Trojan.Vundo - Thanks For Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by MKUltra81, Aug 13, 2008.

  1. MKUltra81

    MKUltra81 Private E-2

    Problem found in:

    Malware Bytes

    Trojan.Vudo

    Registry Key

    HKEY_current_user\software\contim


    Hit remove all selected items and got an error when the log tried to pop up saying that I didn't have permission to access the the file. The normal pop up that says the threat was removed and the log was saved. The threat did show up in quarantine but MB says I still don't have permission to open logs when I try to double click one of them.


    Proceeding with R&RMF, will post results shortly.

    Thanks for help in advance!
     
  2. MKUltra81

    MKUltra81 Private E-2

    Posting Logs
     

    Attached Files:

  3. MKUltra81

    MKUltra81 Private E-2

    Many thank!
     

    Attached Files:

  4. MKUltra81

    MKUltra81 Private E-2

    I forgot to mention, MalawareBytes didn't give me any trouble with accessing my logs anymore...odd?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show any malware. You do need to uninstall the below old Sun Java versions:
    Java(TM) 6 Update 4
    Java(TM) 6 Update 6

    And what is in the below folder which should not exist?
    C:\WINDOWS\system32\drivers\system32

    Also what are the below files for?
    Code:
    2008-08-09 21:38 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
    2008-08-09 21:38 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
     
  6. MKUltra81

    MKUltra81 Private E-2

    Old javas are now uninstalled.

    When I moused over the contents of C:\WINDOWS\system32\drivers\system32 it was a bunch of stuff that identified itself as Microsoft Automatic Updater and it's accompanying DLLs and drivers. When I got the properties of the MAU .exe it said Microsoft Corporation, file version 5.4.3790.5512 (xpsp.080413-0852).

    I was not able to ascertain the origin or what program x2.64 or x.264 belonged to. No information was provided when mousing over or in their properties.

    Many Thanks!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just ignore this folder.

    It more than likely is part of SUPER c Version 2008.bld.32 which you installed.


    Since your logs are clean, we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. MKUltra81

    MKUltra81 Private E-2

    Fixme.reg successfully run.

    Combofix uninstalled successfully.


    Something odd has happened when I try to toggle system restore. When I hit properties after right clicking 'my computer' there is no system restore tab. To try and resolve this I went into system restore and hit the hyperlink for adjusting system restore settings and it takes me to a 'microsoft automatic updates' tab along with all the other standard system tabs.

    Any ideas/help are much appreciated!
     
  9. MKUltra81

    MKUltra81 Private E-2

    I restarted and the system restore tab is back. Prior to restarting I scanned or cleaned with all updated versions of: a-squared, avg, ccleaner, MBAM, SBS&D, and SAS. Everything came through clean. So having done that should I be able to toggle now and be confident I haven't re-infected with restarting?

    Thanks in advance!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your fine. Just continue!


    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds