View Single Post
Old 01-21-2008, 10:13 AM   #7 (permalink)
alba
Analyst, Security Team
 
alba's Avatar
 
Join Date: Feb 2005
Location: Eire
Posts: 2,006
OS: Vista, Ubuntu 8.04


Re: Trojan.Vundo found, occasional pop-ups

Hi ejr5033

Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding. Please ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.


IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.


You should delete this C:\Documents and Settings\Eric Reese\Desktop\Desktop Folders\Things I use\wpe_pro_undectable_326
folder because of these findings with your Panda Scan
Quote:
Originally Posted by Panda Scan
Hacktool:Sniffer/WpePro Not disinfected C:\Documents and Settings\Eric Reese\Desktop\Desktop Folders\Things I use\wpe_pro_undectable_326\WpeSpy.dll
Hacktool:Sniffer/WpePro Not disinfected C:\Documents and Settings\Eric Reese\Desktop\Desktop Folders\Things I use\wpe_pro_undectable_326\WPE_PRO.exe
Hacktool:Sniffer/WpePro Not disinfected C:\Documents and Settings\Eric Reese\Desktop\Desktop Folders\Things I use\wpe_pro_undectable_326\wpe_pro_undectable_326.zip[WPE_PRO.exe]
Hacktool:Sniffer/WpePro Not disinfected C:\Documents and Settings\Eric Reese\Desktop\Desktop Folders\Things I use\wpe_pro_undectable_326\wpe_pro_undectable_326.zip[WpeSpy.dll]


===============================================

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

===============================================

Open notepad and carefully copy/paste all the text in the code box below into it:


Code:
File::
C:\WINDOWS\system32\fgdmkprr.ini
C:\WINDOWS\system32\drivers\qmpjayhdebjt.sys
C:\WINDOWS\system32\ssttr.dll_tobedeleted_old
C:\WINDOWS\system32\sstts.dll_tobedeleted_old
C:\WINDOWS\IFinst27.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE3C68DE-CB59-4921-8C79-0E828DAAFE3B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D785E699-0B52-41EB-954C-0C5AE809A6B8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFF29BE4-24AC-4E31-B99B-45238B764111}]
Save this as CFScript.txt




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

========================================

I see you have Ccleaner installed

1. Open the program and the "Cleaner" button should be active. (update if required)
2. Click on "Run Cleaner"
3. Once thats done it will clean out the TEMP folder.
4. Click on Applications tab and Click on "Run Cleaner"
5. Now click on "Registry" and then "Scan for Issues"
6. Once it's done checkmark ALL it finds and click "Fix Selected Issues"
7. It will ask you if you want to back up the registry entrys it's removing so please do so. If it removes anything important..just locate the .reg file you saved...double click on it to add the entrys back.

Close the program

=========================

ESET Online Scanner
Please go to the following link ESET Online Scanner Link
Tick the box YES, I accept the Terms Of Use
Click the Start button
Now click the Install button
Click Start

The scanner engine will initialise and update
Do Not tick the box Remove found threats
Click the Scan button

The scan will now run, please be patient
When the scan finishes click the Details tab
Copy and paste the contents of the %ProgramFiles%\EsetOnlineScanner\log.txt back here.

===========================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.

===============================================

From Control Panel->Add/Remove Programs, uninstall the following programs, if present, :
  • J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

=================

Please reboot your computer

Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.


=================

Please Run a scan with HiJackThis and save the log

=================

In your next post, please include fresh logs from:
  • ComboFix.txt
  • %ProgramFiles%\EsetOnlineScanner\log.txt
  • HiJackThis
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now
__________________


Member of UNITE

If I have helped you in anyway, please DONATE to TSF Go raibh maith agat
alba is offline