Vundo-Troj/Agent-DJ removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jeffsav, Jul 9, 2006.

  1. Jeffsav

    Jeffsav Private E-2

    Having lots of pop-ups on my wife's laptop. I followed the steps listed in "READ & RUN ME FIRST Before asking for support" and still having problems. I also tried running XoftSpySE which turned up the Vundo-Troj mentioned in the subject header in the Registry Key. I'd prefer not to pay to remove this one thing, however.

    Hijackthis appeared to find it as well --
    (O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file),
    but I'd love to get any guidance to make sure I get rid of the proper things. I'll attach the log from Hijackthis. Thanks in advance for any help.

    Jeff
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You skipped a few steps in the READ & RUN ME.

    You need to attach your log from CounterSpy as requested. Then you need to run step 6 which you skipped. And then attach the two logs form the online scanners.

    You should also run another cleaning procedure mentioned in the sticky threads: Virtumonde aka Trojan Vundo Removal
     
  3. Jeffsav

    Jeffsav Private E-2

    Sorry I didn't realize how careless I was in following the steps. I'll do it the right way when I get home tonight and post the proper logs. Thanks for your response.

    Jeff
     
  4. Jeffsav

    Jeffsav Private E-2

    Slow Performance after Trojan.Downloader.Conhook.AB removal

    Hi,

    This time I followed the correct steps and was finally able to detect a trojan with the name in the subject header. It appears to have been successfully removed, but the PC seems awfully slow.

    I attached 3 log files, including Hijackthis. The CounterSpy log didn't find anything. Sorry to bother everyone, but I'm wondering if there are any obviousl things in the Hijackthis log that might be causing problems. Thanks in advance for any help!

    Jeff
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Slow Performance after Trojan.Downloader.Conhook.AB removal

    But you should not have started a new thread and you did not run VundoFix as I requested (or you ran it but did not attach the requested log)!!!

    I'm merging back to your first thread.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Slow Performance after Trojan.Downloader.Conhook.AB removal

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ltimmgr.dll once and then click the kill button. After you have killed all of the ltimmgr.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of ltimmgr.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINNT\system32\ltimmgr.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.

    Make sure you tell me how things are working now!
     
  7. Jeffsav

    Jeffsav Private E-2

    Sorry about the new thread. Also, I didn't include the Vundo log because I was limited to 3 attachments and that one didn't show anything.

    Things seem to be much better, a lot faster, and haven't had any pop-ups. Not sure if it means anything but when I ran del %windir%\temp\win*.*
    Ii came back with "could not find C:\WINNT\temp\win*.*

    When I ran through your Killbox I noticed at the top of the window it said "5 User Profiles Detected" I thought that was interesting since we haven't set up any extra profiles on the PC.

    As requested, the latest Hijackthis log is attached. Also, not sure if it was causing problems, but I think I had multiple versions of McAfee running, so I've removed them and will reinstall. Does my hijack log look clean now? Thanks for your help and patience!

    Jeff
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but a second message could have been used to attach the fourth log and you should always give feedback anyway (like VundoFix did not find anything).

    Normal! Sometime the infection does not cause these files to be created. Deleting them is a safety precaution incase they do exist.

    There are more accounts then you know about! Some used/created by the OS and software you install.

    1) your account - possibly your name or called owner
    2) Guest account but normally disabled
    3) Administrator account which only shows in safe mode
    4) LocalService account
    5) NetworkService Account

    Use Windows Explorer to open up C:\Documents & Settings
    Everything listed there is a user account even they you may not use them to login and they will not all appear in Control Panel --> Users.


    Yes! Your log is clean. But you should not be running both Spy Sweeper and Spywware Doctor.

    Are these free versions or paid versions?

    And why is it that you never installed Windows Defender (don't install it now, just answer questions first).

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. Jeffsav

    Jeffsav Private E-2

    Thanks for all the good info and the great website for dealing with these problems.

    I had downloaded the free versions of Spy Sweeper and Spyware Doctor. I thought I uninstalled them, but I'll double check.

    I hadn't installed Windows Defender because I was unable to upgrade to SP2 while I had the problems with my pc. Once it was cleaned up, I was able to install SP2. Should I bother with Windows Defender?

    As suggested I'll return to step 1 for the system restore directions.

    Thanks again!

    Jeff
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need ONE realtime antispyware blocker like these three applications. So if you are not going to purchase Spy Sweeper or Spyware Doctor, uninstall them and install and use Windows Defender which is free.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds