virtumonde problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by garglesand, Oct 14, 2008.

  1. garglesand

    garglesand Private E-2

    Hi,
    I seem to have picked up the vundo virus. I ran through the cleaning process and it seemed to clear it, but a day later my AVG sometimes shows alot of trojan files in my /system32 folder to be healed. AVG still shows 3 changes to files when run too.
    I'm attaching logs as per the run me 1st page:


    Thanks for any help
     

    Attached Files:

  2. garglesand

    garglesand Private E-2

    And the mg logs:
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware issues....what exactly is AVG reporting?
     
  4. garglesand

    garglesand Private E-2

    Hi,
    Thanks for checking the logs. After running the described programs to get rid of vundo i was getting alot of avg alerts saying there were .dlls that needed healing. I think this could just have been it finding files that had already been healed as AVG seems ok now.
    I'm still getting AVG reports of changes:

    http://img.photobucket.com/albums/v702/Garglesand/avglog.jpg

    Last time I got the vundo (on my main PC) it was a real pain to get rid of, so I'm a little paranoid that this one seems to have been exterminated so easily
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look at your logs and you will see what all was found and removed. What you are seeing from avg is just changes to those files which is normal.

    If you are not having anymore malware issues, then:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you get a success message, then:
     
  6. garglesand

    garglesand Private E-2

    Yes, it worked.
    Cheers for help.
    Hopefully I'm clean now
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds