Trojan.Vundo.B help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by FAAT, Oct 27, 2005.

  1. FAAT

    FAAT Private E-2

    I have been getting a Norton Antivirus Virus Alert for Trojan.Vundo.B that will not go away no matter what I have tried.

    Object name: CC:\\WINDOWS\system32\rqrss.dll.

    I have updated and ran Adaware, Norton, Microsoft Spyware, Spybot, CCleaner. They locate the virus, say it cleans it however the red pop up virus alert never disappears.

    My computer specs are: XP Home Edition
    I have a Mobile Intel Celeron M, 1400 MHz
    System Memory 480 MB
    BIOS Size 512KB
    Hewlett-Packard hp pavilion ze4900

    I read another posting for the same virus, but not the same Object name. Any guidance would be most appreciated!
     
  2. FAAT

    FAAT Private E-2

    My apologies. I also tried the Symantec FxVundoB.exe tool with no luck as well. Currently My System Restore has been turned off, and my hidden files are now available for view.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you did not run the newer tool.

    These steps must be run exactly as specfied.

    1) Download this Symantec Trojan.Vundo Removal Tool to a location where you can find it later
    2) Make sure you do not run anything but what is specified. DO NOT OPEN any browsers during this process below so print or save these unstructions locally so you know what to do while offline.
    3) Boot into safe mode and physically unplug your cable to the internet
    4) Run the fixvundo.exe tool downloaded above and save the log
    5) Immediately reboot in normal mode and run the fixvundo.exe tool again. Save the log.
    6) Immediately reboot again into normal mode and now reconnect your cable to the internet.
    7) Open a browser and come back here and post your logs from running fixvundo. Also tell me how these steps went. Any problems?
     
  4. FAAT

    FAAT Private E-2

    I have been able to proceed as far as #4 (Run the fixvundo.exe tool downloaded above and save the log). The folder Vundofix is on my desktop. Opening the folder twice I come to the only thing I believe I am to use which says killvundo.bat. I can agree to the first pop, however the second pop wants me to type a file path. I am not sure what step I might be missing. My apologies for causing more work on your part.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your first message, the filepath is C:\WINDOWS\system32\rqrss.dll
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait.....you are not following my instructions! Killvundo.bat as nothing to do with the Symantec tool. That is a different procedure. Run what I gave you.
     
  7. FAAT

    FAAT Private E-2

    I was able to complete the process and the virus is gone. Many thanks for your help and time. Attached is the first log, will attach the second separately as said file together is too large.
     

    Attached Files:

  8. FAAT

    FAAT Private E-2

    It is stating the 2nd log is too large. I am not sure I understand as it is the same as the first log. If you would still like to see it, please advise another way to attach. Again, many thanks for your help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not posting logs! You are posting screen snapshots.

    The second log should not be the same as the first if the problem was fixed in the first run. The second run should show clean.

    If you are not having anymore problems, I do not need anymore logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds