Victim of vundo and haxdor e

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ghostwolf, Feb 8, 2010.

  1. ghostwolf

    ghostwolf Private E-2

    At the end of January, I began to get IE popups while using Firefox on my laptop. The only thing I had recently done was to download a Java update. My security at that time consisted of the Windows Firewall and AVG free edition.

    Actually, the first thing that was caught was Haxdor E by the CA Yahoo Antispy and I was able to remove it on that scan. I also ran a full scan with AVG as I continued to get the popup ads both on new IE windows and Firefox windows. This scan displayed the following alert popup:

    "C:/windows/system 32/lagoguze.dll
    Threat: Trojan Horse Vundo.KE
    Detected on Open"

    It was removed on that scan.

    Not being knowledgeable about viruses and cleaning them off a system completely, I ended up installing a security suite offered by my ISP and ran a full scan. The following alert was displayed:

    "Adware blocked by Charter Suite in file deSrcAs.dll"

    And Charter removed it.

    Still getting popups, I ran a full scan and a dialog box came up stating:

    "F-Secure Internet Shield Daemon has encountered a problem and needs
    to close"
    The scan didnt pick up anything else----

    Booting up a day later, the Firewall displayed the following alert:

    "new connection to internet tried-outbound from C:/windows/system 32/ called venumeho.dll Portocol (Port):TCP (80)"

    Not sure what this was, I denied it and restarted the computer again and got a bsod stating:

    "an attempt was made to write to read-only memory--if problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing.
    TECH INFO: STOP 0X00000BE (0XF8B299F0, 0X00038121, 0X80549B90,
    0X00000A)"

    On subsequent start-ups I started receiving this error:

    "error loading c:/windows/system 32/daharubo.dll
    The specified module could not be found"

    (Running MSConfig and checking and unchecking startup items seemed to take care of this--actually it ended up disappearing after the first uncheck I did which I had rechecked to see if it would return and it didnt)

    I tried two more things including creating a new admin profile in safe mode and rebooting and deleting old profile (this supposedly would clear system of traces of virus) and a system restore which I undid after I seemed to lose the ability to get on the net with IE. The system restore seemed to uninstall my Security Suite and I had no idea how to start it up anymore--The files were there, but the program was no longer listed in my add/remove programs and a reinstall attempt failed numerous times even with the help of a support rep (later I found a uninstaller link online in their support forum that I used with apparent success when it came time to run ComboFix--was getting a warning that Charter Antivirus was activated and since I didnt have any way to de-activate it, I just ended up uninstalling it for now).

    When I finally came across Major Geeks forum, I did everything in the Read Me First section and used another computer to download all the tools on a flash drive and transfer them to my laptop. I was able to successfully run all of the tools and generate logs.

    My main reason for writing this thread is for someone to review my logs to see if my system is entirely clean before I reconnect online and try reinstalling my Security Suite. If I'm not clean, I need further direction on what to do to become completely clean.

    Thank-you in advance for your time--


    First three logs are attached below--
     

    Attached Files:

  2. ghostwolf

    ghostwolf Private E-2

    Here are the remaining two logs generated:
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you do not intend to keep avg then you should run the removal tool, which you can remind me about after we have made some headway with what remains of the malware removal.


    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    2. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3. Please go to Add/Remove programs and uninstall the following software:
    • Java 2 Runtime Environment, SE v1.4.2_03

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\documents and settings\All Users\Application Data\fssg
    
    File::
    c:\windows\system32\config\systemprofile\Local Settings\Application Data\prvlcl.dat
    c:\windows\system32\hotomoho.dll.tmp
    c:\windows\system32\linanotu.dll.tmp
    C:\WINDOWS\system32\bevuzufo
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\NoExplorer]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. ghostwolf

    ghostwolf Private E-2

    Kestrel13!--Thank-you so much for helping me out--

    For the most part, I had no problems doing or running anything you asked me to do. However, when it came time to run Combofix and drop the CFscript.txt onto it, I didn't realize I was unplugged from the net and ran it without any updates. I ended up plugging in after generating an MGlog and re-ran Combofix with another copy of the CFscript.txt after Combofix updated. I then ran MGtools again and generated another log. I ended up numbering the sequences "combofixlog2.txt" and "MGlogs2.zip" for the first run without the updated Combofix and then "combofixlog3.txt" and "MGlogs3.zip" for the sequence with the updated Combofix. I hope that didnt mess anything up on my part--:-o

    I have included all 4 logs on this post--

    The computer itself seems to be running better and faster than it ever has. Haven't tested surfing the internet yet and wont until I get the ok to plug back into it and try it out. I need to try and reinstall my Security Suite, however, before I do that. It will remain off and unplugged, though, until I get the ok from you to do anything--
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK there's no malware that I can see now. All looks good.

    You can do that but first we need to clear up from avg:


    Run the Official AVG Removal Tool

    Make sure you also delete any leftover AVG folders in Program Files and Documents & Settings/Application Data directories.

    You should then restart your system and run 'CCleaner' (Not the registry part)


    You should now restart your system and then reinstall the AV of your choice.

    If you have any more problems with this then you will need to visit the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. ghostwolf

    ghostwolf Private E-2

    Thank-you so much for helping me out, Kestrel13!--

    After reading disheartening information about gifted people wasting their intellects to purposefully write code for things such as trojan horses and the whole concept of hacking itself, it brought great hope to me to see that there are others out there that are using their intellect for fighting that foolishness and restoring systems, AS VOLUNTEERS--

    Major Geeks are superheroes to me--:major
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome. safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds