I think I HAD Vundo. Help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by cbpsykeval, Apr 6, 2006.

  1. cbpsykeval

    cbpsykeval Private E-2

    I followed all of the steps in read & run me. The only thing that I didn't do was save the bitdefender log. However, there were no malicious files found. My computer is less than 4 days old. I was running Norton Internet Security when I started receiving messages saying that Beagle Virus and Bootworm were on my machine. Then I would get a popup that said I was unprotected (either from WinAntiVirus Pro or SpyProtection). That's when I began your process. There was not any malware in the add/remove programs. The adaware removed 5 "negligible files." Active scan detected 3 files. The vundo fix found and deleted several files. All other programs found nothing. Attached are the vundo fix log, the active scan log, and the HJT log. Can you tell me if I still have any remnants of this beast?

    Also, I'm currently making progress is following your step action process to make my PC safer (I ditched Norton).
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Well according to your log you still have some Norton stuff installed. Are you sure you uninstalled all of it. See the below from your HJT log:
    Also your Sun Java version is significantly out of date. Download and install the latest version from http://java.com/en/ and then uninstall the old version.

    Your logs are clean but you must get a new AV and a firewall installed ASAP (all part of the How to Protect yourself from malware! thread you referred too.
     
  3. cbpsykeval

    cbpsykeval Private E-2

    chaslang: thanks for the quick response. i had actually fixed all of those problems prior to reading this. i'm happy to see that vundo and other problems are gone.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Specifically which problems are you referring to and how did you fix them. You cannot simply fix O23 services by just having HJT fix the lines. In most cases this will not fix them unless the services have already been stopped and disabled and the files are already deleted.
     
  5. cbpsykeval

    cbpsykeval Private E-2

    I ran the HJT prior to realizing that Live Update and the WMI were still installed on my computer. I removed them using add/remove. I also had not completed the steps for making my computer less susceptible to malware, so I updated sun java after running HJT. Attached is updated log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. cbpsykeval

    cbpsykeval Private E-2

    Everything seems to be working. I completed the entire process. My only complaint is that avast seems to be slower than Symantec Corporate AV. I'm not sure if that's an incorrect perception, if the program's scanning more files, or if Symantec was just better. Thoughts?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avast may be scanning more files. In reality if you discuss Symantec versus Avast with most users on this site, you will find that Symantec is frowned upon. A couple reasons are that just having it on your system is a tremendous burdon on system resources which slows down all PC performance and even starting up is slower. Also Symantec seems to have problems finding lots of malware and when it does find various malware issues it does a poor job of removing the malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds