Originally Posted by stanhill
Thanks, Joe5,
I tried to start WMI - I clicked on "Start this service" and got the error message:
"Could not start the WMI service on Local Computer.
Error 1068: The dependency service on group failed to start."
Then we must try some other things , see below.
I downloaded and tried to use VundoFix - couple times. Every time it fails! As soon as I click on OK to confirm that it will close for a minute it disappears and never re-opens.
I did ewido scan overnight and just got the results - TERRIBLE!!!
see attached plus I enclose current
HJT log
Note:
As you see from
HJT, that awvtu.dll still is there, even though ewido said it was cleaned.
But now we know (from ewido) that there is somewhere also awvvu.dll and ssqrp.dll - not shown by
HJT!
Still my question is - could that Trojan.Passview and Adware.Virtumonde create the networking problems I have?
How to really get rid of all of that?
Thanks in advance!
Stan
Trojan.Passview has been very busy it seems... But so has Ewido.
And Virtumundo is the same as Vundo , they just use a different name , but we'll get that bugger in an other way , there are severall ways to kill a vundo infection.8)
Please download
Process Explorer by Systernals from
HERE.
Also download
KillBox by Option^Explicit from
HERE.
Then boot up in
SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.
Unzip
Process Explorer and double click on
procexp.exe
In the top section of the Process Explorer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
awvtu.dll once and then click the
kill button.
After you have killed all of the
awvtu.dll's under winlogon click
OK.
Next In the top section of the Process Exlporer screen again , double click on
explorer.exe and again click once on each instance of
awvtu.dll then click the
kill button.
Once you have done that click
OK again.
Next run
HijackThis and place a check beside each of the following:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: DosSpecFolder Object - {3496D13A-609A-407B-B181-8F47B4F28AE9} - C:\WINDOWS\system32\awvtu.dll
O20 - Winlogon Notify: awvtu - C:\WINDOWS\system32\awvtu.dll
Now click
fix checked and close HijackThis.
Please copy the text in the quote below, and paste it into a blank notepad window.
Save it as
vundo.reg and in the "save as" type box choose "all files".
Once you have saved it double click it and allow it to merge with the registry.
Code:
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder]
[-HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DosSpecFolder.DosSpecFolder]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DosSpecFolder.DosSpecFolder.1]
Double click on
Killbox.exe and then check the
delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box:
C:\WINDOWS\system32\awvtu.dll
Click the
red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)
And to try to fix the WMI problem (if the malware removal hasn't fixed it yet):
Extract (Open with Winrar, Winzip or similiar) file
wbemoc.in_ from the
full Windows CD i386 (or amd64) folder to
Windows\inf folder then run (Start - Run) this:
rundll32 advpack.dll,LaunchINFSection wbemoc.inf, WBEM
When it asks for the files point it to the full Windows CD, i386 (or amd64) folder.
After it finishes copying, reboot the machine.
If that didn't help at first, get a tool called
Dial-a-Fix.
In it, under Tools choose "Reset WMI" and Go.
Reboot after finished.
If maybe it still doesn't work then try this but
be careful when tampering with the registry.
Repeat it all but first
add to the end of the string (
do not replace the whole string, just add to the end of it), this:
;%SystemRoot%\System32\Wbem
To the registry key using regedit (Start - Run - Regedit) under:
HKEY_LOCAL_MACHINE
\SYSTEM
\CurrentControlSet
\Control
\Session Manager
\Environment
\Path
So it looks something like:
%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\Sy stem32\Wbem
When done post a new
hjt log please.