Virtumundo/ Trojan.Vundo/Antivirus2009 Popup

Discussion in 'Malware Help (A Specialist Will Reply)' started by geex_newbie, Jan 11, 2009.

  1. geex_newbie

    geex_newbie Private E-2

    Need help with Vundo Removal
     
  2. geex_newbie

    geex_newbie Private E-2

    Hi,
    My system runs on XP SP3. My antivirus/Firewall is Symantec Endpoint Protection. I started receiving Trojan.Vundo, Packed.Gen, Downloader notification by SEP and it usually quarantineds or deleteds the files. I started receiving (occasionally) Antivirus2009 popup (IE window-I always run FF). Sometimes my antivirus would get turned off automatically right after this notice: 'Trojan.Vundo activity noticed'.

    I ran all basic and cleaning steps as specified in these threads:
    http://forums.majorgeeks.com/showthread.php?t=35407
    http://forums.majorgeeks.com/showthread.php?t=139313

    I am not sure if the infection is completely gone. I am attaching the logs for your perusal. Thanks in advance for your help!
     

    Attached Files:

  3. geex_newbie

    geex_newbie Private E-2

    Here is the MG Tools log.
    Thanks!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a few things to clean up:

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\D
    C:\WINDOWS\system32\FIP
    C:\WINDOWS\system32\HDX
    C:\WINDOWS\system32\VIM

    Now reun CCleaner --> both the cleaner and the issues sections ( making sure you do the backup when prompted).

    Then download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me what issues you may still have.
     
  5. geex_newbie

    geex_newbie Private E-2

    Thanks a lot! I havent seen any popup since then. I will do as suggested this evening and get back to you.
     
  6. geex_newbie

    geex_newbie Private E-2

    Hi Tim,
    1.I deleted the mentioned folders from \system32.
    2.I ran ccleaner for both files and registry (backed up).
    3.I cleaned firefox using ATF Cleaner.

    I havent had any problems since I submitted the logs, and with your guidance I think I have eliminated the residual problems.

    Thanks a bunch!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware issues, then:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds