This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Not sure what's wrong with wife's comp.

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just got a message (1:40 EST) saying that there was a vundo trojan found on opening. It looked like an AVG message. I just closed it without doing anything about it. Seems they pop up whenever the computer is idle for a bit.
Hi sagiter,

Do you recall the location of the detection?



*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.
>>Do you recall the location of the detection? c:\system volume info\_restore [B37680B2-BADA-4E5D-BF3D-83E44C588624\RP2024\AD19985D.dll Process Name: C\windows\sysytem32\svchost.exe Process ID: 1236 Calls it a Vundo KR Trojan The Kaspersky is not running. I've tried it twice, the second time after a reboot and I've waited an hour for it to show it has actually scanned a file. It does the update but once I start the scan it brings up the first file and sits on it. Scanned files never budges from 0. AVG and Tea Timer are off. Just to let you now I will be away all of Thursday and back Friday eve so I won't be able to do anything during that time frame.
Hi sagiter,

No problem with the delay.

c:\system volume info\_restore [B37680B2-BADA-4E5D-BF3D-83E44C588624\RP2024\AD19985D.dll

That is an old System Restore point which we will remove later. It is not harmful unless you restore to that point.



Try this scanner instead.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Thanks
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=942303a7c0e17e4599ce5ece70bb933f # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-03-04 03:08:08 # local_time=2010-03-03 10:08:08 (-0500, Eastern Standard Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777191 100 0 42060551 42060551 0 0 # compatibility_mode=3586 16764926 60 1 208930229 208930229 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16777214 75 18 208930020 278522426 0 0 # scanned=97400 # found=38 # cleaned=0 # scan_time=5537 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\hatutiza.dll.vir a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\janeguwo.dll.vir a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\yikujode.dll.vir a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\yuterahi.dll.vir a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\zelovumi.dll.vir a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199827.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199828.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199829.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199850.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199851.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199852.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199917.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199983.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0199984.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0200964.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0200993.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0201040.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0201070.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2024\A0201071.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\dazuyelu.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\dusukaga.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\duyesedi.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\gifeleho.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\himesuvo.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\hutijezu.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\judopuje.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\lewabenu.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\tipifipo.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\tipilifi.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\vagiwara.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\wayofuge.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\woheluba.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\zobubabe.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\02282010_230144\C_WINDOWS\SYSTEM32\zugoyepi.dll a variant of Win32/Kryptik.CRQ trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\03012010_202515\C_WINDOWS\SYSTEM32\gemewoda.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\03012010_202515\C_WINDOWS\SYSTEM32\jebanemu.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\03012010_202515\C_WINDOWS\SYSTEM32\yoyorena.dll a variant of Win32/Kryptik.CRP trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\03022010_111615\C_WINDOWS\System32\feyumaze.exe a variant of Win32/Kryptik.COR trojan 00000000000000000000000000000000 I
Hi sagiter,

All the ESET detections are in old Restore points or files we have already quaratined. These will be removed shortly during the tools removal.

If no other problems, we can clean up our tools. Keep Defogger, we will use it shortly.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.zip
  • GMER(v8vqkne5.exe)


Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.



Don't forget to re-enable Teatimer when you are finished.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader Adobe Reader 7.0.7 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Hi sagiter, That would indicate there weren't any drivers to re-enable. Defooger is used just as a precaution when using RootKit scanners. Cd emulators can cause false positves or the RootKit scanner to stall. Your early logs did not indicate clearly if these types of drivers were present or not. How is the computer? Thanks
Hi sagiter,

If you uninstalled combofix with the method I posted, all the old restore points should have been removed and a new one created. Did you get a message to the effect that combofix coul not be uninstalled? Where the warning before or after you uninstalled combofix?

Let's do a manual System Restore cleanup



* Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.
Combofix appeared to run without any difficulty. I've deleted the old restore points as directed. I'll let you know if the pop-ups show up again today. I also have a question. I use Slimbrowser as opposed to IE. Is there a problem with that ? I think slimbrowser works on the ie platform anyway. Thanks.
Oldman960, I just wanted to thank you for your help before the thread closed. I really appreciate your time and efforts. I'll make a donation to help keep you guys in business. sagiter

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI