Help with trojan.vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by spikael, Jul 14, 2007.

  1. spikael

    spikael Private E-2

    Hi. The main problem seems to be the trojan.vundo. Our Norton Antivirus detects the treat and so we have continuous pop-ups from norton telling us of thes problem. I have previously 'fixed' this by simple putting the infected file on the exclusions list, as the popups significantly slow the computer. I have complete the steps in the malware removal guide and this is what i have come up with. Attached are logs and picture of norton's alert.

    + from ccleaner a program "smgr" (mgrs.exe) often reappears after its removal.

    Any help would be greatly appreciated.
     

    Attached Files:

  2. spikael

    spikael Private E-2

    other logs
     

    Attached Files:

  3. spikael

    spikael Private E-2

    And the screenshots of the problems just in case im talking about the wrong thing
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Development Kit 5.0 Update 8"
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0 Update 8
    Reboot and install:
    Java Runtime 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Now attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  5. spikael

    spikael Private E-2

    thanks,
    here are the new logs
     

    Attached Files:

  6. spikael

    spikael Private E-2

    and the other log
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run CCleaner and delete all those temp files ....under all accounts.
    How many people use this computers? And I assume you are doing this as an administrator.

    Use windows explorere to find and delete:
    C:\WINDOWS\UNIQ
    C:\WINDOWS\system32\wyadd.tmp

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach new logs for:
    ShowNew
    GetRun
    HJT
     
  8. spikael

    spikael Private E-2

    I ran all as said. We have 2 accounts, and I am doing this through the administrator.
    Norton isnt detecting the trojan anymore so it may have been cleared up:)

    Here are the new logs.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One last thing to do:
    Download this trial version of Ewido Anti-Malware
    • If you have CCleaner installed ( from the READ & RUN ME FIRST Before Asking for Support thread) then run it before continuing. Otherwise use Internet Explorer's Tools menu, Internet Options, General tab, and select Delete Cookies. This will make the Ewido scan faster and the log smaller.
    • Also for you Norton/Symantec users, if you use the Norton Protected Recycle Bin, you should first empty it to avoid getting monster size log that cannot be posted. Use the procedure in this link: Emptying the Norton Protected Recycle Bin
    • Install Ewido Anti-Malware
    • Double-click the icon on Desktop to launch Ewido
    • Now update Ewido to the latest definition files.
      • On the top of the main screen click Shield
      • Click the word active to change it to inactive
      • On the top of the main screen click Update.
      • Then click on Start Update.
      If you have any problems with the updater, you can use the below link to manually update Ewido
      http://download.ewido.net/ewido-sign...ll-current.exe
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    • Now click Scanner & select the Scan tab
    • Click Complete System Scan to begin scanning.
    • If any infections are found you will prompted, then select "Apply all actions"
    • Once finished, click the Save report button, then click Save Report As and save it to your desktop or someplace else that you know you will be able to find it later to upload here as an attachment.
    Be patient while waiting for the scan to complete. It would be best to not do anything else while scanning as it would only slow down the scan and could potentially interfere with some aspects of the scan.

    After the the scan has completed and you have saved your log. Reboot your PC!


    Now attach the Ewido log.
     
  10. spikael

    spikael Private E-2

    rito,
    here is the log
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me how things are running and if you are having any problems.
     
  12. spikael

    spikael Private E-2

    Fine as far as I can tell. It still is quite slow on the start up but thats probably just the computer.
    Thank you so much for your help.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may wish to install a startup manager:
    Startup.

    Otherwise...Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds