help with trojan.vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by DaddysLtlGirl, Oct 15, 2005.

  1. DaddysLtlGirl

    DaddysLtlGirl Private E-2

    My Norton picked up the Trojan.Vundo virus and is unable to quarantine, remove or repair it.
    The object name is C:\WINDOWS\System32\vtsqn.dll
    I have followed the instruction in the Read and Run Me First thread and in the Virtumonde aka Trojan Vundo Fix w/ Tool. I have downloaded the FixVundo tool off of Symantec and it does not detect it on my system, but Norton virus scan does. I have turned off System Restore and have enabled all hidden folders. I am worried about Enabling viewing of hidden files, system files and file extensions. When I uncheck that box, it tells me that if any of the files are deleted my Windows may not run properly. I don't want to screw anything up if I delete the file.
    I read the whole sticky Virtumonde aka Trojan Vundo Fix w/ Tool and I don't quite understand it that much ... was wondering if someone could help me.
    Any help would be great ... Thanks!
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  3. DaddysLtlGirl

    DaddysLtlGirl Private E-2

    Sorry, for the delay. I had my computer off all day ... annoying Norton security risk screen.
    Here's my log:

    Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jan 23, 2006
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You have HijackThis install incorrect. Please install HijackThis as request previosly in Downloading, Installing, and Running HijackThis.

    Never post a HijackThis inline always post as an ATTACHMENT, like I previously requested in my first reply.

    Your log shows no signs of haing completed our standard cleaning procedure.

    Please follow the instructions in the following threads:
    How to view hidden, system files & folders!

    Searching for Hidden Files on WinXP


    Please make sure System Restore is OFF.

    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at.
      it should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\vtsqn.dll
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\nqstv.*
    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\vtsqn.dll
    O20 - Winlogon Notify: vtsqn - C:\WINDOWS\system32\vtsqn.dll
    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a fresh HJT log from normal mode.
     
  5. DaddysLtlGirl

    DaddysLtlGirl Private E-2

    Sorry, I am new to this whole HiJack thing. I think I got it now.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You didn't run the Vundo fix I posted. Run those steps and post a fresh HijackThis log.
     
  7. DaddysLtlGirl

    DaddysLtlGirl Private E-2

    OK, I followed the instructions for VundoFix and it worked.

    Thank you so much for your help.

    Here's my new log:
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean. How is your computer running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds