Just had to share this infected gem

antharr

New member
Pro User
Local time
2:07 AM
Messages
214
I work for an ISP and deal with all sorts of issues when people run into internet connectivity issues. I run into malware issues quite often but ones like this machine shown below never cease to amaze me. This was a scan in progress with Superantispyware. Please keep in mind that this was not the first we have helped this individual clean their machine. This machine has Avast and Malwarebytes installed. This goes to prove that the most valuable security tool is the user.
 

Attachments

  • Capture.JPG
    Capture.JPG
    22.8 KB · Views: 48

My Computer My Computer

At a glance

Windows 7 64xAMD Turion II Dual-Core Mobile M520 2.30 GHz4GBATI Radeon HD 4200
Computer Manufacturer/Model Number
Toshiba L505
OS
Windows 7 64x
CPU
AMD Turion II Dual-Core Mobile M520 2.30 GHz
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4200
TY for sharing and of course, I agree 100%. Just a little common sense goes a long way.
Stay away from the alluring sites, that we know have a virus for all visitors.
 

My Computer My Computer

At a glance

Windows 10, Home Clean InstallIntel Core2 processsor Q8200(2.33Ghz 1333FSB)...6 gbATI Radeon 256MB HD3650
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
I believe that client regularly visit adult sites...
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-bit Version 6.1 (build ...Intel Pentium Dual CPU T2390 @ 1.86GHzSiS Mirage 3 Graphics SiS627 series
Computer Manufacturer/Model Number
Neo Vivid V2121
OS
Windows 7 Ultimate 32-bit Version 6.1 (build 7600.16385)
CPU
Intel Pentium Dual CPU T2390 @ 1.86GHz
Motherboard
SiS M720SR
Graphics Card(s)
SiS Mirage 3 Graphics SiS627 series
Sound Card
Built-in
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1280x800
Hard Drives
Fujitsu MHZ2160BH G1 ATA Device 160GB
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Pointing Device
I believe that client regularly visit adult sites...

Worse... Facebook. From just a glance without looking each one up I'd say it's Facebook and maybe some free games. I'm guessing they got a lot of those "Your infected install our A/V" type pop-ups. I doubt any of this was of any significant threat. I work tech support for an ISP myself and I've seen far worse.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64AMD Phenom II X4 965 Black Edition Deneb 3.4GHz4GB (2x2GB) G.Skill SDRAM DDR3 1600 Dual ChannelSPARKLE SX96GT2048D2-HP GeForce 9600 GT 2GB 2...
OS
Windows 7 Ultimate x64
CPU
AMD Phenom II X4 965 Black Edition Deneb 3.4GHz
Motherboard
GIGABYTE GA-MA770T-UD3P
Memory
4GB (2x2GB) G.Skill SDRAM DDR3 1600 Dual Channel
Graphics Card(s)
SPARKLE SX96GT2048D2-HP GeForce 9600 GT 2GB 256-bit GDDR2
PSU
Rosewill Green Series RG530-2 530W 80 PLUS
I believe that client regularly visit adult sites...

Worse... Facebook. From just a glance without looking each one up I'd say it's Facebook and maybe some free games. I'm guessing they got a lot of those "Your infected install our A/V" type pop-ups. I doubt any of this was of any significant threat. I work tech support for an ISP myself and I've seen far worse.

You are right. I have seen machine much worse myself. There's nothing like logging into a machine to see that 50% of the browser window is covered with tool/search bars.
 

My Computer My Computer

At a glance

Windows 7 64xAMD Turion II Dual-Core Mobile M520 2.30 GHz4GBATI Radeon HD 4200
Computer Manufacturer/Model Number
Toshiba L505
OS
Windows 7 64x
CPU
AMD Turion II Dual-Core Mobile M520 2.30 GHz
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4200
Setting the rogue showings aside and safe/unsafe surfing habits, with the Vundo variants in that image, I would look at Java to make sure the old, vulnerable versions are uninstalled. Even if the most current version is installed, if the old version remains on the computer, the computer is vulnerable to Virtumundo.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
lol I have seen all these except the first one listed. I haven't seen Vundo in a while though. there is a specific program to get rid of Vundo called Vundofix. you can find it here. If the infection comes back use this: |MG| VundoFix 7.00 Download

Also, I have seen many replies on this forum that suggest MSE instead of Avast. that might help this character not be infected as much.
 

My Computer My Computer

At a glance

Win7 Home Premium 64xIntel Core 2 Duo P7450 / 2.13 GHz (2.29 with ...4 GB PC-6400 Hyundai (2X2) at 800MhzNVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
Setting the rogue showings aside and safe/unsafe surfing habits, with the Vundo variants in that image, I would look at Java to make sure the old, vulnerable versions are uninstalled. Even if the most current version is installed, if the old version remains on the computer, the computer is vulnerable to Virtumundo.

That could be the issue now that you say that. I keep getting unrecognized windows command when I tried to use ping or ipconfig. The system path in Advanced Settings was hosed and the file path was pointing to the Java program folder. I had to change it back to c:\windows\system32 to so that commands would work.
 

Attachments

  • Capture.JPG
    Capture.JPG
    31.5 KB · Views: 3

My Computer My Computer

At a glance

Windows 7 64xAMD Turion II Dual-Core Mobile M520 2.30 GHz4GBATI Radeon HD 4200
Computer Manufacturer/Model Number
Toshiba L505
OS
Windows 7 64x
CPU
AMD Turion II Dual-Core Mobile M520 2.30 GHz
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4200
That is an untrained, ignorant user.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32 bitIntel(R) Pentium(R) 4 CPU 3.00GHz2.50 GB RAMNVIDIA GeForce 7600 GS
Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
lol I have seen all these except the first one listed. I haven't seen Vundo in a while though. there is a specific program to get rid of Vundo called Vundofix. you can find it here. If the infection comes back use this: |MG| VundoFix 7.00 Download

FYI, Atri hasn't updated Vundofix in a long time -- probably since he started working for Lavasoft, which he has since left to work for Prevx.

Best course of action is uninstalling all old versions of Java and installing the latest version (although it too has issues -- see Serious New Java Flaw Affects All Versions of Windows) and scanning with MBAM.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Lol thanks Corrine, I haven't seen Vundo in a while. Last time I cleaned it from a comp, VundoFix was still up-to-date. I was looking today after posting to see if MSE and newer programs do the same thing VundoFix does, but had no luck in finding the info so far.

Thanks for the heads up.

Snippet from website:
-------------------------------
Vundofix Update Written by Administrator Jan 28, 2007 at 10:03 AM
-------------------------------
 

My Computer My Computer

At a glance

Win7 Home Premium 64xIntel Core 2 Duo P7450 / 2.13 GHz (2.29 with ...4 GB PC-6400 Hyundai (2X2) at 800MhzNVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
lol I have seen all these except the first one listed. I haven't seen Vundo in a while though. there is a specific program to get rid of Vundo called Vundofix. you can find it here. If the infection comes back use this: |MG| VundoFix 7.00 Download

FYI, Atri hasn't updated Vundofix in a long time -- probably since he started working for Lavasoft, which he has since left to work for Prevx.

Best course of action is uninstalling all old versions of Java and installing the latest version (although it too has issues -- see Serious New Java Flaw Affects All Versions of Windows) and scanning with MBAM.

I always recommend following up with a SAS scan as well. There have been instances where it picked up a few things that MBAM did not and vice versa.
 

My Computer My Computer

At a glance

Windows 7 64xAMD Turion II Dual-Core Mobile M520 2.30 GHz4GBATI Radeon HD 4200
Computer Manufacturer/Model Number
Toshiba L505
OS
Windows 7 64x
CPU
AMD Turion II Dual-Core Mobile M520 2.30 GHz
Memory
4GB
Graphics Card(s)
ATI Radeon HD 4200
Back
Top