lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


 Default 

Whatever I do I can't get rid of TROJAN.VUNDO.H




Reply
 
Thread Tools
  #21  
Old 20th Oct 2008, 21:50
Moderator Group
 
Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O2 - BHO: (no name) - {D6EEB0C3-825E-4FBC-BE0F-38CD08E932FE} - c:\windows\system32\digestp.dll
O20 - Winlogon Notify: paubftzz - C:\WINDOWS\SYSTEM32\digestp.dll


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download OTMoveIt2 by OldTimer and save it to your Desktop.

Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

1. Double-click OTMoveIt2.exe to run it.
2. Copy the lines in the codebox below.

Code:
[kill explorer]
C:\WINDOWS\LMI42.tmp
C:\WINDOWS\SYSTEM32\digestp.dll
HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6EEB0C3-825E-4FBC-BE0F-38CD08E932FE}
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\paubftzz
EmptyTemp
[start explorer]
3. Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
4. Click the red Moveit! button.
5. Copy everything in the Results window (under the green bar) and paste it in your next reply.
6. Close OTMoveIt2

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

----------

After posting the OTMoveIt2 log.

Run the Kaspersky Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.

When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
__________________

  #22  
Old 3rd Nov 2008, 10:34
Member Group
 
I was sick and I am hopeful to resolve this problem today if you can.

When I ran the OTMoveIt2 by Old Timer I executed and received the dialog box with the following

"The application or dll c:\windows\system32\rakxhfy.dll is not a valid widnows image. Please check this against the installation diskette."

Then I copied the right plain as the log file pasted below

Explorer killed successfully
C:\WINDOWS\LMI42.tmp moved successfully.
LoadLibrary failed for C:\WINDOWS\SYSTEM32\digestp.dll
C:\WINDOWS\SYSTEM32\digestp.dll NOT unregistered.
File move failed. C:\WINDOWS\SYSTEM32\digestp.dll scheduled to be moved on reboot.
< HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6EEB0C3-825E-4FBC-BE0F-38CD08E932FE} >
Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6EEB0C3-825E-4FBC-BE0F-38CD08E932FE}\\ not found.
< HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\paubftzz >
Unable to delete registry key HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\paubftzz\\ .
< EmptyTemp >
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFBA5D.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JET8ED2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6f0.dat scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 11032008_122254

I am now going to reboot and run Kasper virus program
  #23  
Old 3rd Nov 2008, 13:09
Member Group
 
Kaspersky Antivirus had no threats. I have CROSSLOOP and it said there are 2 non virus files for Crossloop. Crossloop is a free remote management proagram. Waiting for next instructions.

Thanks
  #24  
Old 3rd Nov 2008, 13:27
Moderator Group
 
Sounds good. CrossLoop works in a way that some antivirus will see as suspicious so no big deal.

1. Double click OTMoveIt3.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
  • When finished exit out of OTMoveIt3

----------

Disable the System Restore Utility to prevent re-infection from an old one

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
Out of date software has security vulnerabilities that malware can exploit.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself safe On The Web for tips and free tools to keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
__________________

  #25  
Old 3rd Nov 2008, 18:07
Member Group
 
OK - I ma going to leave and be at the computer in over an hour. I will run what you said but where do I find the OTMoveIt3.exe program? There is no link to Bleepingcomputer.com. Are we close to solving the VUNDOH after all these steps are followed?

Thanks

James

ON my way please watch for me with results. I have to go back to work tomorrow and would like to resolve tonight.

Again thanks
  #26  
Old 3rd Nov 2008, 18:10
Moderator Group
 
Those are the final steps.

Run this in place of OTMoveIt3.

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
__________________

Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.