Vundo; R n R Me done; am I still having problems?

Discussion in 'Malware Help (A Specialist Will Reply)' started by bingo, Dec 3, 2008.

  1. bingo

    bingo Private E-2

    Hi Dear Angels :)
    I was looking for subtitles to an Italian comedy last night and got hit pretty hard with Vundo, Sheur2, Agent, Cryptor etc... first time in about 6 years i've had a major attagk like this. FYI I'm xp sp2, firefox, AVG8 and windows firewall.

    I was very methodical in running "R n R Me" and it SEEMS I may be clean, but I don't know what to do now; run a new scan above and beyond R n R? Freshen up my security and hope for the best? How can I tell if I'm done?

    There was some anomalous behaviour during the R n R procedure but that is hardly surprising ;-)

    1) instead of SAS giving me notice of quarantine and removal complete, my machine rebooted. I ran again with recommended 5 boxes unchecked and when scan was done I was offered a reboot w/o clicking "finish", which I (perhaps unwisely) did. After reboot I ran again (5 boxes) and again my machine rebooted itself without showing quarantine and removal complete. I chose to move on to Spybot at this point, and have attached all 3 SAS logs to this post.

    2) After the mbam restart suspicious dlls attempted to load (ihugiyelovawub?)

    3) If combofix backed up my registry it did it VERY quickly; I didn't see it happen.

    4) throughout, until I started mgtools, AVG kept finding new instances of Vundo, which I quarantined. I'll go empty the vault in a minute. I have reactivated Resident Shield.

    I am now at Step 3 of R n R, and have not toggled System Restore.

    How can I tell if I'm done?

    ...like many others, I offer my sincerest gratitude for your kindness and generosity; bless you

    yrs
    Kevin
     

    Attached Files:

  2. bingo

    bingo Private E-2

    Re: logs.Vundo; R n R Me done; am I still having problems?

    Here are the MB, CF, and MG logs; thanks again!
    -k
     

    Attached Files:

  3. bingo

    bingo Private E-2

    sorry, I meant I'm at step 3 of winXP cleaning procedure, not step 3 of R n R. Thanks again! -k
     
  4. bingo

    bingo Private E-2

    oh, I just noticed; I have now got an icon in the middle of my desktop for Internet Explorer, and IE has somehow replaced Firefox as the "Internet" item in the top level of my start menu. I normally run firefox from a desktop icon so it's not a big problem, but why it there?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your Desktop is a mess! I strongly recommend that you cleanup all of the junk on it and leave only shortcuts. A cluttered Desktop is malware's playground.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. bingo

    bingo Private E-2

    I'm so glad to hear from you... I was flipping out! I'll do that right away!
    -k
     
  7. bingo

    bingo Private E-2

    I'm getting an update prompt for combofix; do it?
    Also, I installed the JRE11 as part of R n RMe...the file you just directed me to has the same name... do I really need to reinstall it?
     
  8. bingo

    bingo Private E-2

    OK, I ran combofix (version I DLd tuesday)... I clicked "no" or "cancel" or whatever when it offered me a "newer version". It then ran in textbook form, but I never noticed a reboot. I closed the log.txt file, checked for the other file, and went for a "start>turn off computer>restart", which caused my screen to flash and nothing else... after trying that 3 times, I went "start>turn off computer> turn off" (3 times) with the same result... turned to my laptop to send you this message, and 45 seconds later the requested restart took hold; it took about 4 minutes (I type very slowly)...all this anomalous behavior is making me nervous but I've run one more apparently normal "turn off", and turned my computer back on with the big green button for an apparently normal boot. I'm going to continue your instructions from "install the latest JRE"... the only thing to add is that I've been seeing splash screens on bootup from superantispyware... I'll carry on and send the logs you requested... wish me luck!
     
  9. bingo

    bingo Private E-2

    HERE ARE THE LOGS: OK, I've done as you instructed as best I can, and things behaved normally... things seem to be working normally but it's not like I've done anything but MG stuff for the last hour ;-)...

    One thing still wierd: I wrote earlier that "I have now got an icon in the middle of my desktop for Internet Explorer, and IE has somehow replaced Firefox as the "Internet" item in the top level of my start menu."... this is still true. I keep IE around to check my html, but it's installed in the usual place ie C>program files> Internet Explorer, and I almost never open it... what's now on my desktop doesn't seem to be a shortcut, but a seperate install. I've looked at its properties and some of the settings seem a little sketchy to me, but I haven't started it or anything... it's set for homepage = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop

    Thanks!!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's all junk from your HP computer.

    As far as IE replacing FireFox, I'm not sure what happened. Perhaps it was just a reset of a registry key that one of the scanners thought may have been hijacked. This happens quite often since malware changes many settings on PCs and scanners have to sometimes just reset things to defaults just to be sure that the changes being seen are not due to malware.

    You need to run C:\MGtools\GetLogs.bat again and attach a new log. You did not let it finish running and the log is incomplete. Do not close the command prompt window until it tells you it is finished.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot this! I wanted to ask if you knew what the below folder is from Dec 1st? If not, tell me what is inside of the very non-standard folder name:
    Code:
    "C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\"
    #32E2~1       Dec  1 2008              ".#"
     
  12. bingo

    bingo Private E-2

    mg tools log attached...
    I don't know what that folder is but it appears empty (I have views set to see all hidden)...
    Can you think of a reason why print jobs aren't getting to my printer? (HP psc 2600)

    My display seems balky and struggley-- messy desktop icons flickering lots more than i remember...

    gotta run... thanks a bunch!!!
     

    Attached Files:

  13. bingo

    bingo Private E-2

    PS do I appear more or less safe to use email (thunderbird) and browse freely (ffox) at this point?
    thx
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I suggest that you delete it.


    This is a question better asked in the Software Forum.

    Does not appear to be due to malware. I did tell you that you need to cleanup your Desktop and you did not take this advice to heart since it is still a mess.

    I do also suggest that you double your RAM which will help with PC performance. You also may want to try uninstall AVG8 and using a different antivirus program to see it that helps.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. bingo

    bingo Private E-2

    Chaslang you've been swell... alas, I think I'm not quite done: I accidentally clicked on that explorer install and heard a bunch of clicks, which made me suspicious... I closed explorer and ran AVG8, which found nothing. I completed your cleanup procedure except for deleting tools and toggling system restore. I uninstalled combofix and HJT, then downloaded CFix and ran the entire Read and Run Me procedure again (updating the tools as I went). Spybot found Smitfraud-C in the registry. The other tools didn't offer me any "fix" instructions. I'm attaching and appending a new set of logs (including the spybot log which R n R doesn't normally ask for). I hope I haven't done wrong to do this...

    I fixed my printer problem by folk-remedy aka disconnect/reconnect ;-)

    About my desktop: I DID take your advice to heart and tidied up some (and will do more), but, well, it's actually not a mess but intensely-ordered, icons arrayed in a way that visually organizes my workstream. My question is, will replacing all of these items with shortcuts give good benefit? I've heard many different ideas about this, and since you obviously have lots of experience and a strong opinion, I hope you can answer definitively... if the answer is "No, having 80 shortcuts on your desktop is just as bad as having 80 files and folders on your desktop" is there perhaps some way to emulate this organizational strategy without having it all on my desktop?

    I loved AVG 7.5 and I loved the idea of antivirus and antispyware in a single scan, but if 8.0 is a problem, away with it... I'll continue to work through your "How to Protect yourself from malware".

    Will you have a look at my logs again? Getting a positive on Smitfraud 4 hours after you said my logs were clean is a little spooky...

    Thanks again, from the bottom of my geeky heart!
    -kc
     

    Attached Files:

  16. bingo

    bingo Private E-2

    2 more reports
    -k
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are referring to??

    You are still clean.

    The Desktop items are still an issue. If you don't want to change it then it is your decision. You should not have all of this junk on your Desktop. It slows your PC down and it provides easy hiding places for malware and in addition it makes it easy for malware to delete all of these on you. No you don't want to try replacing everything with links. You want to remove most of it period. One other thing you could do but this is not my first choice, is to create folders on your Desktop and group related items into the appropriate folder. It reduces clutter a lot but still can have an effect of slowing your PC down each time the Desktop is access and reloaded.

    Repeat my final instructions to remove everything that you put back in.

    What Spybot found was unimportant and is not a real smitfraud infection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds