![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
My Windows Live OneCare detects that it has found potentially unwanted software "Trojan:Win32/Vundo.gen!A" and wants me to clean it. when finshed cleaning it promts for a restart and I am in the same boat again when the computer reboots. if there is anyone that can get me a detailed instructions on how to remove this and any other malwear would greatly help me thanks.
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Majorgeeks!
Run the below and attach the rewuested logs and then one of our malware experts will assist you in mopping up the remaining infection, Please follow the instructions in the below link and attach the requested logs when you finish these instructions. READ & RUN ME FIRST. Malware Removal Guide
__________________
Microsoft® MVP - Windows Expert ~ Consumer Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
here is the things you requested
|
|
#4
|
||||
|
||||
|
Now Disable Spybot's TeaTimer as requested in the READ & RUN ME
Java 2 Runtime Environment, SE v1.4.1_02 Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck After clicking Fix, exit HJT. Now download The Avenger by Swandog46, and save it to your Desktop.
Quote:
Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
this isnt showing up on the in the analyize this window that opens only the first two HKLM's you list are there. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Just continue on with the rest of the instructions ignoring that line that is no longer there.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
do i run Sun Java Runtime Environment after the boot up after avenger? then Ccleaner,C:\MGtools\GetLogs.bat file and attach the new C:\MGlogs.zip and log from Avenger?
|
|
#8
|
||||
|
||||
|
Yes you need to complete all steps in the order written.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#9
|
|||
|
|||
|
here are the logs
|
|
#10
|
|||
|
|||
|
after all you magic is done with fixing my computer what progam should i use for virus protection and pop up blocking? I have windows live and stopzilla are they worth keeping or should i go a different way?
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Please attach the requested log for Avenger. Not the Avenger program that you downloaded.
Windows Live and StopZilla are very low on my list of things to use.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
||||
|
||||
|
Do you have any idea what all the below new files are from? Are they from StopZilla
Code:
"C:\Documents and Settings\Owner\Local Settings\Temp\" 060835~1 Dec 25 2007 10362 "060835d4-c14d-44f7-bd6d-1aa60310c70e" 135c28~1 Dec 26 2007 10398 "135c286a-1a8e-4a22-a0d0-8d088497a377" 207a77~1 Dec 24 2007 10326 "207a77a6-7a60-4694-a6bd-838be3438704" 22300d~1 Dec 25 2007 10398 "22300de9-aa4b-4fc7-80e8-79fd4360d1d8" 259d76~1 Dec 25 2007 10398 "259d7654-b9f2-4727-8e58-8b9ca8f48ca6" 29cebf~1 Dec 25 2007 10326 "29cebfc1-3061-4dcb-9da6-25badf6deef3" 2b9123~1 Dec 25 2007 10362 "2b9123ac-e72e-4f03-b2f1-55fc1bad708a" 2dd967~1 Dec 25 2007 10398 "2dd967f7-3b31-4c2d-b25a-e0d8ad844539" 3f9a1b~1 Dec 26 2007 10398 "3f9a1b78-8f6d-4cea-84ae-04d8717eff1f" 43090d~1 Dec 26 2007 10398 "43090dd0-aee5-4d23-b03a-ed03d65c64bf" 6105a4~1 Dec 26 2007 10398 "6105a4fd-1f6a-4c1a-9e93-44506f4c8e3c" 618f4b~1 Dec 26 2007 10398 "618f4b3c-e62f-4ebb-b183-d2086a3d715e" 670fec~1 Dec 25 2007 10398 "670fec2a-5cf5-422f-95de-2ef70c87a07e" 6fc97a~1 Dec 25 2007 10398 "6fc97ae4-19c9-480e-9cd7-a0b9d7a27b77" 727845~1 Dec 25 2007 10398 "72784538-48ee-4efb-9d39-4a7edf147e11" 8f015b~1 Dec 25 2007 10398 "8f015b80-b0ee-4377-b44c-5c01fbbbcc4b" 9cc28f~1 Dec 25 2007 10398 "9cc28fbe-6dfb-49e6-b26a-8287b12b8749" 9f394c~1 Dec 25 2007 10398 "9f394ce3-7a82-492d-8ce5-3ec4ba028562" ada393~1 Dec 26 2007 10398 "ada39359-e1ed-4e41-8ae5-085faeffb202" b2992d~1 Dec 25 2007 10398 "b2992d28-40a5-49e0-b875-f75fe5c31661" b70e60~1 Dec 26 2007 10398 "b70e6060-0c8e-4393-a1fe-e1683439c1b3" b72646~1 Dec 26 2007 10398 "b72646cd-f9c9-45cd-a4f1-051c491a6124" c35df0~1 Dec 26 2007 10398 "c35df047-9588-4986-954e-e6d2fd3c059b" c7ad85~1 Dec 26 2007 10398 "c7ad8556-0810-40f6-85b8-1323cab83fb5" d6e644~1 Dec 26 2007 10398 "d6e6449b-2d61-4a81-a490-8289ca6e2171" d8c341~1 Dec 25 2007 10362 "d8c341e1-5b10-4dae-9986-19ec1dffc09e" ec6852~1 Dec 25 2007 10398 "ec685289-a554-40a4-95fc-f077ad18a0c0" f5ba33~1 Dec 25 2007 10398 "f5ba33cc-b3ef-4ce5-8b05-bc3add5b72bf" f8da3c~1 Dec 26 2007 10398 "f8da3c95-e0a0-4f5b-ab3d-c791db4d8140" ff3c4f~1 Dec 26 2007 10398 "ff3c4fc7-e846-4d12-a195-63930f0075ec" You said you have Windows Onecare Live! I do not see it installed! If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#13
|
|||
|
|||
|
i uninstalled windows onelive care when i first came on the site cuz it said not to have more than one virus protection program installed.
Also the new files maybe from avg everytime i reboot it says that i am now updated and secure. what program should i use for protecting my computer? on reboot stopzilla comes up with detection of trojans in register key HKLM\system\CurrentControlSet... saying it infection name is "CatchMe" |
|
#14
|
||||
|
||||
|
Quote:
Quote:
Did you read the link I gave you in my previous message? Quote:
Where do you have the combofix.exe file installed? You can run combofix /u from a command prompt to uninstall it but you need to have combofix.exe in your path or you need to give the fullpath in the command. When shown the disclaimer, Select "2"
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
Quote:
|
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Quote:
*well i dont know where they may be from then *no i just shut the computer down i had work in the morning *C:\Documents and settings\All Users\Doucuments |
|
#17
|
||||
|
||||
|
We requested that you download ComboFix to your Desktop. The command I gave you to uninstall it it will not work if it is not on your Desktop.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#18
|
|||
|
|||
|
so do i just re download it to my desktop or what do i have to do?
|
|
#19
|
||||
|
||||
|
You can move the file you already have to your Desktop or you can delete the one you have and redownload to your Desktop and then run the command to uninstall it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#20
|
|||
|
|||
|
alright thanks for everything. I will update you on how the computer is running soon, i am just busy with stuff right now. It seems ok just the page loading is kinda slow for being on a cable modem.
|
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Please help remove Trojan.Win32.Agent.akk | halljab | Malware Removal | 7 | 12-10-07 15:16 |
| Vundo Trojan, Hard to remove!!! | Tsavu8 | Malware Removal | 1 | 05-27-07 01:01 |
| Urgent! Can't Remove Trojan.Vundo | lostsoul_jr | Malware Removal | 5 | 10-09-05 18:00 |
| How to remove trojan.win32.agent.cs? | 92minutes | Malware Removal | 2 | 05-21-05 18:42 |
| Trojan Vundo - Can't Remove!!! | Leezza | Malware Removal | 27 | 03-23-05 15:25 |