NEWS: Naratriptan Corp loan student Mesoridazine First time home buyer home loan Danaparoid Credit card debt consolidation Loan personal credit credit repair report Free Ringtones For Samsung Phone fix credit score Plicamycin Guaranteed loan student texas Online debt consolidation program Loan nz personal: Canada payday loan online Bad credit personal loan 1? second mortgage bad credit Timolol? Va home loan interest rate Debt consolidation consolidate your debt hsbc credit card Naproxen California construction home loan Free Sprint Pcs Sanyo Ringtones Meloxicam Free Nokia Ringtones And Logo! Imiquimod Free Cingular Ringtones Student loan consolidation services Bank federal home loan rate Centered christian consolidation debt Zetia. card credit interest low uk Home loan bad credit ok Albuterol Corticotropin credit card numbers Alternative loan student Consolidation debt loan mortgage second Free Real Voice Ringtones Interest only home equity loan Cash loan payday quick best card credit rate transfer Dofetilide: Card consolidation credit debt services credit card debt Tramadol Nextel Ringtones Program Bontril gas rebate credit card, Epirubicin Free Ringtones Samsung Sprint? Chlorpheniramine bad credit 2nd mortgage Consolidation debt loan online uk Famvir credit free once report year private loan for a student with bad credit, Consolidation loan student travel Free Real Ringtones Sprint Norflex i have bad credit need a loan California home loan program refinancing Bill consolidation debt free erase bad credit approval bad card credit credit instant experian credit score Oxcarbazepine New hampshire home equity loan Pancuronium, California home loan rate american consumer credit counseling? Benztropine chase reward credit card consolidation credit debt credit equifax free online report Federal government home loan Lone Star Ringtones! phone credit card processing Card consolidation credit debt unsecured Toprol credit card special offer free equifax credit report 3 bureau credit free report Bad credit down home loan money no Debt consolidation loan online. credit report repair Nextel Real Music Ringtones Download Mobile Mosquito Ringtones T mortgage application bad credit Norfloxacin Florida free debt consolidation loan Acitretin Fast bad credit personal loan no credit check business loan Zestoretic? Bromodiphenhydramine Default student loan consolidation! Personal loan agreement Temazepam Consolidation direct federal loan student credit history repair Ringtones For Tmobile Cell Phone Naltrexone Advance advance cash loan payday Oxaprozin? Lamotrigine Praziquantel Michigan home equity loan Thiotepa Ursodiol Home equity mortgage refinance loan Free Ringtones For T Mobile Phone Debt consolidation mortgage uk bad credit unsecured personal loan Buprenorphine. Debt consolidation service uk credit card debt settlement. Free Pink Floyd Ringtones Debt consolidation loan online uk, Consolidate private student loan Cefdinir Consolidation ford loan student free porn without credit card Online home improvement loan Sprint Download Ringtones bad credit home loan mortgage services Accupril. Easy loan online personal compare credit card offer No equity debt consolidation loan Debt consolidation organization instant approval credit card bad credit mortgage rating Trimethaphan Midazolam! Military bad credit personal loan Tegretol secured credit card canada Alesse, Anisotropine citi credit card Dolasetron Well fargo home equity loan clean credit report Equity home loan mortgage second xxasdf Student loan consolidations Butorphanol Cefaclor Card consolidation credit debt program Indomethacin Hotlink Tamil Caller Ringtones Dopamine car loan for people with bad credit California countrywide home loan low apr credit card. Mosquito Pitch Ringtones 1 hour payday loan Betaxolol Oxazepam, Ceforanide Ditropan Eulexin card compare credit offer online providian visa credit card Triflupromazine Ambenonium credit card merchant terminal? Keyword free debt consolidation Free Ringtones For Verizon Wireless Phone. Consolidation debt non profit program business credit free report. Promethazine Home equity debt consolidation Department education loan student Apomorphine Cetirizine Pseudoephedrine: Hexocyclium Free Ringtones For Verizon Lg Vx3200 Phone, Carteolol Uk home loan online? Student loan debt elimination Tolmetin, web site credit card processing Delaware home equity loan rate: Government home improvement grants loan Home interest loan mortgage only Broward home loan Indocin: Lasix Fixed rate home loan. Aztreonam 0 apr credit card First horizon home loan free instant online credit report card credit low rate Consolidation debt loan payday! Free I730 Nextel Ringtones How to get a personal loan with bad credit 0 application card credit interest Trimetrexate Trihexyphenidyl Free Real Cell Phone Ringtones: Consolidation consumer credit debt High risk lender for a personal loan Acetaminophen Methacycline Carbinoxamine credit free online report uk Amphetamine Amoxapine credit and debit card processing Poor credit debt consolidation loan? consolidation credit Colistimethate! Diltiazem Deferoxamine Pantothenic Hydroflumethiazide Colorado home loan Bad consolidation credit debt loan no credit card porn capital card credit one service credit equifax free online report Felodipine Personal cash loan Fenoprofen Tesco personal loan credit card offer North carolina home equity loan Second debt consolidation mortgage people with bad credit free credit card processing software Well fargo home loan Ethynodiol credit repair kit free credit repair kit best low rate credit card america card credit mbna Mebendazole Phenylephrine. Wyoming student loan corporation Imiquimod Consolidation debt loan student apply credit card bad credit Lincomycin instant credit card application, Compare home equity loan bad credit fix repair report citibank credit card shell oil credit card Bad credit debt consolidation credit counseling center? Loan mae sallie student Iowa student loan liquidity corp credit fico report score Adalat Tolazamide Benicar Hyzaar Free Ringtones From Alltel Home equity loan tennessee Online payday cash loan best student credit card 100 credit free report Motorola Razr Ringtones Claritin consolidated credit counseling services Free Pink Floyd Ringtones canada credit free online report College grant student loan: New Found Glory Ringtones Amrinone Student loan default Virgin personal loan, Methyclothiazide college loan bad credit: Lg Ringtones V111 Verizon Wireless bad consolidation credit debt Valsartan Oxytetracycline Citibank student loan consolidation New Radical Ringtones check credit free report New jersey home equity loan In home loan credit repair loan! Alesse Personal loan instant approval! Credit debt consolidation loan Fluorescein Isoxsuprine California home loan refinancing, Advance cash loan online payday Home equity loan refinance credit! Unsecured personal loan australia free credit bureau report Moxalactam Default on payday loan California home loan veteran Fha mobile home loan. Novobiocin hsbc credit card Cheapest personal loan Colorado debt consolidation loan Bc loan student premier bank credit card credit counseling new york credit bureau report bad credit auto loan financing Robaxin Caller Ringtones the best credit card Phentermine Personal debt consolidation loan Imuran Relient K Ringtones Federal student loan program Download Nextel Ringtones Software Doxorubicin Qualify fha home loan. Card consolidation credit debt oregon Consolidate defaulted loan student eliminate credit card debt Relafen Consolidating loan student credit report company, Federal student loan interest rate Cephalothin capital one business credit card credit equifax free report. bad credit mortgage refinancing Darvocet advanta business credit card Get Free Ringtones For My Verizon Phone Enoxaparin 1000 loan payday Free debt consolidation company raise credit score Advance america payday loan Download Polyphonic Ringtones Vancomycin Lypressin? Carvedilol Valsartan Protamine Fluvoxamine Lomefloxacin Epinephrine? Carolina loan south student Leuprolide Irbesartan Apply for personal loan, aspire credit card payment Minnesota home improvement loan Free Ringtones For Verizon Samsung Phone Consolidation debt loan mortgage second! bad credit unsecured loan Company consolidation debt minnesota! cosmetic surgery financing for bad credit business accept credit card Apply for unsecured personal loan Bank personal loan for bad credit Cell Mosquito Phone Ringtones Free Downloadable Ringtones Cingular Debt consolidation lead Guaranteed personal loan credit rating uk Loan nelnet student self credit repair increase credit score bad card credit credit people unsecured credit monitoring report High risk personal loan Prednisolone card credit fixed interest low small business credit card processing bureau credit free report drastically improve credit score free credit repair kit first financial bank usa credit card: capital one credit card Personal debt consolidation Best equity home loan quote Fast private student loan shell oil credit card Dulcolax? small bad credit loan Fluconazole:

MG Data

Computers, Internet, SEO, Windows, Cycling, Food & Nutrition

Archive for June, 2007

Trojan.Vundo - removing the virus

Posted by Matt on 7th June 2007

Below is my account of getting the Trojan.Vundo virus. Here’s what I did to get rid of it. Use this info at your own risk. 

Recently while browsing the internet with MSIE version 7 on Windows XP SP 2, fully updated I got a bunch of windows suddenly popping up and things started downloading onto my computer. AVG antivirus said I had a virus but couldn’t do anything about it. The virus seemed to install a number of crap software on my computer and imbedded into winlogon.exe process. Some things I saw were think-adz search assistant, zenosearch, twink, yazzle, outerinfo. Keep in mind I was just browsing the internet, I did not download anything.

The first thing I did when processes and things started going crazy was start killing processes, then disconnected my internet connection. I delete whatever I could out of my temp folders, windows/temp and each users temp folder in documents&settings/localsettings/temp. I deleted all my internet browsers cache/history/cookes. I downloaded a uninstall for outerinfo from outerinfo website which I will not link to here. In short I deleted everything I could that I could find and that the system would let me delete. I also tried to delete things in safe mode but still could not remove the apparent virus file sstqp.dll. When using MSIE, search windows would pop open and windows to other websites, some of them are think-adz, searchhound, mysearchlive, hollywood, canceriq, jack9, and a few other ip address, all of which I blocked with norton internet security. I also changed my browser settings. In internet explorer -> tools->internet options->security->trusted sites, set the slider to high and click ok, delete every site that was there which were added by the viruses because I never use this feature. These viruses exploit the trusted sites feature by injecting urls in there, having another program visit them, which becuase they are trusted, download more viruses with ease because of the slacker active x default settings of the trusted sites.

AVG antivirus couldn’t do anything about it. I installed norton internet security including the firewall and antivirus and it also couldn’t do anything about it. I downloaded fixvundo.exe from Norton, followed the instructions and after a long scan of the computer it could not even find the virus…. yet Norton Antivirus is showing me the problem file seems to be in WINDOWS/system32/sstqp.dll

I downloaded a VundoFix.exe file by atribune.org. It found a list of files that were problems but couldn’t delete 3 of them:

cbxvsst.dll

ddcbcyw.dll

pmnljii.dll

pmnnono.dll - could not be deleted

pqtss.bak1

pqtss.ini - could not be deleted

sstqp.dll - could not be deleted

 

Seeing how all these programs had been downloaded and installed on my computer without my knowledge during this time, I was limiting my internet connection, I’d just turn it off. Checking my running processes with windows task manager (ctrl+alt+del) I observed winlogon.exe using tons of resources, about every second it would flicker on then off, then on then off…… it was really slowing the computer down. I found that by using process explorer and suspending winlogon.exe which is where the virus was hiding, the resource usage went back to normal and I could still use the computer normally. I connected to the internet only when winlogon.exe was suspended thinking that if the resources aren’t being used, possibly nothing more is being downloaded. I would un-suspend winlogon.exe only when I was not connected to the internet and I also set internet explorer to work-offline and was using netscape instead which the virus didn’t seem to be involved with. When the virus would try to pop open an IE window, I would just click tell IE to stay offline.

Now to actually fixing the problem. I found my answer at spywareinfo forums. I had before downloaded some software while reading in other forums about the problem. Software I downloaded included HiJackThis, which is vitally useful for this problem, brute force uninstaller, which I didn’t end up using and some other files at the suggestions of different forum threads that I read. I used hijackthis and delete registry entries that didn’t look right to me, but only ones I was sure about. I followed the suggestions from spywareinfo forums, downloaded their software called VundoFix.exe. Their instructions were basically to do the following, run VundoFix.exe to unzip the files:

restart in safemode:

run killvundo.bat

at the first screen type: C:\WINDOWS\system32\sstqp.dll

enter 

at the second screen type C:\WINDOWS\system32\sstqp.*

enter, and the program does its magic.

Place the hijackthis file in the root C folder (do this to begin with). After typing the second string I got an error that the hijackthis file couldn’t be found and the whole safemode desktop screen went black and all my desktop icons disappeared. I got worried.

I manually turned the computer off by holding the power button. Turned it back on and it started normally. First thing I noticed is that when norton antivirus loaded it no longer gave me a popup that could not be turned off saying I had the trojan.vundo virus in file sstqp.dll. That was nice. Then I opened hijack this and deleted the two entries pertaining to sstqp.dll, one a BHO and one a winlogon notify which now said (file missing) next to them. I also noticed my system resources seemed normal.

Looking good……. I was still not connected to the internet. I then deleted every possible thing I could think of, all the temp folders, internet cache…. etc…. Installed Spybot, Spywareblaster, and Ad-aware SE personal, ran them without updating the definitions and deleted everything they found that was a problem.

Then connected to the internet, update the definitions of all 3 programs and ran them all again. Deleting everything found.

System seems fine. Resources and usage is normal and no apparent virus.

I do still have the pmnnono.dll file and it runs as a winlogon notify according to hijackthis. The main infection is gone, but there is still cleaning up to do.

I found this page, which is very useful: http://forums.spywareinfo.com/lofiversion/index.php/t96702.html

I followed all the directions there. The program VirtumundoBeGone managed to get rid of pmnnono.dll, and also gave me the blue screen of death which was a bit heart stopping for a moment… but all is well, reboot by holding the power button and it booted fine.

Then I ran Dr. Web CureIt. It found a few more files with problems that I took care of. This program scan takes a long time but seems very thorough.

The next program SDfix found a few hidden files which shouldn’t have been there and I manually reviewed them and deleted them. One of them was C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe. The other 4 belonged to GTek, which it seems from a Google search is not a good thing, so I deleted that entire folder also. C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp

Back in non-safe-mode….. I removed my older version of Java via add/remove and downloaded the latest version from sun java and installed it. I also replaced my hosts file in windows/system32/drivers/etc with one from http://www.mvps.org/winhelp2002/hosts.htm ….. there were a few entries that I omitted in the file because I need them turned on, but it is nice to have this level of definite security from these sites, most of which are no good.

System seems good and may even be running better than before all of this. HiJackThis log file shows no apparent problems to me, one file it shows that I can’t figure out what it is for is named mjdsregl.exe in windows/system32. Google search for this turns up nothing.

The hijackthis entry is O4 - HKLM\..\Run: [{F4-4A-A9-9E-ZN}] C:\windows\system32\mjdsregl.exe CHD003

The file does not even exist on my computer, so I guess it is fine.All in all, I lost about 2 days productivity due to this virus.

–end

 

 

 

 

Posted in Windows XP, Internet | No Comments »