Trojan.Vundo,Malware.Trace and Problems on boot and Norton Anti-virus Protect

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bluerage27, Jun 30, 2008.

  1. bluerage27

    bluerage27 Private E-2

    Hi once i have read some of your arhive threads last 6-27-08 i began to follow all of the steps from cleaning, defrag and Removal. I found out my PC had been infected with Trojan.Vundo(it was detected by malware)... I think it started when i downloaded last 6-26-08 a file at Bitlord. The first virus that was detected was a backdoor.trojan the Norton Anti-virus detect it and remove it. So i thought it was ok when i noticed my PC is slowing I already think that there are still problems with my PC. So i run again the Anti-virus and when it reaches 24% (estimated) my PC reboot and my keyboard got stalled and in my monitor it is BAD BIOS. but when i manually reboot it, it just jump to windows and didn't do the normal process when booting... and everytime I scan my PC with my AV it always reboot so i try to search the net and find you guys... a bit STRICT but helps us more to know and learn how to fix things with our PC;)

    1. From cleaning guide my pc was running better than it was before...
    2. From the Malware Removal Guide i don't know if i got the right proceedure
    but got some problems...
    a. SAS - it doesn't goes blue screen,but my problem here is when it attemps to scan my files it becomes stalled. the first time i ran it i left it for almost 6 hours... (thinking it would still work) so reading from the procedure if it doesn't work proceed to the next
    b. Spybot - I dom't have problem here works really great
    c. MAM - no problem here either
    d. combofix - ok too...
    e MTG - here is my bigger problem as it run from the first scan i got an error message type 4
    The application failed to initialize properly (0xc000007b). Click on OK to terminate the application.

    6-30-08 i have been installing and update my windows but still the Net framework doesn't install and now my nortn AV doesn't protect my PC please help
    I only slept 8 hours in repairing my PC for 3 days and now decide to ask your guidance... thanks....

    I'll post the first logs here and post the second logs scan from HJT,MAM and combofix.
     

    Attached Files:

  2. bluerage27

    bluerage27 Private E-2

    here are the second logs of HJT and Combofix.

    BTW,when i right-click all my folders and files and choose properties it seems that it has security tab and when i click the security tab there's been so much users and administrators in it. Is my files been publicly displayed or does this HighJacka** i mean Hacker get and manage my files...

    Thanks...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is:
    C:\STAT.DAT

    Are you running these scans in normal startup mode?

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Using Internet Explorer, Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  4. bluerage27

    bluerage27 Private E-2

    no i don't know

    No. all the logs are from the normal startup

    I got a problem on bitdefender everytime i click install it hangs...
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run this in safe mode:
    CounterSpy - 15 day trial. Requires installation

    Attach the log and be sure you have it fix whatever it finds.
     
  6. bluerage27

    bluerage27 Private E-2

    Sorry if i reply to long... BTW, I want to let you know that I have change some things in my computer when i'm doing it for myself...(just before I post here) :)

    1. I have change the security of C:\drive
    I right click the C:\ then I click properties​
    then click the security Tab and change all the Ownership of the files​
    My question is does this affect anything in the process?

    2. I try to download SpySweeper and try to install it but I can't Install it properly cause everytime I install it and reboot the PC. spysweeper it says It didn't Install well and need to reinstall

    here is my log of the Bitdefender you requested... I can't have it on *.txt as save file so I copy it one by one on hand written :-D I can't install the counterspy everytime I try to install it stop at Windows Installer..
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where did you download MGTools to? For MGtools, did you save MGtools.exe to C:\MGtools.exe as requested. It must be save to the root folder of your Windows boot drive. Do not save it anywhere else and do not attempt to Run or Open it from the download link. You must save it to your PC. Please try again and make sure you follow the instructions exactly. If you get any error messages, see if it is one of the ones that are explained on the download page. If the error is not on the download page, give us the exact word for word message.

    Find and delete:
    C:\Program Files\AskSBar
     
  8. bluerage27

    bluerage27 Private E-2

    Hi TimW
    yes

    when I download it I save it at C:\

    Now I've try it again but it stop at updating : MGTools/sysinfo.txt
    the error message is
    ProcessDll.exe - Application Error
    The application failed to initialize properly (0x0000135). Click on OK to terminate the application

    I've been trying to Install the Microsoft .Net framework (I've Uninstall it last year thought it has no use :()but everytime I install it it blocks me installing it...
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happened when you downloaded and ran Counterspy? Do you have the log from it?

    Also, do you have your xp cd?
     
  10. bluerage27

    bluerage27 Private E-2

    I did download counterspy but I can't install it properly... I don't have the log form...

    I got a question Why did I keep Logging out in the forum without logging out while i'm waiting for replies.

    yup!! I have my XP cd :)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you log in...check the box next to your user name that says "Remember me".


    Go to start / run / and type "sfc /scannow" without quotes.....run it at least twice. Tell me what happens.
     
  12. bluerage27

    bluerage27 Private E-2

    I have done what you said but no problem or log came out
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. bluerage27

    bluerage27 Private E-2

    I think I crash the window repair cause when i boot the Pc it says
    ntldr is missing... I'm now using my another pc. can i still fix the drive without reinstalling the pc need some of the files there... :D
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try doing this...although the problem could be a failing hard drive.
     
  16. bluerage27

    bluerage27 Private E-2

    i had browse to the software forum here at MG. and try to copy that but the error is Access is denied... So browsing in the form i download the fixntldr.exe it help me to load into windows setup.. but once I'm it the setup process it says setup error... an errorlog appears and says asms error sxs.dll error
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum.....you will get more help there regarding this issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds