Oddthought Forums
vBookie Blogs Oddthought Arcade Dopewars Global Conflict Survival of Species

Go Back   Oddthought Forums > Oddthought Community Forums > Techie Section

Techie Section Geek Chat from Hardware to Software to Internet, Video Games, Pc and a load of "how the hell did I do that and how the hell do I stop it" Stuff!

Techie Section Thread, Malware problems in Oddthought Community Forums; You mean we should start charging? lol...
Reply
 
LinkBack Thread Tools Display Modes
  #11  
Old 23rd August 2008, 03:04 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

You mean we should start charging? lol
__________________
Reply With Quote
  #12  
Old 23rd August 2008, 03:09 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

He means I occasionally PM him after forgetting to install drivers
__________________

Reply With Quote
  #13  
Old 23rd August 2008, 03:22 AM
Dymond's Avatar
Bad Ass Tech Boss
 

Join Date: Feb 2007
Posts: 6,037
Default

Quote:
Originally Posted by Red Dragon View Post
You mean we should start charging? lol
LOL definitely!
__________________
Best A Game Score: Round 43
9 Blanco Loco $133,317,727 TLB (A4 - Junkie)
Best Overall A Finish: Round 53
2 Rolling Stock $124,229,022 The Bee Hive (A5-machine)
Favorite B game Score: Round 41
1 Devastator $135,998,871 The Street Kings (B7)
Reply With Quote
  #14  
Old 23rd August 2008, 03:43 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

The problem is back lol...



Deleted them all and here is the log.
Attached Files
File Type: txt mbam-log-8-23-2008 (02-48-11).txt (2.4 KB, 1 views)
__________________

Reply With Quote
  #15  
Old 23rd August 2008, 04:15 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

Combofix
  • Download Combofix to your desktop. Don't run it yet!
  • Right click Avira in your system tray and uncheck enable system guard
  • Right click Comodo and disable that as well
  • Double click combofix.exe & follow the prompts.
  • A window will open with a warning.
  • When the scan completes it will open a text window. Please attach that log back here together with a fresh HJT log.
Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Combofix is a very powerful tool so please do NOT do anything without instruction

Combofix will automatically save the log file to C:\combofix.txt

After it is complete and the log is open turn your firewall and real time protection back on
__________________
Reply With Quote
  #16  
Old 23rd August 2008, 05:28 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

Done. I had to split it in 2 due to the gay upload rules.
Attached Files
File Type: txt ComboFix.txt (14.6 KB, 2 views)
File Type: txt ComboFix2.txt (8.0 KB, 1 views)
__________________

Reply With Quote
  #17  
Old 23rd August 2008, 05:54 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

Download and Install SDFix
  • Download SDFix and save it to your Desktop.
  • Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

Boot into Safe Mode
  • Restart your computer and start pressing the F8 key on your keyboard.
  • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

Run SDFix
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
  • Attach Report.txt back here
__________________

Last edited by Red Dragon; 23rd August 2008 at 06:01 AM.
Reply With Quote
  #18  
Old 23rd August 2008, 06:05 AM
steff's Avatar
SofS Game Admin/Moderator
 
Join Date: Feb 2007
Location: UK
Posts: 3,515
Blog Entries: 1
Default

Should I go into "Steven" or "Administrator"? I'll do it later though... 5am... bedtime.
__________________

Reply With Quote
  #19  
Old 23rd August 2008, 06:13 AM
Red Dragon's Avatar
Tech Mod
 

Join Date: Apr 2006
Location: Florida
Posts: 903
Blog Entries: 2
Send a message via MSN to Red Dragon
Default

Go under your normal account
__________________
Reply With Quote
  #20  
Old 23rd August 2008, 09:42 AM
XXX's Avatar
XXX XXX is offline
Secret Agent
 

Join Date: Apr 2006
Posts: 644
Blog Entries: 1
Send a message via MSN to XXX
Default

We got it too,,,,,,


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aldd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SysUpd
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F7813 A-AF74-4474-B1DC-7EE6FB6C43C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D2FC9 B-041C-470E-AE72-F8C001247626}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB 5-BD7D-4D49-A1AA-8AB0F3D3CB44}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52B1DFC 7-AAFC-4362-B103-868B0683C697}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6DD0BC0 6-4719-4BA3-BEBC-FBAE6A448152}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7BF451A C-2010-4804-B256-DB2F0A8D9EB6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{827DC83 6-DD9F-4A68-A602-5812EB50A834}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DBF02D A-4360-4A7E-BEA1-347B87816327}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF7FCAF B-9FDB-4F5E-BAC6-68BDEE61D6C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC14822 8-87E1-4D00-AC06-58DCAA52A4D1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B5527 4-0F9A-41E5-9067-A3539BD9E860}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBE0D59 D-F985-4AC6-8826- FEE957065D42}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AEFF96 5-B1A9-4675-966A-26C2E812AD51}
HKEY_CLASSES_ROOT\MSEvents.MSEvents
HKEY_CLASSES_ROOT\MSEvents.MSEvents.1
HKEY_CLASSES_ROOT\psapianalyzer.psapianalyzer.1
HKEY_CLASSES_ROOT\psapianalyzer.psapianalyzer
HKEY_CLASSES_ROOT\MFCOptimizeClass.MFCOptimizeClas s.1
HKEY_CLASSES_ROOT\MFCOptimizeClass.MFCOptimizeClas s
HKEY_CLASSES_ROOT\RawExecAction.RawExecAction
HKEY_CLASSES_ROOT\RawExecAction.RawExecAction.1
HKEY_CLASSES_ROOT\iepl.iepl.1
HKEY_CLASSES_ROOT\iepl.iepl
HKEY_CLASSES_ROOT\ATLDistrib.ATLDistrib.1
HKEY_CLASSES_ROOT\ATLDistrib.ATLDistrib
HKEY_CLASSES_ROOT\WTLHelper.WTLHelper
HKEY_CLASSES_ROOT\WTLHelper.WTLHelper.1
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder.1
HKEY_CLASSES_ROOT\DPCUpdater.DPCUpdater.1
HKEY_CLASSES_ROOT\DPCUpdater.DPCUpdater
HKEY_CLASSES_ROOT\ADOUsefulNet.ADOUsefulNet
HKEY_CLASSES_ROOT\ADOUsefulNet.ADOUsefulNet.1
HKEY_CLASSES_ROOT\InfoDocReader.InfoDocReader
HKEY_CLASSES_ROOT\InfoDocReader.InfoDocReader.1
HKEY_CLASSES_ROOT\ATLEvents.ATLEvents.1
HKEY_CLASSES_ROOT\ATLEvents.ATLEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\psapianalyzer. psapianalyzer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\psapianalyzer. psapianalyzer.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MFCOptimizeCla ss.MFCOptimizeClass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MFCOptimizeCla ss.MFCOptimizeClass.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RawExecAction. RawExecAction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RawExecAction. RawExecAction.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iepl.iepl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iepl.iepl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLDistrib.ATL Distrib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLDistrib.ATL Distrib.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WTLHelper.WTLH elper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WTLHelper.WTLH elper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DosSpecFolder. DosSpecFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DosSpecFolder. DosSpecFolder.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DPCUpdater.DPC Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DPCUpdater.DPC Updater.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADOUsefulNet.A DOUsefulNet
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADOUsefulNet.A DOUsefulNet.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InfoDocReader. InfoDocReader
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InfoDocReader. InfoDocReader.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLE vents
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLE vents.1
Presence of the mutex 'SysUpdIsRunningMutex' .
Technical Information
Win32/Vundo is a multiple-component family of programs that deliver 'out of context' pop-up advertisements. They may also download and execute arbitrary files.
Vundo is often distributed as a DLL file and installed on an affected machine as a Browser Helper Object (BHO) without a user's consent. This family uses advanced defensive and stealth techniques to escape detection and to hinder removal.

Please see our detailed Win32/Vundo family analysis elsewhere in this encyclopedia for additional information.
Steps
Take the following steps to help prevent infection on your system:
Enable a firewall on your computer.
Get the latest computer updates.
Use up-to-date antivirus software.
Use caution with attachments and file transfers.
Enable a firewall on your computer
Use a third-party firewall product or turn on the Microsoft Windows XP Internet Connection Firewall.
To turn on the Internet Connection Firewall in Windows XP
Click Start, and click Control Panel.
Click Network and Internet Connections. If you do not see Network and Internet Connections, click Switch to Category View.
Click Change Windows Firewall Settings.
Select On.
Click OK.
To turn on the Windows Firewall in Windows Vista
Click Start, and click Control Panel.
Click Security.
Click Turn Windows Firewall on or off.
Select On.
Click OK.
Get the latest computer updates
Updates help protect your computer from viruses, worms, and other threats as they are discovered. You can use the Automatic Updates feature in Windows XP to automatically download future Microsoft security updates while your computer is on and connected to the Internet.
To turn on Automatic Updates in Windows XP
Click Start, and click Control Panel.
Click System.
Click Automatic Updates.
Select a setting. Microsoft recommends selecting Automatic. If you do not choose Automatic, but you choose to be notified when updates are ready, a notification balloon appears when new downloads are available to install. Click the notification balloon to review and install the updates.
Use up-to-date antivirus software
Most antivirus software can detect and prevent infection by known malicious software. To help protect you from infection, you should always run antivirus software that is updated with the latest signature files. Antivirus software is available from several sources. For more information, see Windows Vista Antivirus Software - Windows Live OneCare - Microsoft.
Use caution with attachments and file transfers
Exercise caution with e-mail and attachments received from unknown sources, or received unexpectedly from known sources. Use extreme caution when accepting file transfers from known or unknown sources.
Recovery Steps
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft online scanner (Windows Live OneCare). For more information, see Windows Vista Antivirus Software - Windows Live OneCare - Microsoft.


Search the Encyclopedia
Go



Latest Definition Updates
Windows Defender
Antispyware: v1.41.689.0
32 bit
64 bit
Information on updating Windows Defender
Microsoft Forefront Client Security
Antivirus: v1.41.689.0
Antispyware: v1.41.689.0
32 bit
64 bit
Information on updating Microsoft Forefront Client Security



Severity
High
Medium
Low


Glossary
View the Glossary
__________________
XXX's Multie Factory



Hey Boss, Someone's comming! What should we do ?

RUN!!!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
XicemanX Malware Thread Red Dragon Techie Section 168 3rd April 2008 05:41 PM
Guide to Removing Malware Red Dragon Tutorial Section 0 22nd February 2008 04:21 AM
Virus/malware/spyware removal... TraPStaR Techie Section 6 2nd December 2006 08:42 PM


All times are GMT +1. The time now is 02:55 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109