Vundo and Trojan Problem tried everything

Discussion in 'Malware Help (A Specialist Will Reply)' started by magicmasterk, Jun 26, 2008.

  1. magicmasterk

    magicmasterk Private E-2

    Hi, I've been having trojan problems for some time and my current software wouldn't work so I tried the steps you guys outlined in your tutorial and I think there still might be problems.

    I've attached my logs. Thanks
     

    Attached Files:

  2. magicmasterk

    magicmasterk Private E-2

    Here's the last log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing anything from the logs.....but tell me what this is:
    C:\Documents and Settings\All Users\Application Data\amjmwaey.gaf

    And this user really needs to clean up the desktop....it's a good way for malware to hide in:
    C:\Documents and Settings\Kenneth Kozakura\Desktop

    What problems are you still having?
     
  4. magicmasterk

    magicmasterk Private E-2

    I'm not sure what that file is.

    While I was browsing firefox, often IE windows would often pop-up displaying ads. For the moment, I think they've stopped but I wasn't sure. I knew for a while I had some vundos but I wasn't able to remove them even though I didn't have symptoms of a problem.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you don't know what it is, I suggest you delete it. Let me know if you have further problems.

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. magicmasterk

    magicmasterk Private E-2

    I've tried to remove combo fix via your instructions but it doesn't seem to be working. the computer gives me the message "This file doesn't have a program associated with it for performing this action. Create an association in the folder options control panel" I renamed it as requested and its on my desktop.

    Also command prompts keep popping up randomly on my screen is combofix the culprit? I think it says something like msi?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete the ComboFix.exe file, C:\ComboFix (Or cf) folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that were created.

    You will have to give me more infor about the prompt that is popping up.
     
  8. magicmasterk

    magicmasterk Private E-2

    nvm I solved the command prompt issue, it was a ghost software i installed.

    Thanks for the help!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are more than welcome ...safe surfing. :)
     
  10. magicmasterk

    magicmasterk Private E-2

    hey sorry to bump this thread but I recently started having this other problem. Although I know i have around 3-4 GB left of harddrive space, without notice, my computer will tell me that I am suddenly running out of harddrive space and when I check the C: it says i have 0 GB of space left. Everytime i run the windows disk cleanup it doesn't free any space at all. After I rebooted, it returned to the 3 GB of space but then another hour or so later my harddrive space disappeared. Do you know what is causing this?
     
  11. magicmasterk

    magicmasterk Private E-2

    Here's my new combofix log (i just ran another scan but this time it didnt find anything) and my MGtools logs. Could you take a look at these and see if you find anything? Thanks !
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It doesn't appear to be malware. You do have a lot in your temp internet files:

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    I would suggest that you post this issue in the software section.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds