Vundo-Variant F

Discussion in 'Malware Help (A Specialist Will Reply)' started by jjoepage, Oct 24, 2010.

  1. jjoepage

    jjoepage Private E-2

  2. jjoepage

    jjoepage Private E-2

    This is not a bump! I just posted a minute ago. I just forgot the MGTools log. It is attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't think I am seeing anything vundo related in your logs now except of course the trace that was removed.

    Why are you using this machine without having antivirus installed??

    Java 2 Runtime Environment, SE v1.4.2_19 <--- uninstall this outdated java.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Install some anti virus and run a full system scan.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  4. jjoepage

    jjoepage Private E-2

    OK -
    1) fixed that Java problem; 2) installed and ran PCTools anti-virus; re-ran MGTools - zip attached.

    I am not convinced I am clean. The hard-drive runs nearly continuously. This is not normal as the drive was rather quiet when the computer was new. I was forced to leave the computer on for 2 months while away - and left the Microsoft Update Service off. Shortly after returning, I was browsing and noticed Viral activity. I'd get browser crashing, redirects, and error messages. One error message was: "Warning! Your computer is at risk of Malware attacks. We recommend you to check your system immediately. Press OK to start the process now." - yeah, right. Like I am going to press OK.
    I also got a re-direct and captured the URL. My browser went to 'www1.get-softprotection32.in' 'in' - what kind of TLD is that?

    Sometimes upon booting I see: "GoogleQuickSearchBox.exe The program can't start because MSVCP8.dll is missing" - not really sure what this is about. But I don't like anything which looks like this. Can you please have another look at my logs - maybe we missed something earlier. My hard drive will not settle down. It drives me nuts. Thanks so much. Your expert help is really appreciated.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. jjoepage

    jjoepage Private E-2

    OK - good to be moving forward. While running MGTools, just after TDSSKiller finished, - at the very beginning of MGTools run - an error window popped up. This window said: "SteelWerx WhoAmI application quite running - blah, blah"
    After, MGTools seems to have completed its task OK. TDSSKiller said everything was clean - a log is attached.

    Thanks again.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes... but now you have that and Microsoft Security Essentials installed! One of them must be uninstalled now.

    I am seeing some strange temp files in your temp folders so let's use OTM to clear them.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Commands
    [emptytemp]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run this GMER - running with a random name

    and this -

    Using ESET's Online Scanner

    Let's see what happens from there, because I am not seeing anything that is standing out to me in the logs as being bad.

    I take it you are using Internet Explorer to surf?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. jjoepage

    jjoepage Private E-2

    Wow, that took 3.5 hours to scan with ESET. But maybe it was worth it - it seemed to find things.

    First, PCTools is total garbage - it interupts you over and over with bullshit commercials to buy their crap. If I got one message per week it'd drive me nuts - I got 17 in one hour. Idiots.

    I uninstalled that garbage malware PCTools and after installed Microsoft's anti virus. I understand we are to only have one installed at a time - that is how I am set up now.

    I ran OTM - results attached.

    Ran GMER with random name. log attached (crapola).

    ran Eset - (ouch - long scan). log attached

    I do surf with IE.

    Thanks tons for the help!!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell Kes what issues you may still be having, if any.
     
  10. jjoepage

    jjoepage Private E-2

    When I initiated this box with Windows 7 64bit - it ran great for a long period. Then, one day - without installing anything - i was receiving browser error messages, crashes and redirects. In addition, and more importantly - the drive seems to never quit. Spinning, searching, spinning, scanning, works constantly. I'd like it to stop when nothing is going on. When the machine was new, it stayed off unless I was invoking some process. Now, after relaxing for more than 10 minutes, the disk is still working - on what? I can't tell. It sounds like a scanning is busy scanning files right now - it shouldn't be doing anything.

    Thanks for your help.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still getting browser redirects or not?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Answer my question about the redirecting.

    crapola.log ---> Please refrain from renaming logs.

    Let's run this anyway as there are a couple files I would like to be rid of before giving you final steps.


    Code:
    :files
    C:\Users\Joe\Local Settings\TEMP\uwldypow.sys
    C:\Users\Joe\Local Settings\TEMP\F71A.tmp
    C:\TEMP\dvmexp
    C:\TEMP\dvmexp.idx
    C:\TEMP\tmpdvmexp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. jjoepage

    jjoepage Private E-2

    No - the redirects seem to have stopped pretty early on in our process. I think some of our steps did kill some stuff - because it was very active a few days ago. Now, the browser is behaving normally.

    We might be done. But I am not convinced this drive noise is normal. It could all be in my head - I'll have to have that scanned next.

    Thanks for all the hard work!!! Looking forward to the wrap up steps.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Users\Joe\Desktop\TDSSKiller.exe <--- Delete this now.

    Run Ccleaner (Not the registry section, just the cleaner)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. jjoepage

    jjoepage Private E-2

    OK!!! Million Thanks. Last time I tried to do this alone - I completely killed the machine and had to start all over. Where is the MajorGeeks PayPal donate button - I'd like to empty my paypal account on you guys. Really, I am one major satisfied customer - Thanks tons. You gals/guys are great.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are *most* welcome. :) At the end of each of my posts are two links to "support MajorGeeks"

    Take care and safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds