trojan vundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by iLLmatic, Jan 31, 2006.

  1. iLLmatic

    iLLmatic Private E-2

    this computer is currently running windows xp service pack 2. i went through step by step per 'ask before posting' sticky. i could not boot into safe mode when i ran the programs, and when i ran the two online anti virus programs they picked up no significant problems, but my mcafee anti virus program keeps on telling me i have the trojan vundo virus. so i looked through special procedures and tried to run the program you guys suggested and when i ran vundo fix as a task it disappeared and never came back. any help would be appreciated. i went ahead and uploaded the bit scan, panda scan, and hijackthis, logs.

    Shaun
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for SaveNow and uninstall if found.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\system32\sstqn.dll (file missing)
    O20 - Winlogon Notify: sstqn - C:\WINDOWS\system32\sstqn.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):

    C:\WINDOWS\system32\sstqn.dll

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. iLLmatic

    iLLmatic Private E-2

    hey whats up. appreciate your time your spending doing this, anyhow i went to symantec and ran their trojan vundo removal tool. i did as you requested and i have a fresh hijackthis log file, thanks for your help.

    Shaun
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The steps I gave you would have fixed the problem as the Vundo infection was already inactive. The Symantec tool rarely works and in many cases does not find the problems at all. We have special removal procedure for Vundo that always work. See the stickies.

    At anyrate, your problems seem to be resolved. Is everything working okay now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds