UNSOLVED

1oldman

updated

20 years ago

1

1oldman

6 Posts

0

516

March 23rd, 2006 19:00

WINFIXER

I have a machine that got the WINFIXER pest. I used the VundoFix per instructions I saw on other posts. I am attaching the VundoFix.txt log and the Highjack This log that I ran after running VundoFix. I am interested to know if I'm clean.
 
 

VundoFix V4.2.35
Checking Java version...
Scan started at 2:27:10 PM 3/22/2006
Listing files found while scanning....
C:\WINDOWS\system32\mljjg.dll
C:\WINDOWS\system32\gjjlm.ini
C:\WINDOWS\system32\gjjlm.bak1
C:\WINDOWS\system32\gjjlm.bak2
C:\WINDOWS\system32\gjjlm.bak1
C:\WINDOWS\system32\gjjlm.bak2
C:\WINDOWS\system32\gjjlm.ini
C:\WINDOWS\system32\mljjg.dll
 Attempting to delete C:\WINDOWS\system32\mljjg.dll
C:\WINDOWS\system32\mljjg.dll Has been deleted!
 Attempting to delete C:\WINDOWS\system32\gjjlm.ini
C:\WINDOWS\system32\gjjlm.ini Has been deleted!
 Attempting to delete C:\WINDOWS\system32\gjjlm.bak1
C:\WINDOWS\system32\gjjlm.bak1 Has been deleted!
 Attempting to delete C:\WINDOWS\system32\gjjlm.bak2
C:\WINDOWS\system32\gjjlm.bak2 Has been deleted!
Performing Repairs to the registry.
Done!
 
 
Logfile of HijackThis v1.99.1
Scan saved at 9:52:19 AM, on 3/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.jhnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = officemain:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HPRestartApp] C:\Program Files\Hewlett-Packard\LJ4200\applch.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.jhnet.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130175938152
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130444031593
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.aviptax.com/tsweb/msrdp.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
 
 
Thanks
  • ALgal

    1188 Posts

    273

    0

    Posted March 24th, 2006 11:00

    Hello 1oldman and Welcome to the Dell forum,

    Your hijackthis log appears to be clean. But I would like to see a scan just to double-check that everything is alright.
    Now run this online scan using Internet Explorer:
    Kaspersky WebScanner from http://www.kaspersky.com/virusscanner

    Next Click on Launch Kaspersky Anti-Virus Web Scanner

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.

    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Standard
    • Scan Options:
    • Scan Archives
    • Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
    • Select My Computer
    • This will program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
    • Save the file to your desktop.

    Copy and paste that information from Kapersky in your next post.
  • 1oldman

    6 Posts

    273

    0

    Posted March 24th, 2006 15:00

    Here are the results of the scan by Kaspersky on-line anti-virus scanner. As a side note Norton product is no longer loaded on this machine. I am using a different product now.

     

     

     

    -------------------------------------------------------------------------------
     KASPERSKY ON-LINE SCANNER REPORT
     Friday, March 24, 2006 11:16:19 AM
     Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
     Kaspersky On-line Scanner version: 5.0.78.0
     Kaspersky Anti-Virus database last update: 24/03/2006
     Kaspersky Anti-Virus database records: 172738
    -------------------------------------------------------------------------------
    Scan Settings:
     Scan using the following antivirus database: standard
     Scan Archives: true
     Scan Mail Bases: true
    Scan Target - My Computer:
     A:\
     C:\
     D:\
    Scan Statistics:
     Total number of scanned objects: 43648
     Number of viruses found: 1
     Number of infected objects: 51
     Number of suspicious objects: 0
     Duration of the scan process: 00:52:47
    Infected Object Name / Virus Name / Last Action
    C:\Program Files\Norton AntiVirus\Quarantine\200E54D2.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\2AD324C1.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\41F31CBF.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\44BE56F3.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\4A705686.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\5B7958E9.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\66A31EE0.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\670914E8.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\676F0AEF.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\69233751.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\709B02C1.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\77A91EFD.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C2361AB.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C2935A3.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C30099C.Exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C365D95.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C3A0791.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C3D318E.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C430587.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C472F83.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C4A5980.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C4D037C.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C512D78.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C545775.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C570171.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C5A2B6E.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C747B51.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C78254D.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7C7E7946.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CC36AFB.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CC93EF3.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CCD68F0.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CD012EC.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CD33CE9.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CD666E5.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CDA10E1.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CE064DA.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CE30ED7.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CE738D3.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CF136C8.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CF72ACE.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7CFE5EBA.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D0108B6.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D0432B3.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D115AA4.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D1404A1.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D182E9D.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D1B589A.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D1E0296.exe Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7D597655.EXE Infected: Virus.Win32.Tenga.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7E9002EC.exe Infected: Virus.Win32.Tenga.a skipped
    Scan process completed.
  • ALgal

    1188 Posts

    273

    0

    Posted March 24th, 2006 20:00

    Hello 1oldman,

    Your logs appear to be clean. Please do the following:
    STEP 1.
    ======
    Cleanmgr
    To clean temporary files:

    • Go > start > run and type cleanmgr and click OK
    • Scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files and Recycle Bin are the only things checked.
    • Click OK to remove those files.
    • Click Yes to confirm deletion.


    STEP 2.( Windows XP only)
    ======
    Prefetch Folder
    Open C:\Windows\Prefetch\
    Delete All files in this folder but not the Prefetch folder

    STEP 3.
    ======
    System Restore for Windows XP
    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

    • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.

    Reboot.

    Turn ON System Restore.

    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.



    STEP 4.
    ======
    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:


    • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


    • Test your Firewall - Please test your firewall and make sure it is working properly.
      Test Firewall


    • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


    • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
      A tutorial on installing & using this product can be found here:
      Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers


    • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
      A tutorial on installing & using this product can be found here:
      Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer


    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
      A tutorial on installing & using this product can be found here:
      Using SpywareBlaster to protect your computer from Spyware and Malware

    • Update your Java to the latest version. Uninstall any and all versions you have listed in add/remove programs and install the latest version from here: http://www.java.com/en/


    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

    • More info on how to prevent malware you can also find here (By Tony Klein)
      and here: http://wiki.castlecops.com/Malware_Prevent...nt_Re-infection



    Follow this list and your potential for being infected again will reduce dramatically.

    Thank you for allowing me to assist you.

    Susan
  • 1oldman

    6 Posts

    273

    0

    Posted March 29th, 2006 17:00

    I am in the process of folling your suggestions. Thanks for the help.:smileyvery-happy:
     
    Dick