Keep getting Winfixer Popups and finding Virtumondo or Virtumudo when running spyware. Cannot remove Virtumondo/mundo when running spyware.
The following is my log. I would appreciate any feedback to remove these HIJACK programs.
Cal-Tex
Logfile of HijackThis v1.99.1
Scan saved at 3:59:46 PM, on 11/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\DOCUME~1\Dick\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
When you do so, either HJT will not create its log files and backup files; or if it does, you risk losing them when the TEMP's cache is cleared. It's important that you save these backup files, in case you have to "undo" [restore] some of the things you "FIX" incorrectly.
So you need to move HJT into a separate, non-temporary, non-Desktop, directory of its own. We recommend using the directory C:\HJT , so that it will then appear in your log, under running processes, as C:\HJT\HiJackThis.exe
Note: If you have previously download this file on another occasion, please download it again, to be absolutely sure you have the most current version.
* Save it to your Desktop * Close all running programs (including your Internet Browser) * Double-click VirtumundoBeGone.exe on the desktop * Follow the directions as indicated
please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.
just reboot if your system "jams"
*********************
you actually have TWO vundo/virtumundo infections.
REBOOT. run VirtumundoBeGone a second time. REBOOT.
**************************
After rebooting, it's now time to run FixVundo (which you had downloaded earlier).
Make sure all other programs, including your Internet Browser, are closed.
Double-click the FixVundo.exefile to start the removal tool.
Click Start to begin the process, and then allow this tool to run.
Important: Do not launch any new applications while the tool is running!
Reboot your computer.
Run the FixVundo removal tool again to ensure that the system is clean.
*********************
It's now time to report back to us:
VirtumundoBeGone generated a "log" file of its own, which it should have placed on your Desktop... please REPLY to this thread, and copy/paste the VirtumundoBeGone log back here, along with your latest HJT log.
Ok, it appears that the vmundo fix worked. However, I'm not sure about WinFixer. Both the VBG and HJT logs are pasted below following the repair action.
[11/21/2005, 0:38:47] - Starting Process... [11/21/2005, 0:38:47] - Looking for Browser Helper Object [MSEvents Object] [11/21/2005, 0:38:47] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class [11/21/2005, 0:38:47] - 2: {53707962-6F74-2D53-2644-206D7942484F} - [11/21/2005, 0:38:47] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank. [11/21/2005, 0:38:47] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll) [11/21/2005, 0:38:47] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}. [11/21/2005, 0:38:47] - 3: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess [11/21/2005, 0:38:47] - 4: {8DBF02DA-4360-4A7E-BEA1-347B87816327} - MSEvents Object [11/21/2005, 0:38:47] - Found MSEvents Object! [11/21/2005, 0:38:47] - File location: C:\WINDOWS\system32\ddabx.dll [11/21/2005, 0:38:47] - Attempting to kill C:\WINDOWS\system32\ddabx.dll [11/21/2005, 0:38:47] - Terminating Process: RUNDLL32.EXE [11/21/2005, 0:38:47] - Terminating Process: IEXPLORE.EXE [11/21/2005, 0:38:48] - Disabling Automatic Shell Restart [11/21/2005, 0:38:48] - Terminating Process: EXPLORER.EXE [11/21/2005, 0:38:48] - Suspending the NT Session Manager System Service [11/21/2005, 0:38:48] - Terminating Windows NT Logon/Logoff Manager [11/21/2005, 0:38:48] - Re-enabling Automatic Shell Restart [11/21/2005, 0:38:49] - Renaming C:\WINDOWS\system32\ddabx.dll -> C:\WINDOWS\system32\ddabx.dll.vir [11/21/2005, 0:38:49] - File successfully renamed! [11/21/2005, 0:38:49] - Removing Registry references to {8DBF02DA-4360-4A7E-BEA1-347B87816327} [11/21/2005, 0:38:49] - Adding Internet Explorer Protection (Kill ActiveX) for {8DBF02DA-4360-4A7E-BEA1-347B87816327} [11/21/2005, 0:38:49] - Removing Winlogon Notify Entry: ddabx [11/21/2005, 0:38:49] - BHO list has been changed! Starting over... [11/21/2005, 0:38:49] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class [11/21/2005, 0:38:49] - 2: {53707962-6F74-2D53-2644-206D7942484F} - [11/21/2005, 0:38:49] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank. [11/21/2005, 0:38:49] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll) [11/21/2005, 0:38:49] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}. [11/21/2005, 0:38:49] - 3: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess [11/21/2005, 0:38:49] - 4: {AE7CD045-E861-484f-8273-0445EE161910} - AcroIEToolbarHelper Class [11/21/2005, 0:38:49] - Finished searching for [MSEvents Object] [11/21/2005, 0:38:49] - Finishing up... [11/21/2005, 0:38:49] - Enabling Automatic Reboot on STOP Error. [11/21/2005, 0:38:49] - Attempting to Restart via STOP error (Blue Screen!)
[11/21/2005, 0:42:17] - Starting Process... [11/21/2005, 0:42:17] - Looking for Browser Helper Object [MSEvents Object] [11/21/2005, 0:42:17] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class [11/21/2005, 0:42:17] - 2: {53707962-6F74-2D53-2644-206D7942484F} - [11/21/2005, 0:42:17] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank. [11/21/2005, 0:42:17] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll) [11/21/2005, 0:42:17] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}. [11/21/2005, 0:42:17] - 3: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess [11/21/2005, 0:42:17] - 4: {8DBF02DA-4360-4A7E-BEA1-347B87816327} - MSEvents Object [11/21/2005, 0:42:17] - Found MSEvents Object! [11/21/2005, 0:42:17] - File location: C:\WINDOWS\system32\ddccy.dll [11/21/2005, 0:42:17] - Attempting to kill C:\WINDOWS\system32\ddccy.dll [11/21/2005, 0:42:17] - Terminating Process: RUNDLL32.EXE [11/21/2005, 0:42:17] - Terminating Process: IEXPLORE.EXE [11/21/2005, 0:42:17] - Disabling Automatic Shell Restart [11/21/2005, 0:42:17] - Terminating Process: EXPLORER.EXE [11/21/2005, 0:42:17] - Suspending the NT Session Manager System Service [11/21/2005, 0:42:18] - Terminating Windows NT Logon/Logoff Manager [11/21/2005, 0:42:18] - Re-enabling Automatic Shell Restart [11/21/2005, 0:42:18] - Renaming C:\WINDOWS\system32\ddccy.dll -> C:\WINDOWS\system32\ddccy.dll.vir [11/21/2005, 0:42:18] - File successfully renamed! [11/21/2005, 0:42:18] - Removing Registry references to {8DBF02DA-4360-4A7E-BEA1-347B87816327} [11/21/2005, 0:42:18] - Adding Internet Explorer Protection (Kill ActiveX) for {8DBF02DA-4360-4A7E-BEA1-347B87816327} [11/21/2005, 0:42:18] - Removing Winlogon Notify Entry: ddccy [11/21/2005, 0:42:18] - BHO list has been changed! Starting over... [11/21/2005, 0:42:18] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class [11/21/2005, 0:42:18] - 2: {53707962-6F74-2D53-2644-206D7942484F} - [11/21/2005, 0:42:18] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank. [11/21/2005, 0:42:18] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll) [11/21/2005, 0:42:18] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}. [11/21/2005, 0:42:18] - 3: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess [11/21/2005, 0:42:18] - 4: {AE7CD045-E861-484f-8273-0445EE161910} - AcroIEToolbarHelper Class [11/21/2005, 0:42:18] - Finished searching for [MSEvents Object] [11/21/2005, 0:42:18] - Finishing up... [11/21/2005, 0:42:18] - Enabling Automatic Reboot on STOP Error. [11/21/2005, 0:42:18] - Attempting to Restart via STOP error (Blue Screen!)
[11/21/2005, 1:07:16] - Starting Process... [11/21/2005, 1:07:16] - Looking for Browser Helper Object [MSEvents Object] [11/21/2005, 1:07:16] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class [11/21/2005, 1:07:16] - 2: {53707962-6F74-2D53-2644-206D7942484F} - [11/21/2005, 1:07:16] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank. [11/21/2005, 1:07:16] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll) [11/21/2005, 1:07:16] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}. [11/21/2005, 1:07:16] - 3: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess [11/21/2005, 1:07:16] - 4: {AE7CD045-E861-484f-8273-0445EE161910} - AcroIEToolbarHelper Class [11/21/2005, 1:07:16] - Finished searching for [MSEvents Object] [11/21/2005, 1:07:16] - Nothing found! Exiting.
Logfile of HijackThis v1.99.1 Scan saved at 1:41:20 AM, on 11/21/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Nice work. Looks like VirtumundoBeGone successfully deactivated both bad WinFixer/Vundo files. I saw where you wrote " However, I'm not sure about WinFixer. " Does that mean, you want to wait a bit to be sure? or does it mean you're still getting (specifically) WinFixer popups?
If you're getting other popups, that's a separate matter yet to be addressed... in fact, at this point, I'm gonna try to ask someone else to step-in, to determine additional problems (if any) that you might have. Please be advised that we're very "understaffed" at the moment, so I can't make any guarantee as to when (or even if) the next helper will arrive.
Thanks for the help. I havn't gotten any winfixer popups yet since the fix action. I wasn't aware that Winfixer & Vmundo were the same. I thought I had 2 different problems.
actually, they are different. WinFIxer comes in many different types/variations... but the most common form is the V-mundo trojan... so in these cases, it turns out to be the same.
Log looks OK. If the popups have stopped then it's probably OK.
Ron
Make sure you have System Restore running (toggle it off and On today to get rid of any bad stuff it may have retained)
and then you can just go back to an earlier time if you hit a bad site.
One way to make this more obvious is to check everything in your current HijackThis and Add to Ignore List then set up Hijackthis to run at boot and to show you if it finds anything new.
ky331
5 Journeyman
•
15621 Posts
•
45046 Points
308
0
Posted November 20th, 2005 11:00
First: You're running HJT from a TEMP directory:
C:\DOCUME~1\Dick\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
When you do so, either HJT will not create its log files and backup files; or if it does, you risk losing them when the TEMP's cache is cleared. It's important that you save these backup files, in case you have to "undo" [restore] some of the things you "FIX" incorrectly.
So you need to move HJT into a separate, non-temporary, non-Desktop, directory of its own. We recommend using the directory C:\HJT , so that it will then appear in your log, under running processes, as C:\HJT\HiJackThis.exe
*************************
Download [but do *NOT* yet run] FixVundo from
http://securityresponse.symantec.com/avcenter/FixVundo.exe
[we'll have you run it later]
Note: If you have previously download this file on another occasion, please download it again, to be absolutely sure you have the most current version.
********************
Next, download VirtumundoBeGone from:
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
* Save it to your Desktop
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Follow the directions as indicated
please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.
just reboot if your system "jams"*********************
you actually have TWO vundo/virtumundo infections.
REBOOT. run VirtumundoBeGone a second time. REBOOT.
**************************
After rebooting, it's now time to run FixVundo (which you had downloaded earlier).
Make sure all other programs, including your Internet Browser, are closed.
Double-click the FixVundo.exe file to start the removal tool.
Click Start to begin the process, and then allow this tool to run.
Important: Do not launch any new applications while the tool is running!
Reboot your computer.
Run the FixVundo removal tool again to ensure that the system is clean.
*********************
It's now time to report back to us:
VirtumundoBeGone generated a "log" file of its own, which it should have placed on your Desktop... please REPLY to this thread, and copy/paste the VirtumundoBeGone log back here, along with your latest HJT log.