Vundo Help Request

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hargon, Dec 16, 2008.

  1. Hargon

    Hargon Private E-2

    Hello, I had/have a Vundo variant infection that I think I got because I had Sun Java 5.0 (removed now). I went through the steps in the read me, but superantispyware is still coming up with the 6 same hits (1 file, 5 reg keys) for vundo infection.

    A few extra details, I had taken some steps before coming here, and tried vundofix but that program didn't detect any vundo infection (I had run spybot before that, as I already had spybot installed). Also, my IE popups have stopped after going through your read me/windows XP cleaning steps, but superantispyware still detects vundo, altho spybot does not.

    I tried to follow the steps as closely as possible, hopefully I didn't make too many mistakes, log attached following. Could someone please look them over and let me know if I still have an infection and how to get rid of it? Thank you.

    One more important thing to note, the logs for superantispyware and MGtools are the most recent logs/things I've done.
     

    Attached Files:

  2. Hargon

    Hargon Private E-2

    Here is the MGlogs, please let me know what my next step is, thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log. Do the exact same with Malwarebytes.

    Then reboot and run another scan with SUPERAniSpyware and Malwarebytes to see if they come back clean or still has detections. Let me know.


    Unrelated Question: Are you actually able to run L4D on this PC? If so, what model graphics card are you using.
     
  4. Hargon

    Hargon Private E-2

    Hello, and thanks in advance for your time and assistance. I ran the procedure as described in your link and rebooted after, then updated and ran scans with SAS and AntiMal, both logs which are attached. The only change I noticed since running that registry procedure is that now SAS says that the items are unidentified malware instead of vundo (altho this might be the SAS definitions update, I don't know).

    Unfortunately, SAS still comes back as showing the same infections, and AntiMal comes back showing the same 1 hit for a reg key BHO, which apparently they can't remove.

    Anything else I can try? I've run scans from safe mode as well (altho prior to the registry procedure) and that didn't seem to do the trick either.


    As for Left 4 Dead, it runs just fine on my rig, my vid card is a nvidia 7900 GS 256MB. I don't have all the bells and whistles turned on of course, and I play most everything at 1024x768, but L4D doesn't seem too resource hungry and I can host 4 people and still pull 30 FPS. Assuming I don't end up having to wipe my C: hit me up on Steam sometime if you want to play, ID is wearylamplighter.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These recent forms of Vundo are causing us grief in getting these last few registry keys permanently removed. I have asked SUPERAntiSpyware to come look at this thread and some others. Hopefully they can come up with a reason why their program is not able to properly delete these registry keys. Hangon while we wait for them to come in. I guessing that what is left right now is not causing you any major problems though. Is that correct?

    I don't play. My kids do and one of them was having a problem running it on there PC mostly due to the PCI graphics card not being able to support pixelshader 2.0. Also had a lot of lag even though using a 2.8 Ghz PC with 2 GB of RAM. The other son was able to play because he has a 2.8 Ghz Dual-Core and an ATI Radeon X300/X550/X1050 which while not quite what is required for graphics would work.
     
  6. Hargon

    Hargon Private E-2

    I'm not seeing any symptoms of infection (ie popups or random slow downs, etc.), but I've only been using it to run scans with. It is actually my wife's computer with the vundo infection (I'm on my vista machine which I've been using to do any and all internet stuff for the past week). Is it safe to let her go back to using it Online as far as entering user names and passwords is concerned and all that with those registry keys and that one infected .dll still there? I've actually had the net cable physically unplugged from it except for updating the spyware removal programs for fear of getting more infected or it stealing info or something.

    Thanks again for your time and assistance during the holidays.

    Oh, sorry I don't have any tips to offer as far as getting the game to run for your son/daughter, I'm not even sure if my video cards is PCI-E or AGP, although I *think* its PCI-E. If they get it up and running though feel free to pass along my steam ID anyway, my wife and I both play, as does her younger brother and a couple of my college buddies and we keep it pretty clean.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was most likelysafe before, but now we have what should be the fix. Please do the below.

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  8. Hargon

    Hargon Private E-2

    Well this new version of SAS looks like it did the trick, did 2 reboots just to be safe, and even ran an updated Malwarebytes scan and everything came back clean after the first SAS scan. Attaching logs anyway, just in case. Thanks for the help, and happy holidays.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent new! Now let's take care of a few other misc details.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Hargon

    Hargon Private E-2

    Sorry for the delay in responding, I went out of town for a few days. Followed all your latest steps and logs attached, thanks again and hope you had nice holidays. Please let me know if there is anything else I need to do.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Jan 4, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds