Am I clean? 8 steps performed for vundo and crypt.fkm.gen

Status
Not open for further replies.

dmcrx7

Posts: 42   +0
avira said I had vundo and crypt.fkm.gen trojans.

I have performed the 8 steps.

Am I clean?
 
Vundo hard to get rid of

avira still showed vundo files.
Re-ran mbam.
Here's the log file for mbam and hijack this.
 
The Vundo malware is in the System Restore points. these are protected files so the cleaning programs don't remove it from there. We will drop the old restore points when the cleaning is complete. In the meantime, Do NOT use system Restore as you will reinfect the system.

Have SAS remove the Tracking Cookies. Click on lower left image here to enlarge- shows where to check:
http://superantispyware.en.softonic.com/images

When done:
Reset Cookies:
For Internet Explorer: Internet Options (through Tools or Control Panel) Privacy tab> Advanced button> CHECK 'override automatic Cookie handling'> CHECK 'accept first party Cookies'> CHECK 'Block third party Cookies'> CHECK 'allow per session Cookies'> Apply> OK.
Update Java:
Your version of Java is now outdated. Java vulnerabilities are commonly exploited by viruses so I strongly recommend you update. Click here to download the latest version of java ( Java Runtime Environment (JRE) 6.0 Update 11 ): http://java.com/en/download/manual.jsp
Please install it and then reboot your computer.
Update Adobe:
Your Adobe Reader is out of date. Vulnerabilities can be exploited. Click here to download the latest version v9: https://www.techspot.com/downloads/2083-adobe-reader-dc.html
OR
Install the FoxIt Reader: this does the same thing as Adobe, but doesn’t have the bloat: http://www.foxitsoftware.com/pdf/rd_intro.php
You need to disable Real Time monitoring while cleaning:
Spybot S&D (Teatimer)
1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Please re-open HiJackThis and scan.*Check* the boxes next to all the entries listed below.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.divx.com/divx/webplayerdemo/en?rcv=1&dist=divxdotcom
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O20 - AppInit_DLLs: xzcrxm.dll
O20 - Winlogon Notify: byXQKaYq - byXQKaYq.dll (file missing)
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot into Safe Mode:

1. Control Panel> Add/Remove Programs> UNINSTALL the following:
All Java EXCEPT v6u11
All Adobe Reader EXCEPT v9
2. Start> Run> msconfig> enter> Selective Startup> Startup menu> UNCHECK everything EXCEPT the processes for Avira/AntiVir
Apply> OK> Reboot.

NOTE: you will get a nag message that you can ignore after checking 'don't show this message again.' Stay in Selective Startup.

Run HijackThis again and attach a new log. I may have you run another program after I see the log.
 
update

The cookies had already been removed - apparently the log printed before removal.

I use firefox most of the time, do I need to change cookie settings there?

Java has been updated, I switched to foxit.

I removed Spybot early in the process, leaving only the resident running. (couldn't figure out how to turn it off)
Should I reinstall and let it scan?

Windows unstaller would not run in safe mode, so I had to switch to regular startup to delete the old java and all adobe.


A bit off topic, but for some reason, I do not have a Run option from the start menu on this computer. I just use the msdos shortcut
 
I use firefox most of the time, do I need to change cookie settings there?
Protection in Firefox:
Yes: Tools> Options> Privacy section> CHECK 'accept Cookies'> UNCHECK 'accept third party Cookies.

For Firefox, I highly recommend using AdBlock Plus and the Easy List filters. These will block Domains that you would normally have to put in 'Exceptions' in Cookies:

AdBlock Plus: https://addons.mozilla.org/en-US/firefox/addon/1865
Easy List: http://easylist.adblockplus.org/
Suggest getting all 3 of the Easy List.

To disable the Spybot Resident (Teatimer)
( if you should need to do this in the future)
1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

I do not have a Run option from the start menu on this computer
Right click on Taskbar> Properties> Start tab> Customize> Advanced tab> be sure 'Run command' is checked> OK> Apply> OK
.

I should have warned you about this. Some of the FoxIt downloads have the ask.com toolbar checked- I see you got it, but we need to remove it. It is a known high deliverer of ads and various adware:

Have HijackThis remove these 2 entries:
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
I know the second one says Foxit Toolbar, but the CLSID is for Ask. Please see the information here why you don't want it:
http://www.benedelman.org/spyware/ask-toolbars/

Boot back into Safe Mode after closing HijackThis and clicking on FixChecked:

Look on Startup and UNCHECK anything for either FoxIt OR Ask.
The use Add/Remove Programs to uninstall the Ask entry.

I really hate it when the software makers do this. While users should always look carefully at the download screens, it is easy to miss this.

Otherwise the log appears to be clean. Looks like the 020 entries are gone. How is you system performing? Do you have any indication at all of remaining malware?
 
almost there

OK, firefox is ready

I saw the ask toolbars, but when I unchecked them, it said that some features of foxit would be disabled unless I downloaded it.

nothing showed up in safemode for ask or foxit.

there was one entry that was blank in the first two columns.

Should I reinstall spybot and turn off teatimer in advance settings? I had read where the resident for IE was a good thing to have running.

System is slower than it used to be, but prob about right with avira running. I had been running without any virus protection previously.

mbam seams to have cleaned the vundo from the restore files (A0000155.exe) These were showing up in avira. Now mbam and avira are clean.
Thanks for all your help.
 
FoxIt does not require the ask.com toolbar. That's just a marketing gimmick. Remove ALL entries and references to ask.com.

Go ahead and reinstall Spybot S&D. You can run TeaTimer if you want- it just needs to be turned off when we're doing scans. It offers real Time protections-some have an occasional conflict from that. I left the information for you in case you needed to disable Teatimer in the future. Whether you run it usually is up to you.

Mbam does NOT remove the restore points. It will show 'System Volume' but they are not removed until we drop them. If you would like to do that now you can:
Clear system restore points
* Clear your existing system restore points and establish a new clean restore point:
1. Go to Start > All Programs > Accessories > System Tools > System Restore
2. Select Create a restore point, and OK it.
3. Next, go to Start > Run and type in cleanmgr
4. Select the More options tab
5.Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.
I should have caught these last night. I'm sorry- I was tired. These autoruns need to be stopped and removed:
Please open Autoruns and remove entries for the following processes. Once the entries have been removed, reopen HijackThis and check the following:
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'LOCAL SERVICE')>>Searchcentrix hijacker
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')
O4 - HKUS\S-1-5-19\..\Run: [vawaluzolu] Rundll32.exe "C:\WINDOWS\system32\hujinuya.dll",s (User 'LOCAL SERVICE')

Also, I suggest you take these off of startup:
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\msconfig.exe /auto>>Not Required at Startup - Microsoft Office Application Launcher- do not need to start on boot.
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe">> does not need to start on boot
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control http://www.onlinegis.net/download/MgViewer6.0CAB/mgaxctrl.cab >>>> Autodesk MapGuide

Please see this information regarding the vulnerability of this CLSID: http://securitytracker.com/alerts
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://mail.cmicompany.com/dwa7W.cab>>>
Lotus Domino Web Access for Web access to email and collaboration
/2007/Dec/1019138.html

This should not be enabled unless you are actively using or giving remote support. It can b a security issue:
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
Related to LogMeIn LogMeIn Rescue is used by IT helpdesks to provide instant remote support to customers and employees.

When done, close all Windows except HijackThis, click on Fix Checked and reboot into Safe Mode:
Start> Run> msconfig> enter> Selective Startup> Startup tab> UNCHECK entries for any of the following:
LogMeIn
Sidebar
Microsoft Office Application Launcher.
RocketDock
Right click on Start> Explore> Windows> System 32> right click> delete of any of the following if found:
hujinuya.dll
xzcrxm.dll
byXQKaYq.dll
Reboot into Normal Mode. You will get a nag message you can ignore after checking 'don't show this message again.' Stay in Selective Startup.

I would like you to run one more HijackThis scan and make sure we have handled the autoruns. If clean, we'll remove the cleaning tools,
 
Update

restore points set and removed.

removed all 04's requested except rocketdock, I kinda like it, is it a vulnerability?

domino is used for my work email, removed it, guess I have to click no on the dialog box that pops up?

Logmeln is used to access a work computer. Can this be set up intermittently and shut off? Is this a vulnerability?

the dll's were already gone from system32.
No references to the removed 04's showed up in msconfig
 
Also noticed java/jre6/bin/jusched in msconfig startup.
This is the Java updater and should be turned off. Every time we do anything with Java, it puts itself back on Startup:

Control Panel> Java> Update tab> UNCHECK 'check automatically check for updates'> OK> Answer Yes when asked if you're sure.

You still show Teatimer running. You said you uninstalled Spybot S&D and I then-again- told you how to disable it, but it's still running:
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Please refer to either of my previous two posts giving directions to disable teatimer.

You still have one process that needs to be stopped in Autoruns:
O4 - HKUS\S-1-5-20\..\Run: [vawaluzolu] Rundll32.exe "C:\WINDOWS\system32\hujinuya.dll",s (User 'NETWORK SERVICE')

The names "vawaluzolu" and "hujinuya" smack of malware and cannot be identified.

Please re-read my comment about Logmein and Domino.

If you go back and read my suggestions in Post #7, you will see that I recommended you take some programs off of Startup. RocketDock was one of them. It does not mean you can't use it- it means you launch it manually when you do want to use it instead of having it start on boot and run in the background.

I also recommend you take ALL of the HP processes off of Startup. Printers, Cameras and Open Office do NOT need to start on boot. When they do, they continue to run in the background. This uses resources that are better applied elsewhere. The can be started manually when needed.

The ONLY processes that need to start on boot are the antivirus, firewall and touchpad if on laptop. Everything else can be called up and started manually when needed,
 
You still show Teatimer running. You said you uninstalled Spybot S&D and I then-again- told you how to disable it, but it's still running:

Quote:
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Please refer to either of my previous two posts giving directions to disable teatimer.

You still have one process that needs to be stopped in Autoruns:
O4 - HKUS\S-1-5-20\..\Run: [vawaluzolu] Rundll32.exe "C:\WINDOWS\system32\hujinuya.dll",s (User 'NETWORK SERVICE')

The names "vawaluzolu" and "hujinuya" smack of malware and cannot be identified.

I'll remove these, and the HP related startups. I guess Spybot only partially uninstalled, so I couldn't start it to follow your instructions. I'll reinstall and disable teatimer.Can I remove superspyware to see if it speeds things up a bit?


I'm still confused about domino and logmein. I can't get to the domino link unless I subscride to securitytracker, and I couldn't find much with a google search. It'll take a couple days to activate a free trial with them.
I think you're saying to only activate when needed, but I don't know how to keep them from popping up in startup again.
 
My apology about referring you to the Security tracker. I though the site had the patch for Domino. I missed that you had to register and ultimately purchase.
Leave Domino running, but check their homesite and see if there is any patch or update for Domino Web Access 7 Control.

Do you really need the program "LogMeIn". It uses up a lot of resources and requires total accessibility to the net. If not I recommend you uninstall it through Add/Remove programs, then DELETE the folder using Windows Explorer and Reboot

When finished, run one more HijackThis l and attach log..
 
update

I think I got it. This is the second time I have removed
O4 - HKUS\S-1-5-20\..\Run: [vawaluzolu] Rundll32.exe "C:\WINDOWS\system32\hujinuya.dll",s (User 'NETWORK SERVICE'

hujinuya .dll was removed the first time and has not returned to the C:\WINDOWS\system32 directory.

I did a search of the c drive and found it here:
C:/documents and settings/all users/application data/Spybot - Search and Destroy/Recovery/Virtumondeprx.zip

I don't see logmein in hijackthis, add/remove programs, or a c: search anymore.

Can I keep windows messenger from running at startup, or do I need it for something?
 
Okay, looking good! You should set up a homepage though so I can make sure it's not getting redirected.

Messenger:
Can I keep windows messenger from running at startup, or do I need it for something?
You sure can. UNCHECK is on the Startup menu using Start> Run> msconfig> enter> Selective Startup> Startup tab.

It tends to be a bit pushy sometimes, so if you don't use it, do this in addition to unchecking on Startup:
Right click on Start> Explore> Programs> Right click on Messenger> Rename> add old to the end, like this: messengerold.

And yet one more setting for this beast:
In Outlook Express: Tools> Options> General tab> UNCHECK 'automatically log on to Windows Messenger> Apply> OK

You can UNCHECK all of these on Startup: The ARE legitimate programs, but they don't need to start on boot
You don't need to remove these entries> just UNCHECK on the Startup menu. I've given you a description and none need to start on boot:
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
SiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
Java:
The Java updater is still running. you can see it as 'jusched' in the Task Manager:
Control Panel> Java> Update tab> UNCHECK 'automatically check for updates'> answer Yes when asked if you're sure.
Adobe:
Since you fired Adobe, let's disable the Service:
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Start> Run> services.msc> right click on Adobe LM Service> Properties> Change Startup type to Disabled.
When you have finished the above, reboot the computer. You will get a nag message that you can ignore and close after checking 'don't show this message again'. Stay in Selective Startup/

We can remove the cleaning programs:
Download OTCleanIt
http://download.bleepingcomputer.com.../OTCleanIt.exe
* Click the CleanUp! button.
* It will go thorough the list and remove all of the tools it finds and then delete itself (requiring a reboot).
The Restore Points should be remove again since you had a few malware entries when you did the removal: Clear your existing System Restore points and establish a new clean restore point:
:
Go to Start > All Programs > Accessories > System Tools > System Restore> Select Create a restore point> OK.
* Next, go to Start > Run and type in cleanmgr
"Ensure the selection is on C:\ and click on OK"-
* Select the *More options* tab
* Choose the option to clean up System Restore and OK it.
* This will remove all restore points except the new one you just created.

It's been a pleasure working with you. If you need more help, please let us know.
 
I think that got it. Thanks for all your help.

On last question: Do you know what this is? looked suspicious to me

O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
 
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')]

You had one or two entries which I had you remove. But these are legitimate entries which I though you had put in place. Read the description and check the URL I leave. If you no longer want this to run, we should be able to stop it- I'll check it out so let me know.

Here is the description of nLite:
Have you ever wanted to remove Windows components like Media Player, Internet Explorer, Outlook Express, MSN Explorer, Messenger...How about not even to install them with Windows ?

nLite is a tool for pre-installation Windows configuration and component removal at your choice. Optional bootable image ready for burning on media or testing in virtual machines.
With nLite you will be able to have Windows installation which on install does not include, or even contain on media, the unwanted components.

See nLite - Windows Installation Customizer http://www.nliteos.com/nlite.html
And check out the FAQ page: http://www.nliteos.com/faq.html

advpack.dll assists with hardware and software installs by reading and verifying .INF files.
 
Status
Not open for further replies.
Back