Vundo Trojan (Part 1)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Challenged, Jul 3, 2008.

  1. Challenged

    Challenged Private E-2

    Hi everyone, I am very content that I found this site - the information available is incredible.

    It amazed me how even though one program in the suggested virus removal programs from the Vista Cleaning Procedure found a malware and the others found additional malware.

    This will be my first of two posts to be able to attach all logs.

    I would like advice, based on the logs, as to whether I should do anything else before attempting the system restore and enable UAC.

    Thanks in advance for the advice and help.

    Much obliged,

    ChAllenged
     

    Attached Files:

  2. Challenged

    Challenged Private E-2

    Vundo Trojan (Part 2)

    Hello everyone,

    this is my second post with the final log.


    Much obliged,

    ChAllenged
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please remember to stay in one thread with all of your posts for this current problem. I merged your two threads together.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [Win2KService] C:\Windows\System32\wbem\MOF\good\mirc.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Challenged

    Challenged Private E-2

    Hi everyone,

    my apologies for not responding sooner - I had 2 infected pc's. For the one listed above, my friend states that it works fine, so I thank you very much for your great guides and suggestions.

    I have a 2nd pc that was contaminated with the same "Vundo" virus :(
    Do I post the logs here as well or in a separate thread?

    Thanks in advance :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should attach the follow up logs so that we can be sure that everything has been properly removed. All it takes is one left over for all the problems to return. Also we have additional final instructions that need to be performed but I cannot give them until the previous requested logs have been attached.

    New PC or new problem on same PC requires a new thread.
     
  6. Challenged

    Challenged Private E-2

    chaslang,

    thanks for the reply. I wish I could give you the follow up logs. I even stated to my friend that I should make sure everything is ok'd by the great staff here, but he was adamant that he wanted it back; although I will inform him of your suggestion and cross my fingers the virus remains dormant.rolleyes
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not just the logs! We were not finished with final cleanup or instructions. That PC was not properly protected and it will get infected again.
     
  8. Challenged

    Challenged Private E-2

    I agree with you, but I can only suggest to my friend to do what you suggested. I hope he does it. :eek:
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's just a matter of time before an unprotected PC will be back looking for help. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds