Vundo and other malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by celebrate, Jul 16, 2006.

Thread Status:
Not open for further replies.
  1. celebrate

    celebrate Private E-2

    My computer's been acting strange for quite some time now. At first it was just running slow, but then I started getting a lot of pop ups for things I didn't want to look at, and also the Winfixer pop up. I followed your READ AND RUN ME FIRST instructions as best as I could, but I'm still getting the message from Norton telling me that I have a high risk virus called Trojan.Vundo located at C:\WINDOWS\system32\awtst.dll.

    When I uninstalled malware via add/remove programs, the only thing I had to remove was MyWebSearch. I also removed at least 20 files from Norton AntiVirus Quarantine. I wasn't able to find the Norton Nprotect folder guarding my recycle bin so I had to skip that. I did empty my recycle bin though. I have not disabled system restore because the directions said not to until my system was completely cleaned.

    I enabled the viewing of hidden files, system files and file extensions. I also removed SpySweeper because step 3 says not to have multiple antivirus applications. Now I only have Norton AntiVirus.

    I downloaded Ccleaner, Ad-Aware SE, Spybot-Search and Destroy, Microsoft Windows Malicious Software Removal Tool, CounterSpy, CWShredder, and Kill2Me. I was unable to install Microsoft Windows Defender. I just got a message that said "installation package couldn't be opened."

    I rebooted in Safe Mode, unplugged my internet cable (even though I have dial-up), and ran all the tools I had installed. After running Ad-Aware it told me I had 57 new critical objects, 17 were registry keys, 35 registry values, and 5 files. I ran the scan again after it removed what it could and it told me I had only 9 critical objects, 5 were registry keys, 1 was a registry value, and there was 3 files. The Spybot Search and Destroy results told me I had the following: Command Service (cmdService), Look2Me.Topconverting, WindowsSecurityCenter.AntiVirusDisableNotify, WindowsSecurityCenter.FirewallDisableNotify, 10 different Wild Tangent things, ISearchTech.YSB, MiniBug, and Virtumonde, to total to 21 objects. It said they deleted all of them but I don't think it did cause I still have Vundo.

    I was unable to get the latest Sun Java Version because it took so long to pull the screen up that it would just say it couldn't find the server and the page would stay white. I ran BitDefender anyways and it was a three and a half hour scan. It found nothing but I'll try to attach the log anyways. Panda ActiveScan didn't work either, it loaded the page but stayed at the 0% for hours. I went to the Special Removal Procedures page to try to get rid of Vundo/Virtumonde/Winfixer and ran the scan but it told me I didn't have the virus even though Norton still says I do.

    I'm sorry for such the long post but I have no clue what to do, I've spent weeks trying to fix my computer in various ways but nothing's working. Any help is appreciated!

    Steph
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spy Sweeper is not an antivirus program. It is an antispyware program. Was it a paid or free version?

    Where is your PandaActiveScan log?
    Also you need to complete step 7 of the READ ME and attach your HJT log.

    Now run the below procedure and attach the newfiles.txt log.
     
  3. celebrate

    celebrate Private E-2

    Can you lock this thread? I took care of it myself. :) After completing the RUN AND READ ME instructions Norton removed it itself and I'm no longer getting the pop up about Vundo/Virtumonde/Winfixer. I ran all the other scans once more just to be sure, and I'm clean. Thank you anyways.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds