Vundo variant - XP Police

Discussion in 'Malware Help (A Specialist Will Reply)' started by bcbrian, Feb 17, 2009.

  1. bcbrian

    bcbrian Private E-2

    Running 2 pc home network - my laptop and teenaged daughter's desktop. The only problem I've noticed on the laptop is network connection loss at times which I believe may only have been fault of infected desktop. We've had Trend Micro Internet Security running until end of 2008. There was a problem last year with the desktop: IE was opening up multiple tabs at random times when she would close out of MySpace. I don't know whether she had allowed an install through the antivirus/spyware or not but I had run manual scans and the problem had still returned. I had deleted temp internet files and temp folders (I doubt I found them all) through safe mode and had Trend Micro tech support analyze HJT log and was told it was clean. There was one repeat around the end of last year.
    I decided to search other options for security software and had not been available to do it timely. The subscription expired in December and I had only assumed that the desktop would run the same as the laptop: With security software still operational, albeit unable to update for a few weeks. Unfortunately, it was completely disabled on the desktop without me knowing it. It was the network disconnects that had me check out the desktop and realize the problem. Google searches were redirecting to similar sites with 'Star Search' titles and there was a repeating security center pop up insisting that I needed to allow MSAntispyware be enabled to remove found threats.
    I had used the 10 software procedures listed in 'Gizmos' site and decided to sign up here for the support forum. The procedures here were not the same and quite specific and time consuming, but I believe it sounded perfectly worthwhile and sensible so I disregarded my other work and followed your Malware Removal Guide in order. I have noticed no malware recognition since finishing up the scans recommended from Gizmos (I believe Bitdefender Online was the last to detect and clean). How much malware was one and the same I am not sure but there were references to a vundo variant and XP Police. Nevertheless, I have gone through your procedures and am attaching logs in these two posts. I realize computers can appear to be clean when they are not. One thing I noticed right now is that a user account seems to be deleted while there still is reference to it when scans listed cookies.
    The only thing I added to the list of tasks was required for combofix to run: It was caused by a windows wmi error which believed McAfee was running. (I don't believe it was ever installed on this computer but could have been offered from another program). Through a command prompt, I shut down wmi service and renamed the repository folder before restarting the pc and the service to allow it to be rebuilt. It worked after repeating the procedure and combofix no longer gave the antivirus warning, and security center no longer shows a false McAfee presence. I also uninstalled Trend Micro before starting any cleaning although it still shows up in control panel and I have not yet been successful deleting the folder with a access restricted dll. (I can deal with that later). After completing your guide, I did install Avira to keep a running antivirus although it won't show on these logs. Please let me know if the logs suggest anything wrong.
     

    Attached Files:

  2. bcbrian

    bcbrian Private E-2

    for the mgtools log
    They all seem clean to me in contrast to the first time (superantispyware and malwarebytes I had used before finding your malware removal guide). I can send you those first time logs if you wish, but these logs are immediately after following your guide.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Any remaining issues would best be addressed in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds