Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 3864
  • Last Modified:

Trojan.Vundo, Downloader.MisLeadApp, and Adware.Ezula Infection

My computer is infected with Trojan.Vundo, Downloader.MisLeadApp, and Adware.Ezula. I've an up-to-date version of Norton Antivirus running and on a daily basis it quarantines Vundo and Ezula. I get popups now and again. I have SpyBot running and every morning when I wake up I have a list of registry entry keys that the system is attempting to change. I have run scans of SpyBot and Ad-Aware and Netcom3 but haven't been able to remove the spawning application.

This happened last Friday (it is now Wednesday). I posted a HijackThis log here: http://www.techsupportforum.com/search.php?searchid=2367013. Perhaps you need a more up to date log? Please let me know what needs to be done. I freelance from home and this bug is eating away at my time. I have only myself to blame for snooping the internet - I have learned my lesson. But how much longer do I need to be wacked!!!!!

I appreciate your help. Regards...
0
joibrooks
Asked:
joibrooks
  • 7
  • 5
7 Solutions
 
IndiGenusCommented:
Vundo is stubborn and nasty. Can't see your log because you need to sign up at the sight.

Download and Run ComboFix (by sUBs)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Disable your Anti-virus and any real-time Anti-spyware monitors that are running.
Then double click Combofix.exe & follow the prompts.
When finished, it will produce a log for you. Upload that log in your next reply with a new HijackThis log. Please upload the log at EE-Stuff.com
Use the link below and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall.
Note 2: Remember to re-enable your Anti-virus and Anti-spyware.

NOTE: If you have issues connecting to your network or internet after running combofix you can either simply reboot, or do the following:
* Going to Control Panel > Network Connections.
* Right click on their Network icons & select "Repair"
or
Alternately, if the Network icon appears in the notification area in the lower right corner of Desktop, right-click it, and then click Repair from the shortcut menu.

Please also rename HijackThis to something else before running it and uploading your log.
0
 
joibrooksAuthor Commented:
i have sent the log files you requested. since i rebooted, i have another issue now. at a cold startup i get a rundll message:

Error Loading
c:/windows/system32/gebrpfgp.dll

when i click okay, the system boots.

thank you...
0
 
IndiGenusCommented:
>""Error Loading
c:/windows/system32/gebrpfgp.dll""<

That is one of the Vundo files. It is in one of your run keys. More work to do with combofix. I will give you a CFScript to run that will fix that. Just give me a bit to comb through the log and I will post a script for you with instructions.
0
 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

 
IndiGenusCommented:
I would recommend you remove the Pando Toolbar and program. It is supported by Adware.
Also...Spyclean and or Netcom3 Cleaner is also a rogue Anti-Spyware application and should be removed.
You can try using Add or Remove Programs to get these first but we may need to make manual deletions.
I am going to include Spyclean removal in the combofix script.

1. Open Notepad.

2. Now copy/paste the text between the lines below into the Notepad window:


---------------------------------------------------------------------------------------------------------------

File::
C:\WINDOWS\system32\hggda.dll
C:\WINDOWS\system32\drvvih.dll
C:\WINDOWS\system32\gebbcdc.dll
C:\WINDOWS\system32\gebrpfgp.dll

Folder::
C:\Program Files\yzudexmv
C:\Program Files\Unezyuxj
C:\Program Files\Netcom3 Cleaner

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{299E86A2-BF77-41BC-84C2-FA57787C2BCE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{376F3CEB-BB08-4FA1-B7FC-168A61DFA458}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79B3844B-6DAC-4B78-B0B8-C99D8BBDCD50}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86F7CF81-69B0-4270-BC06-9D3D0CC42B87}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpyClean"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"9cac5db8"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{79B3844B-6DAC-4B78-B0B8-C99D8BBDCD50}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbcdc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


---------------------------------------------------------------------------------------------------------------


3. Save the above as CFScript.txt on your desktop.

4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please upload the following reports/logs.

-Combofix.txt
-A new HijackThis log

0
 
joibrooksAuthor Commented:
okay. i've uploaded a new combo and hijackthis log file. doctor, what is the prognosis?
0
 
IndiGenusCommented:
Looks better, how's it running?

A couple of Vundo files popped up or were missed. You can run another CFScript with them under files:, or just delete them manually.

C:\WINDOWS\system32\adggh.ini2
C:\WINDOWS\system32\adggh.ini
C:\WINDOWS\system32\pgfprbeg.ini

Also, still a service present for that Spyclean garbage program.

To remove...

Click Start -> Run...
Enter the following commands one at a time into the window and click [b]OK[/b] each time.

sc stop Netcom3
sc delete Netcom3

Run HijackThis and fix this item:

O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
0
 
IndiGenusCommented:
Sorry, left bbcode around "OK" above. There shouldn't be any [b]'s
0
 
joibrooksAuthor Commented:
okay. status:

after i ran sc stop and delete Netcom3, the comment doesn't show up in the HiJack log.

i created and ran the cfscript to delete the .dll files in the win system32 directory.

i'm very hopeful here!

should i get rid of  the SpyBot app?
0
 
IndiGenusCommented:
>""should i get rid of  the SpyBot app?""<

No, well, up to you....Spybot S&D is good for one time scans. And TeaTimer works well if it's not too annoying. But the program has been around since the dawn of spyware and is good.
0
 
joibrooksAuthor Commented:
that's a roger on spybot.

i'm going to leave this ticket open for a day. i'm VERY hopeful. by tomorrow you oughtta be 500 points richer. and tonight, if your ears are ringing it is because i'll be praising you at dinner time prayers. thank you for hanging in there with me.

-jb
0
 
IndiGenusCommented:
No problem jb, glad we could help and thank you (lord knows I need all the prayers I can get ;))
Dave
0
 
joibrooksAuthor Commented:
Prompt response, exceptional ability, professional and  knowledgable. Well deserved rating of  A++
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

  • 7
  • 5
Tackle projects and never again get stuck behind a technical roadblock.
Join Now