VirtuMundo -- opnnm.dll version

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dbutzer, Sep 19, 2005.

  1. dbutzer

    dbutzer Private E-2

    I'm sure you see this a lot, but HELP! McAfee has identified a file "c:/winnt/system32/opnnm.dll" as having VirtuMundo, but it can't clean or delete it. Spyware Doctor doesn't even see it; nor do any of my other anti-spyware programs.

    My browser does exhibit the symptoms of VirtuMundo: pop-up adds keep popping up, usually to supposed -- yeah, right -- anti-spyware software.

    Ran HijackThis. Tried to clear the entries (it's listed as a BHO), but that didn't work. Tried to delete the file both manually and using HijackThis' delete on reboot function. That didn't work. Tried a couple other things that also failed.

    The HijackThis logs are attached. Can you help me to get rid of this thing?
     
  2. dbutzer

    dbutzer Private E-2

    Ooops! Looks like I had an old/broken version of Ad-Adware. Running a newly downloaded/updated on now. It's found lots of SOMETHING, hoping it's the VirtuMundo. Please don't spend time in a reply until I get back.

    Thanks!

    PS GREAT site!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like Vundo B. You will have to work thru the below steps first. Then we will know for sure what the problem is and how to fix it.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. dbutzer

    dbutzer Private E-2

    Been doing all that -- installed/updated all latest versions, running scans now. Not done yet. About the only thing that's popped out is BitDefender identified CCleaner as having some variant of a trojan virus (!). Is this a know goof, or is CCleaner infected? (Downloaded it from the TX site.)

    Not done with all the scans yet, so no logs attached.
     
  5. dbutzer

    dbutzer Private E-2

    Here's what BitDefender had to say about CCleaner:

    C:\Program Files\CCleaner\ccleaner.exe
    Infected with: Trojan.Banker.VB.15E70689

    C:\Program Files\CCleaner\ccleaner.exe
    Disinfection failed

    C:\Program Files\CCleaner\ccleaner.exe
    Deleted

    OK, now I'm afraid to re-install ccleaner and run it. The last thing I want is another problem. Help?
     
  6. dbutzer

    dbutzer Private E-2

    OK, ran all the steps. Notes on results are attached as "logs." (I decided that the CCleaner "infection" was a false positive and ran it as instructed in the sticky thread.)

    Still having the problem. Still can't delete opnnm.dll, which McAfee still says is infected with VirtuMundo. The HijackThis log is also attached from when I ran it in safe mode. The log includes "opnnm.dll" and a BHO. Delete on reboot did not work. (I also have a copy of the log from normal mode -- will attach to next reply.)

    I also have the startup log from HijackThis. Here's the BHO section:

    (no name) - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
    (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    (no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
    (no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
    (no name) - C:\WINNT\system32\opnnm.dll - {827DC836-DD9F-4A68-A602-5812EB50A834}
    (no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll - {B56A7D7D-6927-48C8-A975-17DF180C71AC}

    If you need the whole log, from safe or normal mode, I've got it. Please help -- I'm at wit's end!

    Thanks!
     
  7. dbutzer

    dbutzer Private E-2

    HijackThis log under normal boot mode is attached.
     

    Attached Files:

  8. dbutzer

    dbutzer Private E-2

    Arrrg, the adware keeps hijacking my upload window. Failed to upload the logs and hijackthis log under safe mode. Trying AGAIN (fourth time).

    More AAARRRG! Can't get attachements to work now. Well, here are my notes from the various scans:

    BitDefender Notes:

    C:\Program Files\CCleaner\ccleaner.exe
    Infected with: Trojan.Banker.VB.15E70689

    C:\Program Files\CCleaner\ccleaner.exe
    Disinfection failed

    C:\Program Files\CCleaner\ccleaner.exe
    Deleted


    RAV notes:

    Scan started at 9/20/2005 3:18:19 AM

    Scanning memory...
    Scanning boot sectors...
    Scanning files...
    C:\Download\1st page 2000 html editor\setup.exe->(CABSfx)->\data1.cab->[ishld.445]->(SCRIPT0000) - JS/Loop* -> Infected

    Scanned
    ============================
    Objects: 69869
    Directories: 6817
    Archives: 8515
    Size(Kb): 1781208
    Infected files: 1

    Found
    ============================
    Viruses found: 1
    Suspicious files: 0
    Disinfected files: 0
    Mail files: 154


    Ad-aware SE:

    Appeared to run normally, nothing detected


    Spybot S & D:

    Appeared to run normally, nothing detected


    CWShredder:

    "removed" vx2.look2me, but remained present after multiple reboots.


    AboutBuster:

    appeard to run normally


    kill2me:

    appeared to remove look2me


    hsremove:

    removed 8 items, but when run again, said that it again removed 8 items
     
  9. dbutzer

    dbutzer Private E-2

    Can't seem to do any more attachments. I have a "better" hijackthis log (more stuff shut off) as well as a hijackthis log from running under safe mode (almost no tasks running). I can post them if you need them or try to attach them again.

    Sigh.
     
  10. dbutzer

    dbutzer Private E-2

    Um, help? Is there something else you need? Increasingly desperate here...
     
  11. dbutzer

    dbutzer Private E-2

  12. dbutzer

    dbutzer Private E-2

    KILLED IT! Yeah!!!!! :D

    Used the KillVundo.bat -- it aced the d### thing. No more WinFixer ads!!! Whooopeeeee!!!!

    Thanks for the great site, guys (and gals, if any)!!!

    PS It's amazing to me that Symantec, McAfee, et al. couldn't write a tool that worked. Sheesh, what am I paying them for? LOL

    Once I have some extra cash, a donation will be forthcoming.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's make sure! Post a new HJT log from normal boot mode (we almost never want them from safe mode - they are typically of no use).

    That tool from Symantec is old and does not pick up the new form and remove it. The problem that many people are calling Winfixer is still just a Virtumundo problem with the same type problem files as in Vundo B. We have fixed dozens of them here. They are no big deal.
     
  14. dbutzer

    dbutzer Private E-2

    Here you go. No unknown BHO's, no O20's, all my scanners (definitely have enough now, LOL) say everything is clean, and my computer is behaving properly for the first time in weeks and weeks! I not a pro, though, so I might still be missing something.

    Thanks for all the help!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Vundo is gone. We just have a few minor cleanups to do. But I'm curious how you and many other people are getting CWShredder to be running as a service. This is not how it should be running and does not get installed that way just by doing what is in the READ ME FIRST. It actually requires no installation. You just download it and run it.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so.

    Run HijackThis again and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/23962285f317ed717505/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Now that should finish your cleanup. To help you stay clean, see the steps in the below:

    How to Protect yourself from malware!
     
  16. dbutzer

    dbutzer Private E-2

    Not sure how CWShredder got on as a service. I just downloaded and ran it. Maybe it's an update? Anyway, after my last log, I killed it myself.

    Will do the rest of the cleanup. Thanks for the help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! It is not a service and never should be! Funny thing is I have seen this very often on systems having Vundo problems. I really cannot believe there is any relationship between them but it is just an observation. Perhaps where you are all going to pickup Vundo is also doing this strange thing to make it look like CWShredder is a service. I have installed CWShredder on literally dozens of PCs (even tried it again with latest version), it never shows up as a service because it is just a simple executable that you download and run.

    Which link from the download list did you use? Try it again! Does it come back as a service (an O23 line in you HJT log) again?
     
  18. dbutzer

    dbutzer Private E-2

    Actually, after I stripped it as a service, I ran it again to see what would happen. Didn't re-appear as a service.

    Strange, eh?

    Got a testbed somewhere that you can infect with Vundo and then run CWShredder on? Maybe that might help you figure out what's going on. Maybe Vundo or some part of it is trying to hide in a service called CWShredder as camouflage??

    In any event, it doesn't seem to do any damage or harm...
     
  19. dbutzer

    dbutzer Private E-2

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No test bed. We cannot even get anyone to reveal where the heck the are getting this infection from. Perhaps no one wants to reveal their surfing habits or maybe they just do not know where it came from.

    I have tried surfing on a test PC with no AV, no spyware protection, and no firewall and I still cannot get most of the crap the people seem to pickup.
     
  21. dbutzer

    dbutzer Private E-2

    Can I e-mail you with where I *think* that I got mine? (Don't want to post it because of potential libel issues -- don't want to get sued.)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Send it to me in a PM (Private Message).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds