View Single Post
Old 01-09-2008, 11:22 AM   #6 (permalink)
TheBruce1
Moderator, Analyst, Security Team
 
TheBruce1's Avatar
 
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP


Re: I cannot get rid of Ping.exe - Vundo?

Hello again

Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:

SpywareBot 1.9.0<--This is considered a rogue programme as it exploits "Spybot Search & Destroy" name, same app as AdwareAlert.
http://spywarewarrior.com/rogue_anti...e.htm#products

==================================

Open notepad and copy/paste the text in the quotebox below into it:

Quote:
KillAll::

File::
C:\WINDOWS\mrofinu11.exe.tmp
C:\Documents and Settings\MarkB\Desktop\VirtumundoBeGone.exe
C:\Documents and Settings\MarkB\Local Settings\Temp\nsn6B.tmp


Folder::
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\VundoFix Backups
C:\Program Files\STOPzilla!
C:\Documents and Settings\All Users\Application Data\STOPzilla!
C:\Program Files\Spyware Doctor
C:\WINDOWS\TWFyayBCcmFiYW50

DirLook::
C:\WINDOWS\mobgslti

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2A7AA16-678C-3F59-895A-3CE672845892}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ffe58e9d-4cfe-42ac-b8d1-7c4360891611}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f49fc3c0"=-
Save this as CFscript







Refering to the picture above, drag CFscript into ComboFix.exe

Follow the prompts, and post the resulting log, C:\ComboFix.txt

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

==================================

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

===============================

Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

===============================
Logs Required
C:\Combofix.txt
Kaspersky scan log
Hijackthis log


Can you tell me why you have no Anti-virus programme installed?
__________________
Member of ASAP since 2007
Member of UNITE since 2008


**Notice to BT customers**
BT to dump Phorm, see Here for more information. No DPI

If we have helped you in anyway, please consider Donating
TheBruce1 is offline