vundo.t have i cleaned?

Discussion in 'Malware Help (A Specialist Will Reply)' started by chix2k8, Jul 6, 2008.

  1. chix2k8

    chix2k8 Private E-2

    Hey there! long time no help:p Can you please check these for me? Have found that 'Mywebsearch' crap, using spybot . Many thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I am seeing is this:

    C:\WINDOWS\Tasks\A66AD950918554F8.job

    Use windows explorer to find and delete it.

    What problems are you having?
     
  3. chix2k8

    chix2k8 Private E-2

    Well, the most simple tasks is using 100% CPU. I have s**t loads of porn arriving in my inbox, and poker keeps installing. I have taken all the steps i should have, will try again.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to delete all items in your email program as some attachment or item is infected.

    What do you mean poker keeps installing? By itself? It just appears?

    What security setting do you have in your browser? What setting are in your firewall?

    Please re-run MWB's and SAS on all user profiles and attach any log that finds something.
     
  5. chix2k8

    chix2k8 Private E-2

    I have deleted all my emails. Poker just seems to appear, I havnt seen it installing though, it also isnt bundled in with any other program that i installed. My browser settings seem to be ok, everything is set to ask permission. I have however, noticed in my firewall, lansetx.exe. I have now blocked that, will update all virus programs and so on, then scan in safe mode, should i disable system restore? Also MBAM and SAS didnt pick up anything, neither did spybot.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets make sure before you disable system restore.

    lansetx.exe is the setup file for your ethernet adapter. Not something that needs blocking.

    Can you now do an online scan with Bitdefender?

    Go here and download SysClean:

    http://www.trendmicro.com/download/dcs.asp

    You will need to download two additional files, one for viruses and the other for spyware. Instructions for which ones to download are found here:

    http://www.trendmicro.com/ftp/products/tsc/readme.txt

    After running SysClean, attch the log from it.
     
  7. chix2k8

    chix2k8 Private E-2

    Ok i have unblocked that program. I cannot use bitdefender for some reason, have made sure I.e was set up for that, but its having none of it. Will do the trendmicro scan. Thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you have problems with that.
     
  9. chix2k8

    chix2k8 Private E-2

    Man!! it was scannin for maybe 5 hours before my system failed, or at least i think it failed, there was no sign of the program when i got up this morning, mthe report does say though, that it was aborted? Will try it again now. My comp is now telling me tyhat virtual memory is low and stuff, i know its not.
     
  10. chix2k8

    chix2k8 Private E-2

    Good program
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, that caught a lot of junk....how are things running now?
     
  12. chix2k8

    chix2k8 Private E-2

    Crap! lol still really slow, 100% CPU
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And still unable to do an online scan?

    Please re-run MWB's and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MWB's.
     
  14. chix2k8

    chix2k8 Private E-2

    I cant scan online for some reason:confused Avira is catchin stuff all over the place! MWB has been sannin for like....11 HOURS!! Thank god for sleep. Am gonna look up some info on the virus's caught. On the Sysclen program, when scanning, i noticed it reported lots of errors, what has it done with the errors?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see a log.....let me know what Avira is reporting ( the log ) . and get me the MGLogs.zip. :(
     
  16. chix2k8

    chix2k8 Private E-2

    Man, this pc is proper messing about. I had a few logs for you to see, but i think the virus/spyware is trying hard. My anti virus stopped working properly, i couldnt get to the logs to save. I re-installed, or i tried! should i say. I cannot even install it anymore. MWB has picked up the same virus that infected me a couple of months ago. My anti virus caught 2 different viruses. I had a message about my firewall setting being tampered with by an outside source. SAS found nothing.
     

    Attached Files:

  17. chix2k8

    chix2k8 Private E-2

    TR/Crypt.XPACK.Gen - Trojan, SPR/Tool.Hide.A These r the viruses Avira picked up on, before it all messed up. I dont know if i should uninstall my firewall and reinstall it? no matter what i try i cant download Avira or anything from this site
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you not run the MGTools and get me a new log?

    You can do as our guide suggest:

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  19. chix2k8

    chix2k8 Private E-2

    Have scanned with Avira, MWB and MGTools in safe mode.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have the logs for MWB's....did you run SAS?

    I'm not seeing anything .....

    Please run the F-Secure Online Scanner

    Note: This Scanner is for Internet Explorer Only!

    • Follow the Instruction Here for installation.
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
     
  21. chix2k8

    chix2k8 Private E-2

    The log for MWB is below....#66. SAS picked up nothing, and i named what viruses Avira picked up before i uninstalled. Will run this scan over night and see what i find in the morning. Thanks
     
  22. chix2k8

    chix2k8 Private E-2

    Ok i keep getting a runtime error when its scanning, 3 times it has crashed, i will keep trying
     
  23. chix2k8

    chix2k8 Private E-2

    Statistics
    Scanned:

    * Files: 64640
    * System: 3537
    * Not scanned: 82

    Actions:

    * Disinfected: 0
    * Renamed: 0
    * Deleted: 0
    * None: 0
    * Submitted: 0

    Files not scanned:

    * C:\PAGEFILE.SYS
    * C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
    * C:\WINDOWS\SYSTEM32\CONFIG\SAM
    * C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
    * C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
    * C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
    * C:\53C23CF0220964925019BE66\ADMPARSE.DLL
    * C:\53C23CF0220964925019BE66\ADVPACK.DLL
    * C:\53C23CF0220964925019BE66\BROWSEUI.DLL
    * C:\53C23CF0220964925019BE66\CORPOL.DLL
    * C:\53C23CF0220964925019BE66\CUSTSAT.DLL
    * C:\53C23CF0220964925019BE66\DHTMLED.OCX
    * C:\53C23CF0220964925019BE66\DXTMSFT.DLL
    * C:\53C23CF0220964925019BE66\DXTRANS.DLL
    * C:\53C23CF0220964925019BE66\EXTMGR.DLL
    * C:\53C23CF0220964925019BE66\HMMAPI.DLL
    * C:\53C23CF0220964925019BE66\ICARDIE.DLL
    * C:\53C23CF0220964925019BE66\IDNDL.DLL
    * C:\53C23CF0220964925019BE66\IE4UINIT.EXE
    * C:\53C23CF0220964925019BE66\IEAKENG.DLL
    * C:\53C23CF0220964925019BE66\IEAKMMC.CHM
    * C:\53C23CF0220964925019BE66\IEAKSIE.DLL
    * C:\53C23CF0220964925019BE66\IEAKUI.DLL
    * C:\53C23CF0220964925019BE66\IEAPFLTR.DLL
    * C:\53C23CF0220964925019BE66\IECUSTOM.DLL
    * C:\53C23CF0220964925019BE66\IEDKCS32.DLL
    * C:\53C23CF0220964925019BE66\IEDW.EXE
    * C:\53C23CF0220964925019BE66\IEENCODE.DLL
    * C:\53C23CF0220964925019BE66\IEEULA.CHM
    * C:\53C23CF0220964925019BE66\IEFRAME.DLL
    * C:\53C23CF0220964925019BE66\IEPEERS.DLL
    * C:\53C23CF0220964925019BE66\IEPROXY.DLL
    * C:\53C23CF0220964925019BE66\IERNONCE.DLL
    * C:\53C23CF0220964925019BE66\IERTUTIL.DLL
    * C:\53C23CF0220964925019BE66\IESETUP.DLL
    * C:\53C23CF0220964925019BE66\IESUPP.CHM
    * C:\53C23CF0220964925019BE66\IEUI.DLL
    * C:\53C23CF0220964925019BE66\IEUINIT.INF
    * C:\53C23CF0220964925019BE66\IEXPLORE.CHM
    * C:\53C23CF0220964925019BE66\IEXPLORE.EXE
    * C:\53C23CF0220964925019BE66\IMGUTIL.DLL
    * C:\53C23CF0220964925019BE66\INETCPL.CPL
    * C:\53C23CF0220964925019BE66\INSENG.DLL
    * C:\53C23CF0220964925019BE66\JGAW400.DLL
    * C:\53C23CF0220964925019BE66\JGDW400.DLL
    * C:\53C23CF0220964925019BE66\JGMD400.DLL
    * C:\53C23CF0220964925019BE66\JGPL400.DLL
    * C:\53C23CF0220964925019BE66\JGSD400.DLL
    * C:\53C23CF0220964925019BE66\JGSH400.DLL
    * C:\53C23CF0220964925019BE66\JSCRIPT.DLL
    * C:\53C23CF0220964925019BE66\JSPROXY.DLL
    * C:\53C23CF0220964925019BE66\LICMGR10.DLL
    * C:\53C23CF0220964925019BE66\MSFEEDS.DLL
    * C:\53C23CF0220964925019BE66\MSFEEDSBS.DLL
    * C:\53C23CF0220964925019BE66\MSFEEDSSYNC.EXE
    * C:\53C23CF0220964925019BE66\MSHTA.EXE
    * C:\53C23CF0220964925019BE66\MSHTML.DLL
    * C:\53C23CF0220964925019BE66\MSHTML.TLB
    * C:\53C23CF0220964925019BE66\MSHTMLED.DLL
    * C:\53C23CF0220964925019BE66\MSHTMLER.DLL
    * C:\53C23CF0220964925019BE66\MSLS31.DLL
    * C:\53C23CF0220964925019BE66\MSRATING.DLL
    * C:\53C23CF0220964925019BE66\MSTIME.DLL
    * C:\53C23CF0220964925019BE66\NORMALIZ.DLL
    * C:\53C23CF0220964925019BE66\OCCACHE.DLL
    * C:\53C23CF0220964925019BE66\OCCACHE.INI
    * C:\53C23CF0220964925019BE66\PNGFILT.DLL
    * C:\53C23CF0220964925019BE66\SHDOCVW.DLL
    * C:\53C23CF0220964925019BE66\SHLWAPI.DLL
    * C:\53C23CF0220964925019BE66\SPMSG.DLL
    * C:\53C23CF0220964925019BE66\SPUNINST.EXE
    * C:\53C23CF0220964925019BE66\SPUPDSVC.EXE
    * C:\53C23CF0220964925019BE66\TDC.OCX
    * C:\53C23CF0220964925019BE66\TRIEDIT.DLL
    * C:\53C23CF0220964925019BE66\URL.DLL
    * C:\53C23CF0220964925019BE66\URLMON.DLL
    * C:\53C23CF0220964925019BE66\VBSCRIPT.DLL
    * C:\53C23CF0220964925019BE66\VGX.DLL
    * C:\53C23CF0220964925019BE66\WEBCHECK.DLL
    * C:\53C23CF0220964925019BE66\WEBCHECK.INI
    * C:\53C23CF0220964925019BE66\WINFXDOCOBJ.EXE
    * C:\53C23CF0220964925019BE66\WININET.DLL

    Options
    Scanning engines:

    * F-Secure USS: 2.40.0
    * F-Secure Hydra: 2.8.8110, 2008-10-29
    * F-Secure AVP: 7.0.171, 2008-10-29
    * F-Secure Pegasus: 1.20.0, 2008-09-22
    * F-Secure Blacklight: 1.0.68

    Scanning options:

    * Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
    * Use Advanced heuristics
     
  24. chix2k8

    chix2k8 Private E-2

    I am still using that firewall? thats more of a statement than a questionrolleyes I dont understand whats going on? I did a few days back, get a message saying that my firewall settings were tampered with and that full settings were applied, to protect me. :-S Either way, i know something here
     
  25. chix2k8

    chix2k8 Private E-2

    Oops sorry, clicked to come here n it took me back to an older post:-D
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Having your firewall tighten security means it is doing what it is supposed to do, protect you from external attacks. This could just be a result of your surfing habits or what you're downloading.
     
  27. chix2k8

    chix2k8 Private E-2

    I now keep getting a message reading....'jpegdll not found, reinstall' over and over........and over:( and that virtual memory warning keeps popping up
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is starting to sound like either a software or hardware issue.

    If you have your xp cd, go to start / run / type "sfc /scannow" without qoutes and note the space between the c and the /

    Let it run twice.

    The reason you are getting memory alerts is you are way short of ram.
     
  29. chix2k8

    chix2k8 Private E-2

    And what if i dont have my xp disc?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can borrow one...as long as it is the exact same version of what you are running:
    Home, Pro, etc.
     
  31. chix2k8

    chix2k8 Private E-2

    I can?:confused from where?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No friends that have computers running xp?

    If so, what would you do if your system crashed and you needed to do either a complete re-installation or a repair install?
     
  33. chix2k8

    chix2k8 Private E-2

    how much will it cost to buy one? I will ask a m8 tomorrow
     
  34. chix2k8

    chix2k8 Private E-2

    oh i just hope it stays ok
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can post in the software section regarding any other non-malware issues you are having. :)
     
  36. chix2k8

    chix2k8 Private E-2

    Ok, well thanks for ur time neway. You kinda understand my paranoia with viruses n stuff:) take care
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....and do look into adding ram to your system. :)
     
  38. chix2k8

    chix2k8 Private E-2

    Yeh i will, i just dont wanna deal with a techie man:cry: hey, is this a record....amount of posts on 1 topic?:-D:wave
     
  39. chix2k8

    chix2k8 Private E-2

    Hello Stranger.

    Am inneed of help again. Have picked up on a few virus'.
    logs below
     

    Attached Files:

  40. chix2k8

    chix2k8 Private E-2

    ouch
     

    Attached Files:

  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AVG is just finding items in your system restore files and ComboFix. You can handle this by doing the following:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  42. chix2k8

    chix2k8 Private E-2

    Thanks... i have done all that. I am still not able to gain access to documents and settings, its acting like i dont have administrator rights even tho im the only one with those rights. I try to click on owners documents and settings and it tells me access is denied?
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Code:
    C:\Documents and Settings\"
    ADMINI~1      25 Feb 2006              "Administrator"
    ADMINI~1.FAM  10 Aug 2007              "Administrator.FAMILYCOMPUTER"
    ADMINI~1.YOU  27 Jul 2006              "Administrator.YOUR-1P37D9KIHS"
    ALLUSE~1      28 Oct 2004              "All Users"
    BABYBL~1      13 Nov 2005              "babyblueeyes"
    DEFAUL~1      28 Oct 2004              "Default User"
    GUEST         28 Jan 2005              "Guest"
    KID'S         25 Jul 2007              "Kid's"
    KID'S~1.YOU   13 Jun 2008              "Kid's.YOUR-1P37D9KIHS"
    LOCALS~1      28 Oct 2004              "LocalService"
    NETWOR~1      28 Oct 2004              "NetworkService"
    OWNER         28 Oct 2004              "Owner"
    OWNER~1.FAM   29 Jul 2007              "Owner.FAMILYCOMPUTER"
    OWNER~1.THE   12 Sep 2006              "Owner.THE-BOX"
    OWNER~~1      23 Oct 2008              "OWNER~1~FAM"
    
    Does this happen on all accounts?

    Again, this is something best addressed in the software forums.
     
  44. chix2k8

    chix2k8 Private E-2

    :-ohi

    I am still having trouble. I have been told it is a rootkit but nobody seems to know what to do....im assuming this as im getting no more response?
    Can u help plz?
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Getting no response from who? Advised by who?

    If you suspect a rootkit, then run this: Running Rootkit Revealer

    It has been three weeks since your last post so I suggest that you go back to the Read and Run First instructions and download the latest versions of the scans and run them an then attach the logs.
     
  46. chix2k8

    chix2k8 Private E-2

  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not attach the logs so that I could check them.
     
  48. chix2k8

    chix2k8 Private E-2

    I have tried to save the logs but it will not allow me to? The other programs picked nothing up the last time i scanned, will do again tho if needed. rootkit program is picking things up but crashes when i try to save the log.
     
  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just tell me what it is finding.
     
  50. chix2k8

    chix2k8 Private E-2

    1 path:HKU\DEFAULT\control panel\international
    Time stamp:2009-02-13 20:59
    size: 0 bytes
    description: Security mismatch
    2 path:HKU\DEFAULT\control panel\international\geo
    Time stamp:2009-02-13 20:59
    size:0 bytes
    description:Security mismatch
    3path:HKU\-1-5-21-670792205-2161807218-2885428501-1003\control panel\international
    Time stamp:2009-02-13 20:59
    Size:0 bytes
    Description:Security mismatch
    4 Path:HKU\5-1-5-21-670792205-2161807218-2885428501-1003\control panel\international\geo
    Time stamp:2009-02-13 20:59
    Size:0 bytes
    Description:Security mismatch
    5 Path:HKU\5-1-5-18\control panel\international
    Time stamp2009-02-13 20:59
    Size0 bytes
    Description:Security mismatch
    6 Path:HKU\5-1-5-18\control panel\international\geo
    Time stamp:2009-02-13 20:59
    Size:0 bytes
    Description:Security mismatch
    7 Path:HKML\SECURITY\Policy\secrets\SAC*
    Time stamp:2001-09-04 02:20
    Size:0 bytes
    Description:Key name contains embedded nulls(*)

    WILL FINISH TOMORROW...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds