Vundo and other Malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jaypatron, Aug 17, 2008.

  1. jaypatron

    jaypatron Private E-2

    My computer has been operating extremely slowly. Most of the CPU usage has been hogged leaving me little CPU to work with. I always seemed to remove Vundo/Virtumonde from my system but it continuously seems to come back. It came back a few days ago and progressively worsened. After completing everything on the "READ ME & RUN FIRST" my computer seems almost back to normal, but still lags more than it should.

    I sincerely appreciate your help,

    Jay.
     

    Attached Files:

  2. jaypatron

    jaypatron Private E-2

    (and the MGLogs.zip compilation)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You logs are clean so it is not due to any remaining malware. It may be due to what you are running (like Roxio, McAfee, Active Desktop Calendar, PCbooster) and it is also due to what you are trying to run which is no longer there (Cold Fusion). The below may help a little.

    Uninstall SUPERAntiSpyware now since we are finished with it.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. jaypatron

    jaypatron Private E-2

    Hello chaslang. Thank you so much for the swift response. ComboFix was locked up for several hours on my computer at the 10 minute scan phase so I manually deleted the files, folder, and driver registry values corresponding to the ComboFix script you provided me with. After this I ran ComboFix again the way it instructs in the Read/Run Me thread and the log I'm putting up is from that scan. I successfully added fixme.reg to my registry and I also ran CCleaner and Getlogs.bat.


    However... I recently decided that my computer has given me one too many problems over the past year (dll problems, slow performance etc...). I have some free time over the next week so I'm going to backup everything, reformat, and reinstall windows.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You did not attach the two follow up logs; but if you are going to format, there is no sense wasting any more time on this.
     
  6. jaypatron

    jaypatron Private E-2

    Oh woops I forgot to go back and change that after I switched my mind. Lol yea but thanks for your help regardless though, most other threads I've posted at for malware take forever or never respond.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You mean on other websites. ;)
     
  8. jaypatron

    jaypatron Private E-2

    Lol correct, I meant to say other websites.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds