Trojan disabled my anti-virus/malware programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by anom, Jul 9, 2009.

  1. anom

    anom Private E-2

    Hi

    Yesterday I tried to play a downloaded video torrent and since then I've been having problems. Norton first detected a trojan and it appeared that it repaired the issue but after reboot Norton did not load, and I could not load Malwarebytes Anti-Malware or Spybot. After reading the forums I found out that changing the file name to mb.exe might help and it did. So I was able to scan with mbam which found 6 files with problems. After this I was able to run SAS and now my system appears to be mostly fixed except that every once in a while Norton will pop up with the same trojan, so I think that there may still be a residual issue.

    I followed the "read me" thread and have attached my logs here. There are 2 each of SASlogs and MBAMlogs because after re-scanning there were still bad files.

    Thanks in advance
     

    Attached Files:

  2. anom

    anom Private E-2

    here are the other logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what Norton is finding....the full path.

    You also need to run CCleaner and then empty out these folders:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Monica\Local Settings\Temp\

    Please install this:
    AutoEater.

    You are running out of room on your C:\ drive. Are you installing programs on the D drive?
     
  4. anom

    anom Private E-2

    I ran CCleaner and emptied those folders (at least the files that I could delete). Installed Autoeater. Also deleted 2gb from the C: drive, I'm still installing programs there.

    Norton detected: Suspicious.Vundo.2
     
  5. anom

    anom Private E-2

    Last night, Norton again detected and fixed Suspicious.Vundo.2, so it appears that my system is not fully clean.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what Norton is finding. I have no idea as to whether it is an infected file or a false positive. I need the exactly path for the items it is reporting.
     
  7. anom

    anom Private E-2

    How do I find the path?
     
  8. anom

    anom Private E-2

    I used a tool available through symantec with the following results:

    Symantec Trojan.Vundo Removal Tool 1.5.1
    The process "iexplore.exe" might be affected by the threat. It cannot be terminated.
    The process "iexplore.exe" might be affected by the threat. It has been suspended.
    The process "iexplore.exe" might be affected by the threat. It has been suspended.
    The process "iexplore.exe" might be affected by the threat. It has been terminated.
    The process "iexplore.exe" might be affected by the threat. It has been terminated.
    The process "iexplore.exe" might be affected by the threat. It has been terminated.

    C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\Quarantine: (not scanned)
    C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp: (not scanned)
    C:\System Volume Information: (not scanned)
    D:\System Volume Information: (not scanned)

    Trojan.Vundo has been successfully removed from your computer!

    Here is the report:

    The total number of the scanned files: 67587
    The number of deleted files: 0
    The number of viral processes terminated: 3
    The number of viral processes suspended: 2
    The number of viral threads terminated: 0
    The number of registry entries fixed: 0
     
  9. anom

    anom Private E-2

    Here is a screenshot of the details of the risk.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then let me know if you have additional problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds