Vundo & other Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by XLNTA, Oct 26, 2008.

  1. XLNTA

    XLNTA Private E-2

    Hello all,
    This is a first for me, so lets see how it goes. I was given a used Dell, XP Pro, SP2. It had no virus protection that I could tell. I installed Macafee & it found numerous problems -- QHosts-95, AdClicker-FK, Vundo, Several: Adwares, Generic PUP.x, & Winfixers.

    I have done all the Read & Run me first proceedures, & the XP Cleaning proceedures. Gives me a new respect for how much time you guys spend on this stuff!!!

    Spybot was the only program that had previously been installed & run & had some stuff removed. Thus when I ran it, it tested clean. I am assuming that it ran with all default settings. I did update it to the newest version first.

    I would like to have someone review the log files, & help me confirm that everything is cleaned up. I don't want to connect this computer to my home network if it is still smacked up. Also, I have yet to clear my restore point. Finally, when all is done, should I delete all the downloads or save them for later use?

    I will attach your log files for your review.

    I am not sure I understand this part of your instructions: "You will need to post 2 messages to attach all four logs since only 3 attachments are allowed in any single message. Post all of them in one thread."

    Thanks in advance for your help.
     

    Attached Files:

  2. XLNTA

    XLNTA Private E-2

    Attachment of final log file from your MG tools.

    Thanks again.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your system is very low on ram......
    There are just a few things to do:

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Then use windows explorer to find and delete:
    C:\WINDOWS\system32\sviriqvt.ini

    Reboot and tell me how things are running.
     
  4. XLNTA

    XLNTA Private E-2

    Thanks for the help.

    I have done the HJT proceedure, & deleted the referenced file.

    Everything seems to be running fine.

    Since submitting my first post, MacAfee had a warning to block or allow: "Tool-NirCmd". I have assumed it to be from ComboFix or the MG Tools, but have not taken any action on it. What do you suggest?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....now we just have to clean up from the scans:

     
  6. XLNTA

    XLNTA Private E-2

    Have cleaned up from the scans & will work through the "How to Protect...." page. It seems thorough, but if I have questions during that process, do you suggest I post to this forum or would there be a more appropriate one.

    Thanks again for your help. I assume we will be finished now. I'll check back to see if you close the thread, or if you have anything further.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We do not close these threads..there is always the chance that you need to post with new questions regarding these issue. So do reply if you need something. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds