Help really needed with Vundo!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mbens07, May 16, 2008.

  1. mbens07

    mbens07 Private E-2

    Hey guys any help would greatly be appreciated. Have no idea how to get rid of this Vundo virus and have spent many hours and every idea i could think of to get rid of it. Below you will find the requested logs. Thanks again for your help.
     

    Attached Files:

  2. mbens07

    mbens07 Private E-2

    here is the other log requested. Hopefully someone can help me!
     

    Attached Files:

  3. abri

    abri MajorGeek

    Hi mbens07,
    Welcome to Major Geeks!

    Sorry it took us a bit to get to your thread. You got most of the malware out with your scans. There are a few things remaining and a few cleanup items that will help your computer in general and make it less vulnerable.

    Please do the following.


    1) Please disable your guest account if this hasn't already been done.

    2) Open your Windows Live Messenger, go to Help -> Customer Experience Improvement Program and turn it off. Then go to C:\ and delete all the files with this structure: sqmnoopt12.sqm


    3) Go to add/remove programs and uninstall the below:

    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 5


    4) Reboot after uninstalling the above.

    5) Install the current version of Sun Java from: Sun Java Runtime Environment

    6) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    7) Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {EFA34E6A-BF42-4667-999C-FD4C21E105A4} - C:\WINDOWS\system32\iifeeCSl.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O20 - Winlogon Notify: iifcYRKE - iifcYRKE.dll (file missing)

    After you click fix, just close hijackthis.


    8) Download and install Erunt. Use it to create a backup of your registry.

    9) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the File Type type is set to "all files" Once you have saved it, look for it on your desktop and when you find it, double-click it and allow it to merge with the registry.
    10) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the 'Execute' button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt


    11) Now run CCleaner at the default setting with the Windows tab as the top one.

    12) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  4. mbens07

    mbens07 Private E-2

    Hey Abri

    Thanks alot for your help. I don't mind waiting, i understand you have alot of other problems to deal with and i am just grateful you had the time to look over my logs. Below i have attached the new avenger log and MGlog. Hope it all looks ok and thanks again for the time spent helping me.
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi mbens07,

    Your logs look good. If you're not having any further problems, please do the final cleanup instructions:
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds