Vundo help please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wubbazzie, Oct 29, 2005.

  1. wubbazzie

    wubbazzie Private E-2

    Alright I ran all of the scans and stuff posted on the "read me first" page and I couldn't get rid of the Virtumonde thing. I keep getting a ton of pop-ups and now I can't even open my homepage. If anyone could help me I would really apprecaite it! Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In step 6 of the READ & RUN ME we gave you a link to Special Removal Procedures

    You should have clicked it. Try it now and see the links there. One mentions Winfixer aka Virtumonde

    You can also try the below if desired!

    These steps must be run exactly as specfied.

    1) Download this Symantec Trojan.Vundo Removal Tool to a location where you can find it later
    2) Make sure you do not run anything but what is specified. DO NOT OPEN any browsers during this process below so print or save these unstructions locally so you know what to do while offline.
    3) Boot into safe mode and physically unplug your cable to the internet
    4) Run the fixvundo.exe tool downloaded above and save the log
    5) Immediately reboot in normal mode and run the fixvundo.exe tool again. Save the log.
    6) Immediately reboot again into normal mode and now reconnect your cable to the internet.
    7) Open a browser and come back here and post your logs from running fixvundo. Also tell me how these steps went. Any problems?
     
  3. wubbazzie

    wubbazzie Private E-2

    sorry it's taken me so long to get back to you. I tried using the symantec trojan.vundo tool but when I ran the scan it told me that it couldn't find any trace of virtumonde on my computer. However I ran Microsoft Antispyware later and it said that it still found it on my computer. I'm really confused. Here are the logs from when I ran the symantec thing in safe mode:

    Symantec Trojan.Vundo Removal Tool 1.4.0
    The process "winlogon.exe" contained a viral thread (0000023C). The thread was terminated.
    The process "winlogon.exe" contained a viral thread (00000248). The thread was terminated.
    The process "winlogon.exe" contained a viral thread (0000024C). The thread was terminated.
    The process "explorer.exe" contained a viral thread (00000300). The thread was terminated.
    The process "explorer.exe" contained a viral thread (00000304). The thread was terminated.

    C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir: (not scanned)
    C:\System Volume Information: (not scanned)

    Trojan.Vundo has not been found on your computer.

    And here's the log from when I ran it in normal mode:

    Symantec Trojan.Vundo Removal Tool 1.4.0
    The process "winlogon.exe" contained a viral thread (000003BC). The thread was terminated.
    The process "winlogon.exe" contained a viral thread (000003C8). The thread was terminated.
    The process "winlogon.exe" contained a viral thread (000003CC). The thread was terminated.
    The process "explorer.exe" contained a viral thread (00000578). The thread was terminated.
    The process "explorer.exe" contained a viral thread (0000057C). The thread was terminated.

    C:\System Volume Information: (not scanned)
    registry: HKEY_CLASSES_ROOT\MSEvents.MSEvents (key deleted)
    registry: HKEY_CLASSES_ROOT\MSEvents.MSEvents.1 (key deleted)


    Trojan.Vundo has not been found on your computer.



    If I'm doing something wrong let me know.
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post a HijackThis log as an ATTACHMENT.
     
  5. wubbazzie

    wubbazzie Private E-2

    Here are the logs that I posted as attachments. Sorry about that.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please post a HijackThis log not the Vundo logs.
     
  7. wubbazzie

    wubbazzie Private E-2

    Here's the Hijackthis log
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the instructions in the following thread: thread:
    Running Ewido Security Suite


    Then post the Ewido log and a fresh HJT lig when completed with the above.
     
  9. wubbazzie

    wubbazzie Private E-2

    Alright here are the logs you asked for. The first one is for ewido and the second one is for hijackthis.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You have HijackThis installed incorrectly, please reinstall HijackThis to C:\HJT.

    Also that log appears to be from Safe Mode. After you have reinstalled HijackThis post a fresh log from Normal Mode.
     
  11. wubbazzie

    wubbazzie Private E-2

    urg, thanks for your patience. I'm trying to get this right. Here's the hjackthis log form normal mode.
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the instructions in the following threads:
    How to view hidden, system files & folders!

    Searching for Hidden Files on WinXP


    Please make sure System Restore is OFF.

    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at.

      it should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\mljgf.dll
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\fgjlm.*
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a fresh HJT log from normal mode.
     
  13. wubbazzie

    wubbazzie Private E-2

    Ok here's the new hijackthis log
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You can unistall Viewpoint Manager and Symantec Security Center using Add or Remove Programs in the Control Panel.

    If there is no entry for Symantec Security Center then do the following:

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to SymWMI Service or SymWSC ... right-click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config' button, and then the 'Misc tools' button ... select 'Delete an NT Service' ... copy/paste the following into the box that opens, and press "OK":

    SymWMI Service or SymWSC (Whichever you found above)

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Reboot your system and post a fresh HijackThis log.

     
  15. wubbazzie

    wubbazzie Private E-2

    here's the new hijackthis log
     

    Attached Files:

  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean. How is your computer running?
     
  17. wubbazzie

    wubbazzie Private E-2

    It's running great! Thank you so much for your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds