Vundo; Infostealer; W32 Spybot

Status
Not open for further replies.
OOOhh ! I haven't actually checked your HJT log (that's why all seems strange)

Here's what you need to do (but I might not continue - info later on, why)

Un-install Trend
Uninstall Norton
Uninstall Bittorent
Run the Norton Removal tool

Re-open HJT and fix all the following (tick then fix all)

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182124299375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/...jc.cab&File=jinstall-6u11-windows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D8FC4FE-7B21-4A21-860E-1D9D6448155E}: NameServer = 207.69.188.185,207.69.188.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{964ED87D-3637-4023-B922-D2DF7B426B2B}: NameServer = 207.69.188.185,207.69.188.186
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

Finally restart

Then

Install Avira free AntiVirus
Run a full scan
Actually if you just install and update Malwarebytes and run that (with Avira installed) that'll be fine

Attach the logs.

Note: I usually never support users with FileSharing programs installed, basically there's no use (in my mind) These programs are the most likely cause of Malware infection, and here's the punch line - re-infection ie I don't help users with this installed.
Your choice to uninstall Bittorent ;)
 
Yes, this was self-inflicted and I learned my lesson - bittorrent goes. Do I have to uninstall Trend to get this cleared up? Digging up my disc to reinstall it and then finding the email where I got a free upgrade to their 2009 security suite will be problematic.
 
Well no.

But I find Trend to be overly slow (back in 2005 and 2006 it was ok - but not now)
So I tried Trend (actually I tried them all ;) )
And found Avira (free) Antivirus to be the best
It's user preference

Therefore some of the above will not be correct !!
 
I'll probably wind up deferring to your expertise, but Trend was awesome in blocking the infection from sending my browser off to the dark nasty corners of the world wide web. As far as preventing the infection in the first place, I clicked on an .exe file and I knew better. No program protects against that kind of stupidity. In any event, I will follow the latest instructions (mostly) and repost. - Thanks
 
I don't have Norton installed so I skipped that step (I've been using the online scanner), but I downloaded and ran the remove Norton tool.

I left Trend installed.

I uninstalled Bittorrent

I fixed everything listed in Hijack except anything notated as Trend.

I downloaded Avira, installed, closed Trend, and ran Malwarebytes. I did the quick scan because previously when I ran it both ways, it picked up the same infections. I am doing a full scan with Avira as I write this.

Malwarebytes found those same two pesky files it keeps finding. I've attached the log.

Norton is the only scanner that's been picking up the Help.exe file - I suspect it's still there too.

What's the next step?

Thanks again for your help on this.
 
Well it would have been ideal if you had updated Malwarebytes first
The entire program is now at a new revision (just using the update button in Malwarebytes will automatically download the new version, and then update the defs)

By the way, once Avira finishes scanning, please remove it
There's no telling what corruption you may get with having more than 1 antivirus installed at the same time (ie what happens when Avira scans Trends quarantine folder :confused: who knows!)
So once Avira is done, please un-install it fully
 
oops. Okay, after the Avira scan (it found two new infections) I uninstalled, restarted, then updated Malwarebytes and rescanned. Both logs are attached. Malwarebytes finally says everything is o-tay.
 
Well done :grinthumb

Clear & Reset System Restore's Cache

Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter

* Tick on the checkbox - Turn off System Restore on all drives
* Click Apply

Turn it back 'On' by unticking the same checkbox & click Apply, and then OK

Re-run CCleaner
Restart
Then let me know how it's presently running (Couldn't be worse! :mad: ; ok :suspiciou ; Fantastic :) )
 
Status
Not open for further replies.
Back