Troajn.Vundo Removed?

Discussion in 'Malware Help (A Specialist Will Reply)' started by tubbsbright, Aug 9, 2008.

  1. tubbsbright

    tubbsbright Private E-2

    Hi all,

    I caught a lil' Vundo virus doing something naughty (torrents) and I think I got it removed, but I'm not totally sure. My story so far...

    1. Windows Defender catches and blocks "trojan:win32/vundo.gen!h"
    2. I install BitDefender Trial, it blocks/deletes trojan.vundo.FEV on various instances.

    (up to this time the computer has been running OK...Firefox crashes when I close it out and my screen resolution/monitor zoom is a bit funky when I reboot, but there haven't been any pop-ups or anything too weird.

    3. I ran all the step in the Vista cleaning procedures...here are my logs.

    Do I still have it? Did the Vista cleaning remove it? Here are the first 2 logs. 2nd 2 to follow.

    THanks in advance for any help.
     

    Attached Files:

  2. tubbsbright

    tubbsbright Private E-2

    2nd 2 logs.
     
  3. tubbsbright

    tubbsbright Private E-2

    Try that again with the attachments this time.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing much of anything significant....let's clean up a few things.

    Please disable the guest account in user accounts if you haven't already.

    Use windows explorer to find and delete:
    C:\ProgramData\BM1394a746.txt
    C:\ProgramData\bm1394~1.xml
    C:\ProgramData\WildTangent

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me what issues you are still having.
     
  5. tubbsbright

    tubbsbright Private E-2

    Re: Trojan.Vundo Removed?

    Thanks for writing back....

    I deleted those files, and ran the fixME.reg thing.

    I haven't seen anything on Bitdefender scans since I ran all those steps from the ReadMe- but the PC is still a little funky:

    1. iTunes started giving me this message "ipodservice module stopped responding" ((that's OK...Im sick of itunes and ready to try Foobar))

    2. Firefox still crashes when I close it sometimes (crash report window comes up.-not a big deal)

    3. and the zoom on the monitor seems to be different everytime I restart. (havent tried to reinstall video driver yet)

    All in all its up and running fine..just those few annoying quiggles. I'll keep you posted if I find anything more regular. Also, bitdefender is new to me and I blocked some fishy stuff: wermrg.exe, winlogon.exe, some svchost.exe's, .\system(?)
     
    Last edited: Aug 10, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not sure what you may have stopped with bitdefender ....some may be legit. I would suggest that you post in the software forum to explore the other issues.

    If you are not having any other malware problems, it is time to do our final steps:
     
  7. tubbsbright

    tubbsbright Private E-2

    Done, done...and d--woops. I saved ccombo fix to the desktop but didnt install it there- I'll have to reset the folder settings manually.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds