Vundo madness

Discussion in 'Malware Help (A Specialist Will Reply)' started by pfran42, Jan 27, 2009.

  1. pfran42

    pfran42 Private E-2

    I have a work machine that wont allow IE of Firefox to start on it. I moved the necessary scanning files over to it via thumb drive and have completed all steps listed in this forum.

    Please review my logs and let me know if I am cleaned up.

    Thank you for your time
     

    Attached Files:

  2. pfran42

    pfran42 Private E-2

    here is the 4th log for review
     

    Attached Files:

    • log.txt
      File size:
      15.5 KB
      Views:
      4
  3. pfran42

    pfran42 Private E-2

    I had also noticed that even when IE and FF were closed down, the task manager showed 2 active IEXPLORER.EXE processes. The hard drive was completely saturated and I discovered that there were a ton of what appeared to be bogus files in (this is a guess as I deleted the directory) C:\Documents and Settings\Network User\App Data\Local\IE5. The was over 10 GB of what appeared to be HTML pages referencing everything from pimpmyspace, to sexxx101.

    I followed all of the instructions to a T and now the machine apears to be running much better. My concern is that the last time I followed these steps, the computer degrated back to its malware ridden state in about two days. This time I am including the proper logs for the experts at Major Geeks to review. Please let me know if there is any other data that I can provide.

    Thanks again for your time.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really!

    The below is a direct quote from step 1 of the READ & RUN ME and it is in a very large bold font and cannot be missed.



    Also you did not accept the license agreement for TrendMicro HijackThis. You need to click Accept twice as stated.


    Once you do this and then reboot we need a new log from running MGtools. Then we can continue. We did say this would delay getting help.


    You should have follow the instructions you were given in the last message last time. Because you didn't, your PC is still not properly protected and that is your fault. Here is your last thread: HELP ME! I have a major deliverable due on Fri See message # 11 posted on 12/13/2008
     
    Last edited: Jan 28, 2009
  5. pfran42

    pfran42 Private E-2

    Thanks for the prompt reply. The computer from my previous post is my work laptop and it works perfectly!

    This thread is dealing with a completely different machine.

    I do remember going into msconfig and setting it to boot with normal startup. Is there a possibility that something might have changed the setting back to whatever it was that you read from the logs?

    I will go through the necessary steps again tonight and repost the required logs. Sorry for the wasting your valuable time.
     
  6. pfran42

    pfran42 Private E-2

    OK, I checked again and msconfig was set for normal startup mode (like the instructions say). Not sure what happened when I was going through the cleaning procedure the first or second time but perhaps I did a step out of order...my bad.

    As for where you say "Also you did not accept the license agreement for TrendMicro HijackThis. You need to click Accept twice as stated.", I looked at the instructions quoted here:

    "o You may see a popup window with a license agreement for TrendMicro HijackThis. Make sure you click the I Accept button."

    I did not see where it said to accept the agreement twice. Not trying to be combative, but if the agreement pops up twice maybe the directions should say something about accepting the agreement twice. If I missed documentation contrary to my findings, I apologize.

    Here are the new logs that you requested. Once again, thank you for taking your time to assist me with this issue.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are correct. This was missing. Perhaps somewhere along the way with edits for different versions it was deleted or just left out. It is there now though so thanks for your observation. ;)

    The below however is not where MGtools is to be run from and that is explained:
    C:\Documents and Settings\scott\Desktop\Work by Paul Francis 01.22.09\AV Tools\MGTools\MGtools.exe

    MGtools.exe should be located in your root folder. That is, C:\MGtools.exe Not doing this can sometimes cause improper execution. Delete the above copy ( and folder).

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds