Infected w/ Vundo & others - am I clean

Discussion in 'Malware Help (A Specialist Will Reply)' started by momeeyore, Jul 9, 2008.

  1. momeeyore

    momeeyore Private E-2

    Hello. I have been infected with multiple Trojans with the most notable being the Vundo variant. I have run through the entire README process and believe I followed every step to the letter. I am not sure if I am actually clean yet and was hoping for someone to look at my logs.

    History:
    Back in end of May (25-May), my daughter was logged on to her account on the PC (Brit's space) looking at guitar tabs and playing in myspace. She called me to the PC when she started getting non-stop pop-ups about the PC not being protected but the messages were not from any protection software I installed. I realized then that I had a big problem but could not even get to your site because the virus(s)/trojan(s) had taken over Internet Explorer.

    I have one other home PC which I used to download the software packages in the cleaning process and burned to a CD to use on the infected PC. Even after moving them from the CD to the hard drive, some of the programs would not even launch. I finally used your renaming trick and was able to get through the process but after rebooting was still having issues. Because it was Memorial Day Weekend, I gave up and completely unplugged the PC (both the ethernet cable and the power cord).

    I just now am getting back to this PC (which is the newer of the 2 that I have so I really would like to get things fixed). I ran all the scans overnight and the logs are attached (9-July). The scans look better than when I ran them in May (although in some cases, I could not save those May logs for comparison because even notepad was having issues because of the infection.)

    One last thing. My daughter did have admin rights on her user account (yes, I know this was stupid. Don't worry, I am kicking myself!!). I did change this account to be limited as soon as realized what happened back in May which was how it was set up when I ran the scans from my user account (Mom's space).

    I hope this is enough information to get started but not too much to waste your time. I appreciate any help that can be given!!!
     

    Attached Files:

  2. momeeyore

    momeeyore Private E-2

    Here is the last of the logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    Please find and delete:
    C:\WINDOWS\system32\ytucegpi.tmp

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Are you having any malware issues still?
     
  4. momeeyore

    momeeyore Private E-2

    I removed the file and uninstalled Windows Messenger.
    Everything appears to be back to normal on my user account and my daughter's account.

    Thank you, thank you, thank you for checking my logs.
    You have alleviated my fears that things are still lurking and hiding on me :)

    Since things look good, I was going to finish with step 4 to toggle system restore and step 5 to put the right things in place to prevent future problems.
    If you would suggest any other steps, let me know.

    I can't say it enough. Thank you for your time!!! And thanks to all the experts who contribute and support this forum!! You all are amazing!!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your welcome......If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox ( or whatever you renamed it to) and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!

    You might want to keep MalwareBytes as a backup ( and watch the torrent downloads ...;)).
     
  6. momeeyore

    momeeyore Private E-2

    I have what may be a stupid question so I decided to bundle it with my other question that is definitely stupid and hopefully these will be the only ones. :eek:

    I just unistalled combofix and it went through successfully; however, McAfee popped a PUP detected warning message when I did this with the Name: RemAdm-ProcLaunch!171 and Location: C:\327882R2FWJFW\psexec.cfexe.
    It then gives me the 3 options: remove, trust, or close alert.

    Don't want to screw anything up at this point so I am leaving the window up for now why I post.

    (And my second definitely stupid question, I have no idea what torrent downloads are (I bet this one is showing my age). You are not responsible for educating me but if we are downloading them, I don't know what they are or why we are).
     
    Last edited: Jul 9, 2008
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First question .....many anti-virus programs have issues with ComboFix....you can tell McAfee to remove them as it is no issue and we are done with COmbofix.

    Second ....torrents are large files that are compacted for download speed ....they can be anything from files to movies to programs ....which can mean they can be "illegal" downloads.

    Other P2P ( peer to peer ) programs such as Bearshare/ Limewire / etc can also be possible entry points for malware. :)
     
  8. momeeyore

    momeeyore Private E-2

    Thanks for the explanations!!

    I finished the steps up to and including enabling/disabling system restore without any problems.

    I am now just walking through the last step(s) of making sure my PC gets protected. Appreciate all the help. I think you are done with me for now but if anything happens going through the protection steps that feels like malware, I'll let you know. But I am staying positive that we are done!!!

    :-D
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome .....let me know if you have any other problems. And don't be shy about asking questions in the software forums. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds