Stubborn VUNDO

Discussion in 'Malware Help (A Specialist Will Reply)' started by hunnybakedham, Nov 30, 2005.

  1. hunnybakedham

    hunnybakedham Private E-2

    Hi everyone,

    I know this is a subject that has been done to death and has many 'Solutions' (SNORT) too bad i have spent the last couple of days trying all of them and i am still infected.

    I have VUNDO, sigh, as Symantec was nice enough to tell me but it cant do anything about it, I tried the symantec tool (a dozen times hoping for the best) but it either said it was cleaned or that i didnt have it at all. TrojanHunter cleaned out a bunch of other crap i didnt know i had but didnt touch the Vundo. I have tried the methods here but they didnt work either. i now have all the damn software you can throw at these things and still have VUNDO..........

    I am at the end of my patience here guys please help, what am i missing???? it just keeps reinfecting no matter what i do. Give it to me in idiot terms so i cant screw it up, im hoping it has been my own idiocy than a trojan i cant remove......

    I have attached my Hijackthis! log so hopefully someone can help my poor little PC
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download LSP-Fix

    After download is complete, Run LSP-Fix

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    (Note: If the file aklsp.dll is already in the remove section, then just click FINISH.)


    Now, please look in Add or Remove Programs for the following and Uninstall them if found:

    VBouncer

    SpySpotter



    Now, please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  3. hunnybakedham

    hunnybakedham Private E-2

    Vundo free, but slower than a slug on valium

    ok, had a Vundo prob, think i got rid of that sucker and a few others i didnt know about, Thank you spysweeper, but now my PC is running like a slug on valium. when i try to open anything it hangs and takes forever, if i hit Ctrl+alt+del when its hanging it takes a few seconds and it opens like nothing was the matter.... Did i miss something to make it run so slowly??

    BTW I have a celeron 1.8g cpu
    256MB RAM
    120g HDD
    a pissy 64mb vid card (it was free......lol)

    and it usually is pretty quick.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please stay in one thread, I have merged your new thread with your previous thread so please post in here from now on. Let's continue with the fix...

    Download this trial version of Ewido Security Suite

    • First, please download and run CCleaner to clean temp files, cookies, etc; to make the log shorter.
    • Install ewido security suite
    • When installing the program, under "Additonal Options" uncheck..
      • Install background guard
      • Install scan via context menu
    • Launch ewido, there should now be an icon on your desktop, double-click it.
    • You will need to update ewido to the latest definition files:
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    If you are having problems with the updater, you can use this link to manually update ewido. Ewido Manual Updates

    • Once the updates are installed, exit Ewido.
    • Now print the below instructions or save them locally because I want you to have all browsers closed and also have no connection to the internet (unplug your cable) while doing the below:
    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report[/size][/color]
    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    • Reboot into normal mode and reconnect to the internet.
    Once your machine reboots please attach the report from Ewido along with a fresh HJT log from normal mode.
     
  5. hunnybakedham

    hunnybakedham Private E-2

    all done,

    here are the logs
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Did you complete post #2? If not please run Spy Sweeper as requested in that post and attach the log with a fresh HJT log.
     
  7. hunnybakedham

    hunnybakedham Private E-2

    i did everything you told me to :) im a good little soldier lol
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Can you attach the log from Spy Sweeper? If you cant find it, get the latest updates and run it once more to confirm everything was removed then attach that log.
     
  9. hunnybakedham

    hunnybakedham Private E-2

    here is the log from spy sweeper
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thats the whole log? Go back and make sure you have the latest definitions "576" and then run another full sweep. We need to confirm everything was removed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds