vundo struck again

Discussion in 'Malware Help (A Specialist Will Reply)' started by cragarz, Sep 12, 2012.

  1. cragarz

    cragarz Private E-2

    I started off helping a co-worker to regain wireless internet and ended up finding she was running three antivirus programs, and none of which were able to keep the spyware off her computer. I decided to do the read and run me first as multiple infections were found. The end result is 6 files as malware bytes was ran twice and an error message that came up while hijackthis was running. Malwarebytes was ran twice as a bluescreen came up after a restart was done to continue the removal process. I haven't seen any other abnormal activity, but just wanted to make sure the system was clean as she uses the computer for school work as well.
     

    Attached Files:

  2. cragarz

    cragarz Private E-2

    Lastly the error message.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 16 detections:
    • [TASK][SUSP PATH] At8.job : c:\Windows\pstc.exe -> FOUND
    • [TASK][SUSP PATH] At7.job : c:\Windows\rndbs.exe -> FOUND
    • [TASK][SUSP PATH] At6.job : c:\Windows\iopc.exe -> FOUND
    • [TASK][SUSP PATH] At5.job : C:\Windows\crstk.exe -> FOUND
    • [TASK][SUSP PATH] At4.job : c:\Windows\pstc.exe -> FOUND
    • [TASK][SUSP PATH] At3.job : c:\Windows\rndbs.exe -> FOUND
    • [TASK][SUSP PATH] At2.job : c:\Windows\iopc.exe -> FOUND
    • [TASK][SUSP PATH] At1.job : C:\Windows\crstk.exe -> FOUND
    • [TASK][SUSP PATH] At1 : C:\Windows\crstk.exe -> FOUND
    • [TASK][SUSP PATH] At2 : c:\Windows\iopc.exe -> FOUND
    • [TASK][SUSP PATH] At3 : c:\Windows\rndbs.exe -> FOUND
    • [TASK][SUSP PATH] At4 : c:\Windows\pstc.exe -> FOUND
    • [TASK][SUSP PATH] At5 : C:\Windows\crstk.exe -> FOUND
    • [TASK][SUSP PATH] At6 : c:\Windows\iopc.exe -> FOUND
    • [TASK][SUSP PATH] At7 : c:\Windows\rndbs.exe -> FOUND
    • [TASK][SUSP PATH] At8 : c:\Windows\pstc.exe -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.


    Rerun Hitmanpro and have it delete what it finds.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=pwl&s={searchTerms}&f=4
    • O1 - Hosts: 74.113.152.32 istockphoto.com
    • O1 - Hosts: 208.94.0.38 yfrog.com
    • O1 - Hosts: 123.125.50.22 126.com
    • O1 - Hosts: 174.36.28.11 SlideShare.com
    • O1 - Hosts: 213.238.60.190 xing.com
    • O1 - Hosts: 59.106.98.139 seesaa.net
    • O1 - Hosts: 184.72.253.170 hootsuite.com
    • O1 - Hosts: 211.151.146.16 soku.com
    • O1 - Hosts: 72.32.120.222 metacafe.com
    • O1 - Hosts: 204.11.109.133 tribalfusion.com
    • O1 - Hosts: 207.154.14.31 tripadvisor.com
    • O1 - Hosts: 204.9.178.11 typepad.com
    • O1 - Hosts: 216.52.240.133 ustream.tv
    • O1 - Hosts: 174.36.244.132 linkwithin.com
    • O1 - Hosts: 121.67.203.61 scan.novirusthanks.org
    • O1 - Hosts: 209.172.34.139 imagevenue.com
    • O1 - Hosts: 91.206.232.220 booking.com
    • O1 - Hosts: 118.69.251.6 vnexpress.net
    • O1 - Hosts: 208.25.40.80 pandora.com
    • O1 - Hosts: 194.16.241.57 softonic.com
    • O1 - Hosts: 218.83.243.15 match.com
    • O1 - Hosts: 202.57.69.84 nwt.com
    • O1 - Hosts: 65.11.53.80 nttnavi.com
    • O1 - Hosts: 72.51.41.235 nrk.no
    • O1 - Hosts: 110.16.19.157 nozonedata.com
    • O1 - Hosts: 76.106.43.251 nachtagenten.com
    • O1 - Hosts: 70.52.56.163 moscowtimes.com
    • O1 - Hosts: 124.217.235.76 gsn.com
    • O1 - Hosts: 61.178.63.198 mgd.com
    • O1 - Hosts: 174.142.24.205 mediastorm.hu
    • O1 - Hosts: 38.113.207.59 media-servers.com
    • O1 - Hosts: 116.66.206.161 m5prod.com
    • O1 - Hosts: 74.175.65.66 lupa.com
    • O1 - Hosts: 207.200.66.53 liveintercom.com
    • O1 - Hosts: 71.96.135.20 keenspace.com
    • O1 - Hosts: 195.82.124.124 musicmatch.com
    • O1 - Hosts: 202.51.107.37 jetsoftware.com
    • O1 - Hosts: 60.251.54.208 jamba.com
    • O1 - Hosts: 222.161.3.133 ir.com
    • O1 - Hosts: 200.24.227.170 investopedia.com
    • O1 - Hosts: 202.149.24.216 choiceradio.com
    • O1 - Hosts: 91.206.232.220 booking.com
    • O1 - Hosts: 118.69.251.6 vnexpress.net
    • O1 - Hosts: 128.006.192.15 redv.net
    • O1 - Hosts: 194.42.17.124 cgi.com
    • O1 - Hosts: 199.26.254.66 centcomm.com
    • O1 - Hosts: 202.149.24.216 digitallook.com
    • O1 - Hosts: 60.251.189.134 domainfactory.com
    • O1 - Hosts: 222.161.3.133 dvdfocomm.nu
    • O1 - Hosts: 157.95.56.15 e-kolay.com
    • O1 - Hosts: 85.249.23.115 eurosport.com
    • O1 - Hosts: 189.104.149.61 f1cd.com
    • O1 - Hosts: 125.162.92.234 free6.com
    • O1 - Hosts: 80.81.159.20 cdmworldsoftware.com
    • O1 - Hosts: 117.102.101.219 grafika.com
    • O1 - Hosts: 141.76.45.18 chip.com
    • O1 - Hosts: 85.249.23.115 adware-delete.com
    • O1 - Hosts: 69.89.22.135 hbv.com
    • O1 - Hosts: 92.48.201.39 protectorsuite.com
    • O1 - Hosts: 128.31.1.16 techworks.com
    • O1 - Hosts: 85.249.23.117 hyena.com
    • O1 - Hosts: 219.139.158.59 iinfo.com74.113.152.32 istockphoto.com
    • O1 - Hosts: 208.94.0.38 yfrog.com
    • O1 - Hosts: 123.125.50.22 126.com
    • O1 - Hosts: 174.36.28.11 SlideShare.com
    • O1 - Hosts: 213.238.60.190 xing.com
    • O1 - Hosts: 59.106.98.139 seesaa.net
    • O1 - Hosts: 184.72.253.170 hootsuite.com
    • O1 - Hosts: 211.151.146.16 soku.com
    • O1 - Hosts: 72.32.120.222 metacafe.com
    • O1 - Hosts: 204.11.109.133 tribalfusion.com
    • O1 - Hosts: 207.154.14.31 tripadvisor.com
    • O1 - Hosts: 204.9.178.11 typepad.com
    • O1 - Hosts: 216.52.240.133 ustream.tv
    • O1 - Hosts: 174.36.244.132 linkwithin.com
    • O1 - Hosts: 121.67.203.61 scan.novirusthanks.org
    • O1 - Hosts: 209.172.34.139 imagevenue.com
    • O1 - Hosts: 91.206.232.220 booking.com
    • O1 - Hosts: 118.69.251.6 vnexpress.net
    • O1 - Hosts: 208.25.40.80 pandora.com
    • O1 - Hosts: 194.16.241.57 softonic.com
    • O1 - Hosts: 218.83.243.15 match.com
    • O1 - Hosts: 202.57.69.84 nwt.com
    • O1 - Hosts: 65.11.53.80 nttnavi.com
    • O1 - Hosts: 72.51.41.235 nrk.no
    • O1 - Hosts: 110.16.19.157 nozonedata.com
    • O1 - Hosts: 76.106.43.251 nachtagenten.com
    • O1 - Hosts: 70.52.56.163 moscowtimes.com
    • O1 - Hosts: 124.217.235.76 gsn.com
    • O1 - Hosts: 61.178.63.198 mgd.com
    • O1 - Hosts: 174.142.24.205 mediastorm.hu
    • O1 - Hosts: 38.113.207.59 media-servers.com
    • O1 - Hosts: 116.66.206.161 m5prod.com
    • O1 - Hosts: 74.175.65.66 lupa.com
    • O1 - Hosts: 207.200.66.53 liveintercom.com
    • O1 - Hosts: 71.96.135.20 keenspace.com
    • O1 - Hosts: 195.82.124.124 musicmatch.com
    • O1 - Hosts: 202.51.107.37 jetsoftware.com
    • O1 - Hosts: 60.251.54.208 jamba.com
    • O1 - Hosts: 222.161.3.133 ir.com
    • O1 - Hosts: 200.24.227.170 investopedia.com
    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Windows\dsving.exe
    C:\Windows\pcidvc.exe
    C:\Windows\ycinp.exe
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. cragarz

    cragarz Private E-2

    Here are the new logs and roguekiller came up with two log files?


    All processes killed
    ========== FILES ==========
    C:\Windows\dsving.exe moved successfully.
    C:\Windows\pcidvc.exe moved successfully.
    C:\Windows\ycinp.exe moved successfully.
    ========== REGISTRY ==========
    Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}\ not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Cara Kinney
    ->Temp folder emptied: 2251862 bytes
    ->Temporary Internet Files folder emptied: 10928845 bytes
    ->Google Chrome cache emptied: 6207192 bytes
    ->Flash cache emptied: 3127738 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 56504 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 2528 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 24222369 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 45.00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 09122012_171834
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run RogueKiller yet again and attach the new log please. Then explain how things are currently running.
     
  6. cragarz

    cragarz Private E-2

    Everything seems to be running fine. I didn't delete anything from roguekiller as it was left the last time, but left it open if I need to delete them. Here is the text log from this run.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. cragarz

    cragarz Private E-2

    I did the final removal steps and installed avast, performed a scan and everything seems great. I would like to thank you, Kestrel13!, and everybody else who helps out here at MajorGeeks!! I'm sure my friend will appreciate your help as well. :)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You and your friend are most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds