Vundo?

Discussion in 'Malware Help (A Specialist Will Reply)' started by MEDO11, Aug 29, 2008.

  1. MEDO11

    MEDO11 Private E-2

    hi this is my first post, and i hope we can solve this problem...

    problems started some 3 hours ago...i tried to install a program, and zonealarm asked me to blocke it, and the idiot that i am i didnt let him, so now im infected.
    Start menu doesnt have my computer, documents, all programs, no control panel, cant do nothing. And in normal mode c: and d: drives arent listed.
    I did all of your steps in malvare removing guide, and here are the reports.
    p.s. all of this was done from safe mode which is working.
     

    Attached Files:

  2. MEDO11

    MEDO11 Private E-2

    and the mgtools log...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way out of date with your MGtools log. Please download the current version given in the READ & RUN ME and attach a new log. Where or when did you get the copy you used?

    However I do not think you are having malware problems. It looks like you had installed some kind of Start button replacement software ( ViOrb ). Also you have loads of things including ViOrb trapped in MSconfig. Are you using CCleaner or anything else to control these startups that put them all into MSconfig registry keys.
     
    Last edited: Aug 30, 2008
  4. MEDO11

    MEDO11 Private E-2

    here are the updated mglogs...i also put a picture of what my desktop looks like with this infection. Im sure its a virus or smthing just not sure what. VIRUS ALERT pops up next to the closk, and all my programs and other things are unavalible from start menu.
    i did have some vista transfromation pack instaled, but that was months ago...also i use ccleaner few times a month, and use one of your startup cpl programs to clear my start up programs...

    i thought it could be smitfraud but smitfraudfix didnt help me...now im kinda desperate. Unfortunatelly reinstalling windows isnt an option, even as a last resort...

    any help would be apriciated!!
     

    Attached Files:

  5. MEDO11

    MEDO11 Private E-2

    this is my smitfraud check repport

    p.s. i posted another message, but it said it needs to be aproved by an admin....
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs from safe boot mode are not showing any problems. Can you please try to get some logs from Normal Boot mode using the user account that actually has a problem.
     
  7. MEDO11

    MEDO11 Private E-2

    wasnt able to run tests in normal mode before. Sas didnt want to start. Now i done it, and it all got cleaned. Ill post u updated versions of mg logs...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post the other logs too for this user account. The other logs you posted were not from the correct user account.

    When did you install Sunbelt's Software? After the problems began? Is it a paid version? If not, uninstall it.
     
  9. MEDO11

    MEDO11 Private E-2

    kk here are the logs for sas and mbam...im having problems with combofix, it gives the blue screen of death on stage 2.

    i instaled sunbelts software after infection....gone now.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay skip ComboFix but you are way out of date with SAS. You should uninstall it and download and use the current version from the link in the READ & RUN ME.

    How are things working?
     
  11. MEDO11

    MEDO11 Private E-2

    k ill download it and install again(thought it would autoupdate, so i didnt)

    things are great for now,like they were before infection i just wanted to go thru analys/hijackthis and clean up the junk that may have been left over...

    Thanx for all your help chaslang, not just with this, your malvare removal guide saved my *** countless times :drink
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Now you need to do final steps which include getting properly protected which you are not!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds