Trojan.Vundo sticking around.. Please assist

Discussion in 'Malware Help (A Specialist Will Reply)' started by noonway, Apr 21, 2009.

  1. noonway

    noonway Private E-2

    I have a laptop that my Symantec Endpoint Protection has found the Trojan.Vundo on it. I followed the basic malware removal guide twice in a three day period and every day or two since Vundo comes back and is detected again by Symantec. Please assist in helping me remove.

    Thanks in advance... Awaiting your instructions.
     
  2. noonway

    noonway Private E-2

    Scanning logs are here...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\All Users\Application Data\yadebene
    c:\documents and settings\All Users\Application Data\zadoleso
    c:\documents and settings\All Users\Application Data\vewuvepo
    c:\documents and settings\All Users\Application Data\zofufelo
    c:\documents and settings\All Users\Application Data\zukuyepu
    c:\documents and settings\All Users\Application Data\wutakizu
    c:\documents and settings\All Users\Application Data\rurenami
    c:\documents and settings\All Users\Application Data\jujivane
    c:\documents and settings\All Users\Application Data\jubawiro
    c:\documents and settings\All Users\Application Data\zebosewo
    c:\documents and settings\All Users\Application Data\zesuvizi
    c:\documents and settings\All Users\Application Data\migogaso
    c:\documents and settings\All Users\Application Data\jahimaga
    c:\documents and settings\All Users\Application Data\guwawefa
    c:\documents and settings\All Users\Application Data\tivuzale
    c:\documents and settings\All Users\Application Data\piwinala
    c:\documents and settings\All Users\Application Data\neganosu
    c:\documents and settings\All Users\Application Data\pabinula
    c:\documents and settings\All Users\Application Data\wezuhobo
    c:\documents and settings\All Users\Application Data\mepazufo
    c:\documents and settings\All Users\Application Data\notetiki
    c:\documents and settings\All Users\Application Data\morazolu
    c:\documents and settings\All Users\Application Data\denakuja
    c:\documents and settings\All Users\Application Data\dejezibi
    c:\documents and settings\All Users\Application Data\yulofili
    c:\documents and settings\All Users\Application Data\vetariwo
    c:\documents and settings\All Users\Application Data\merahuro
    c:\documents and settings\All Users\Application Data\sodiluha
    c:\documents and settings\All Users\Application Data\fobunayi
    c:\documents and settings\All Users\Application Data\yuyugepu
    c:\documents and settings\All Users\Application Data\gosagure
    c:\documents and settings\All Users\Application Data\budabaze
    c:\documents and settings\All Users\Application Data\bahezefi
    c:\documents and settings\All Users\Application Data\jonojepu
    c:\documents and settings\All Users\Application Data\toyuwipi
    c:\documents and settings\All Users\Application Data\hawupopa
    c:\documents and settings\gramsey\Local Settings\Application Data\Fmofebasusevihe.bin
    c:\documents and settings\gramsey\Local Settings\Application Data\{0C045861-D949-44C6-9DFC-BEAE1EC35B47}
    c:\documents and settings\gramsey\Local Settings\Application Data\Kceyusobo.dat
    c:\documents and settings\gramsey\Local Settings\Application Data\ageliwoluwaruy.dll
    c:\documents and settings\All Users\Application Data\payafini
    c:\documents and settings\All Users\Application Data\masebeba
    c:\documents and settings\All Users\Application Data\tewiroyo
    c:\documents and settings\All Users\Application Data\gifigotu
    c:\documents and settings\All Users\Application Data\buponuvo
    c:\documents and settings\All Users\Application Data\robuzulu
    c:\documents and settings\All Users\Application Data\jedowifa
    C:\Documents and Settings\All Users\Application Data\sitisosa
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.

    Tell me what problems you are still having.
     
  4. noonway

    noonway Private E-2

    I dragged and dropped the script text file onto Combofix.exe and it started up, told me my virus software was running so I disabled the virus software and continued. But then a blue cmd window came up with a single period "." in the title bar. It's been sitting on that window now for 20 minutes and has shown no progress. Any suggestions?
     
  5. noonway

    noonway Private E-2

    I'm clean... Thanks for trying to assist but I had to get this done faster so when to bleepingcomputer.com and received assistance.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, good for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds