all of your directions, except that I ran MGtools as "administrator" since I use Vista and that was what you had me do when I ran it the first time. I hope that was correct. If not, I'll run it again for you.

    EDIT: I went to attach the logs for MGtools, and the only one that was there was the log from the first time I ran it several days ago. :confused I hope I didn't mess up what you need to see. So, then I tried to run it again, and I got all these access denied errors and used the Task Manager to close the MGtools program, shut off my UAC, and rebooted it. I then ran the GetLogs.bat file as adminstrator (I use Vista.) I hope that is acceptable.

    Attached are both logs.

    Currently my PC seems to be running fine. Since my problem I have been only using Firefox, and not IE7. I will now work with IE7 and see if any problems arise.

    If my logs are fine, will you help walk me through hiding those hidden files and changing back the msconfig if necessary? (I'm sorry - but I think that's what the READ ME & RUN first thread had me change/do. I apologize for my ignorance.)

    As a reminder to you, I also had never done this:

    "Step 6: Toggle System Restore"

    Thank you again. :)

    avenger log:

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows Vista

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "C:\ProgramData\kayeyuja" deleted successfully.
    Folder "C:\ProgramData\fupuvuyu" deleted successfully.
    Folder "C:\ProgramData\gewofawu" deleted successfully.
    Folder "C:\ProgramData\jepewosi" deleted successfully.
    Folder "C:\ProgramData\lakenade" deleted successfully.
    Folder "C:\ProgramData\tobuvuzi" deleted successfully.
    Folder "C:\ProgramData\ninobuku" deleted successfully.
    Folder "C:\Program Files\Trend Micro\AntiVirus 2007" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi your post had to come out of moderation so bear with me whilst I look the logs over :)
     
  10. EscapeCat

    EscapeCat Private First Class

    No problem. And I apologize about attaching the avenger log incorrectly. Since it came up in notepad, I didn't realize it saved it to my system, and didn't think to save it as a .txt file myself. So I copy/pasted it there... Sorry about that. (Though the first post that went into moderation had no logs attached at all...) :confused

    Anyway, take your time. I really do appreciate all the help you've given me so far. :)
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How to view hidden, system files & folders!

    Just reverse those steps and set your hidden files and folders to be..hidden again :)

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  12. EscapeCat

    EscapeCat Private First Class

    I'm clean? YAY!!! :D Thank you!!

    I will perform the above steps on Friday. I've had work followed by classes all week. I really appreciate this. :) I'll let you know how it goes. :)
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're welcome! safe surfing :)
     
  14. EscapeCat

    EscapeCat Private First Class

    Thanks again for everything. But I do have one last question. Since doing those final steps my NETWORK and VOLUME icons from my system tray have disappeared. Any idea how to put them back down there? It's frustrating not having them there.
     
  15. EscapeCat

    EscapeCat Private First Class

    Sorry for the double post...

    Just letting you know that before, I had tried right clicking on the Start menu (I have Vista) and clicking the properties tab, but the volume and network were grayed out so I couldn't select them... It was weird. However, I tried a REBOOT, and they appeared again. Very odd. Anyway, thanks so much fo your help. :) You're awesome, Kestrel. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds