[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Antivirus 2009 combofix log

Posted on 2009-02-19
16
Medium Priority
?
4,312 Views
Last Modified: 2013-12-06
Company PC ( Win XP) got hit with the nasty little Antivirus 2009 malware. Ran Combofix, malwarebytes and a full AVG antivirus and rootkit scan. PC seems to be back to running normal again but i beleive there is a bit more to clean up. Attached is the last combofix log done after I did all the scans. Can I have someone take a quick look aand let me know what to do next?
Combofix.txt
0
Comment
Question by:huntleyj
  • 8
  • 6
  • 2
16 Comments
 
LVL 8

Expert Comment

by:Dirtpatch-Jenkins
ID: 23685615
Yeah, still a few problems  

dahanape.dll is associated with Vundo BJF
info here -
http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453144323

I'll check the rest.
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23685635
There is more to fix with combofix. But do me a favor, and run a scan with the following tool. I may be wrong but I'm smelling a Virut infection here, and if that's the case then, I advise a wipe and load on virut infections.

http://www.freedrweb.com/

Just run the free scan, you can let it cure what it finds but post the report in an attachment here. If free from virut I can then give you the cfscript to clean up what's left in combofix.
0
 
LVL 3

Author Comment

by:huntleyj
ID: 23685753
indiGenus:
Done: No virus found
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 8

Expert Comment

by:Dirtpatch-Jenkins
ID: 23685811
Are you able to directly delete those dll's?
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23685853
Good, we can proceed. Give me a bit and I'll give you a script to run.


0
 
LVL 3

Author Comment

by:huntleyj
ID: 23685892
forgot to mention I'm doing this remotely. infected PC is about 300 miles away. lol
Dirtpatch-jenkins:
I can try to delte them one by one but if I can get a script, all the better :)
0
 
LVL 20

Accepted Solution

by:
IndiGenus earned 500 total points
ID: 23685949
Hopefully this will eradicate....

1. Open Notepad.

2. Now copy/paste the text between the lines below into the Notepad window:

------------------------------------------------------------------------

File::
c:\windows\system32\drivers\gaopdxitbwulcj.sys.rmv
c:\windows\system32\drivers\gaopdxsscpmpdi.sys.rmv
c:\windows\system32\stu2.exe
c:\windows\system32\oybnil.dll
c:\windows\system32\vwdrux.dll
c:\windows\system32\zoypxv.dll
c:\windows\system32\timvru.dll
c:\windows\system32\hejivm.dll
c:\windows\system32\ryzyws.dll
c:\windows\system32\omgsff.dll
c:\windows\system32\afqwsa.dll
c:\windows\system32\jtzteo.dll
c:\windows\system32\gelbxc.dll
c:\windows\system32\dahanape.dll
c:\windows\system32\labefala.dll
c:\windows\system32\zohijiho.dll
c:\windows\system32\musirora.dll
c:\windows\system32\virinida.dll
c:\windows\system32\wefihipe.dll
c:\windows\system32\gijimedo.dll
c:\windows\system32\nubamiko.dll
c:\windows\system32\nusuzefa.dll
c:\windows\system32\jekatuji.dll
c:\windows\system32\reveligi.dll
c:\windows\system32\dafamupu.dll
c:\windows\system32\sajekeye.dll
c:\windows\system32\pomazabo.dll
c:\windows\system32\jevogeso.dll
c:\windows\system32\drivers\aucbmj.sys

Driver::
qncftm

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-

------------------------------------------------------------------------

3. Save the above as CFScript.txt on your desktop.

4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please upload the following reports/logs.

-Combofix.txt



0
 
LVL 3

Author Comment

by:huntleyj
ID: 23686147
Well ran the script. It did want to reboot but now it won't boot properly. All they (they being the people 300 miles away) is thier desktop background image. No Icons, no taskbar, nothing.
Oops... lol
Looks like a fresh format coming...
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23686276
Uh-oh... looks like userinit was patched, which was making me suspect a file infector like Virut. I don't see what in the script may have caused things to change....? Can they bring up explorer manually?
0
 
LVL 3

Author Comment

by:huntleyj
ID: 23686312
Im connected to the c drive of that machine. Can I take a working userinit.exe from a known working PC and copy it to there? Would that work?
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23686374
Not sure if that was what happened or not, just a suspect. Can you bring up explorer manually? ctl-alt-del to bring up taskmanager then start from there?
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23686418
If so we can try running cf again and restoring what was done. Not sure if this will even bring it back. Was anything else done? This machine did have some really nasty malware on it. Doesn't mean it can't be fixed but sometimes system damage like this occurs with this.

I have to head out for about an hour or so but will check back in.
0
 
LVL 3

Author Comment

by:huntleyj
ID: 23686569
On a whim I  connected to another machine then  \\infectedmachine\c$\  renamed the existing one and copied a working userinit.exe into the system32 folder.
 Got the people to reboot and it seems to have worked. I connected again and ran one more combofix. here is the log

log.txt
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23687069
Looks good, nice work. I would still advise they do some virus and malware scans for remnants, ect....Kaspersky online scanner, while it doesn't fix anything, is very thorough.

You should also remove combofix and clean up.

Click START then Run...
Now type Combofix /u in the runbox  and click OK.  Note the space between the X and the U, it needs to be there.

The above procedure will:

Delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present

Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Reset System Restore.

Let me know if you have anything else on this one, nice job.
Dave


0
 
LVL 3

Author Closing Comment

by:huntleyj
ID: 31548958
Thanks for your help on this
0
 
LVL 20

Expert Comment

by:IndiGenus
ID: 23687800
You're welcome, glad we got it sorted out.....I was worried for a minute there.

Regards,
Dave
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
This article investigates the question of whether a computer can really be cleaned once it has been infected, and what the best ways of cleaning a computer might be (in this author's opinion).
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Suggested Courses

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question