vundo and others

Discussion in 'Malware Help (A Specialist Will Reply)' started by ccampboyle, Dec 14, 2008.

  1. ccampboyle

    ccampboyle Private E-2

    Hi,

    I first ran into trouble last night trying to download a new CapWiz driver to install on a new laptop, since my CD of DVDExpress wasn't working anymore. Immediately I started getting my browser spontaneously launching and going to sites trying to sell things. McAfee found nothing. The version of Spybot that came on the laptop found a couple of installs of vundo and vundomundo (sp?). It wouldn't let me update to a new version of Spybot (kept crashing).

    After I found your site, I tried to follow the xp cleaning procedure. Superantispyware found 87 infections. When I hit quarantine and remove I got a fatal error blue screen. I rebooted. I couldn't find a way to try quarantine and remove again, so I had to scan again (I did quick scan this time, just to see if it would work at all.) This time I realized I hadn't disabled my wireless connection, so I did that first. Same thing happened again. On the third go round, I unchecked the Kernel options in scanner options. This time it got some way through quarantining and removing before I got the blue screen. At that point I went on to Spybot, and it now allowed me to download the new version, which found 20 or 21 (I don't remember) trojans and removed them.

    Then I followed the Malwarebyte, ComboFix and MGtools directions.

    Logs for the three SAS scans are attached. I'll attach the other logs in the next post.

    Thanks in advance.
     
  2. ccampboyle

    ccampboyle Private E-2

    Here are the other logs.

    Thanks.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome to the forums. We are currently reviewing your logs and will get back to you with a set of instructions as soon as we can.

    Thanks for your patience
    Kes
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you install the below? :


     
  5. ccampboyle

    ccampboyle Private E-2

    I'm pretty sure I did not.

     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) We need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    File::
    c:\windows\system32\truevision3d.dll 
    c:\windows\system32\tvutil62.dll
    c:\windows\system32\tvmedia.dll
    
    
    
    Folder::
    c:\program files\3D Cozy Fireplace Screen Saver 1.0 
    c:\windows\acezsoft
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2) Now Run Ccleaner!


    3) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger or combofix

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Kestrel13!
     
  7. ccampboyle

    ccampboyle Private E-2

    Hi,

    New logs are attached. It went smoothly. By the way, my c drive also has a file called tv3d_debug.txt which has a date modified of 11/24/2008, a week before I bought the computer. Is it something I should worry about?

    At the moment things appear to be running ok, but I really haven't done anything on this computer except some minor web browsing since it got infected. It certainly isn't opening up the browser spontaneously anymore.

    At one point (before running the read me and run first), it was also sort of hijacking a couple of plug-ins (McAfee site advisor and Foxmarks) and trying to get them to launch when not wanted. I disabled them, and have yet to enable them. Should I try to enable them and see how it goes?

    Thanks *very* much.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please update SUPERanti Spyware and Malware Bytes Anti-Malware and run them again. Attach the logs they generate into your next reply.

    Thanks
    Kestrel13!
     
  9. ccampboyle

    ccampboyle Private E-2

    Hi,

    New logs attached.

    Thanks.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please refer to this "sticky" Resetting Registry and File Permissions and follow the instructions laid out.

    • Then ensure that you update SUPERantispyware and rescan with it.
    • Reboot your machine and run a new scan.
    • Attach the log in generates in your next reply.

    Thanks
    Kes13!
     
  11. ccampboyle

    ccampboyle Private E-2

    Hi,

    Next log attached. It's clean; I'm very excited.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Could you please reboot your machine and then update and re-scan with SAS another time, attaching the log it generates into your next reply here.

    Thanks
    Kes13!
     
  13. ccampboyle

    ccampboyle Private E-2

    Hi,

    Sorry, I didn't realize I was supposed to run the scan again. Here is the new log.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. ccampboyle

    ccampboyle Private E-2

    Thanks so much. I will get right on it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds