vundo.t have i cleaned?

Discussion in 'Malware Help (A Specialist Will Reply)' started by chix2k8, Jul 6, 2008.

  1. chix2k8

    chix2k8 Private E-2

    was recently infected by vundo.t! been through a long process to get rid. can someone plz help me and tell me if it has gone?
     

    Attached Files:

  2. chix2k8

    chix2k8 Private E-2

    mg logs below
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First thing you need to do is re-run MalwareBytes and have it remove/fix everything that it finds.....then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MWB's.
     
  4. chix2k8

    chix2k8 Private E-2

    Ok will do. thank you
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you have any problems doing that. :)
     
  6. chix2k8

    chix2k8 Private E-2

    I'm hoping I'm clean:)
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Be sure to tell us how things are running.
     
  8. chix2k8

    chix2k8 Private E-2

    rolleyes Hope i got it right
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well....the registry patch worked but the HJT fix did not. Please make sure you have disabled ALL anti-virus and spyware programs and do the HJT fix again. Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip.
     
  10. chix2k8

    chix2k8 Private E-2

    :cry lol ok well i am using eset antivirus and have disabled it. Am using superantispyware and totally closing that now......lets c
     
  11. chix2k8

    chix2k8 Private E-2

    Shall i just carry on crying?:confused
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'd hand you a tissue, but there is nothing to cry about ...your logs are clean. :)

    Tell me what you are crying about....
     
  13. chix2k8

    chix2k8 Private E-2

    :-D wow thanx honey!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hehe .....If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.

    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  15. chix2k8

    chix2k8 Private E-2

    JEEEEEEEEZ ok u do realise im a chick?:confused lol i will need to come back later and sort this when my brain is willing to recieve. ty
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well......not to many men call me honey....:-D

    Take your time....I'll be here if you have further questions. :)
     
  17. chix2k8

    chix2k8 Private E-2

    Woohoo!! all done I'm hoping. I did all the things listed. A square slowed my pc too much so uninstalled. How sad :( our journey is at an end.We've been through so much together! I know you'll move on....find someone else who can take up your time. I dont know how I'll ever move on without you:cry hehe thanx so much for your help, i really appreciate it honey! x:wave
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.....and consider this not a parting, just a brief interlude in our virtual tryst. ;)
     
  19. chix2k8

    chix2k8 Private E-2

    You'renot gonna believe....but i am infected again! by borlander? comp is extremely slow. I cant install spybot or a square, when do try to install is says unable to create temporary file. setup aborted. error5: acces is denied. It also does this when i have tried uninstalling these programs. I cant even show you the logs which inform me of infection.:eek: Wanna help me out again?
     
  20. chix2k8

    chix2k8 Private E-2

    Also i have been trying to uninstall online armour firewall program but it just wont let me. Ahhhhhhhhhhhh my comp is knackered man! what is a bird to do?
     
  21. chix2k8

    chix2k8 Private E-2

    My spyware terminator says i have bee infected with Trojan.clicker-1344. Will try Kaspersky
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you trying to do an online scan? You can use Internet Explorer to run Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    Do you still have any of the tools we had you download before? I would need to at least see the MGLogs.zip.
     
  23. chix2k8

    chix2k8 Private E-2

    Yes have been trying.Bitdefender wont load the scanner, have tried doing what it says there but no joy.I cant install spybot S&D,says access denied. My spywareterminator says i have 2. Eset says i had 1. I cant uninstall or terminate the process of online armour.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you re-downloaded MGTools? That should run and produce a log....
     
  25. chix2k8

    chix2k8 Private E-2

    Ok have done that. I dont wanna keep pestering you soz.:eek:
     

    Attached Files:

  26. chix2k8

    chix2k8 Private E-2

    My computer has just closed down by itself, upon restarting it told me 'windows has recovered from a serious error' the error signature says...BCCode:100000d1 BCPI:\FF596F4C BCP2:00000002 BCP3:00000000 BCP4 F9CD6F51 OSVer:5_1_2600 SP:3_0 Product:768_1

    Technical information...
    C:\DOCUME~1\OWNER~1.FAM\LOCALS~1\Temp\WER5e9f.dir00\Mini073108-01.dmp

    C:\DOCUME~1\OWNER~1.FAM\LOCALS~1\Temp\WER5e9f.dir00\sysdata.xml

    Do you understand this?
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running multiple Anti-virus programs and firewalls.

    You need to do a search for any of the following:
    Avg8 -> av program
    ESET Smart Security - Has a firewall and AV
    Online Armor 2.1 -> av program
    WinClamAVShield - av program
    PC Tools -> firewall

    Your error code refers to an issue with the firewall program.

    There is a MS fix for this, but I would wait until you have removed all of the firewall components and redundant av programs...then if you still have the error code we can try this ....http://support.microsoft.com/?kbid=916595
     
  28. chix2k8

    chix2k8 Private E-2

    Oh i didn't think it mattered providing they were'nt installed? I will try to delete these programs. Online Armour won't allow me to either delete or uninstall.In your opinion, which should i have to protect me?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some are still in your run keys....and multiple programs will make conflicts that can cause all kinds of problems.....have you tried using CCleaner to uninstall and then do the cleaning?

    You should work thru the below link:
    How to Protect yourself from malware!

    When/if you think you have cleaned it up...run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip.

    (You just wanted me to look at your system again, eh?)
     
  30. chix2k8

    chix2k8 Private E-2

    Haha! man how cheeky! I have managed to uninstall Online Armour, did it in safe mode. I do have some kind of infection, hopefully now tho i should b able to sort it using the programs i did last time.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I mean to say is that you have leftover traces of those programs that were once installed. But it looked like you had two firewalls running. I wasn't seeing much else, but you should get me the logs from:
    Superantispyware
    MalwareBytes
    and a new MGLogs.zip


    :)
     
  32. chix2k8

    chix2k8 Private E-2

    There you go:major:)
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If I am reading this right...you have removed all your firewall programs.

    A few things to remove:
    C:\WINDOWS\unins000.dat
    C:\WINDOWS\unins000.exe
    C:\Documents and Settings\All Users\Application Data\Avg8

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download a new firewall ( Did you have issues with PCTools firewall? ..it has a very easy interface).

    Tell me what problems you are having.
     
  34. chix2k8

    chix2k8 Private E-2

    Have done that, all good i hope. In application data can i delete the folders to the programs i have deleted? I.E Superantispyware, Symantec, PCTools, Lavasoft, ESET. Have acquired Registry Mechnic pro, Driver genius pro, are they any good? will they help me? I will get the best firewall if u tell me what that is:-D I am infected with vundo again, plus a few others...will scan some more tonight(after fighting my kids off pc) Thanks again
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can remove the items in the application data files....some may not but that is ok.

    What do you mean you are infected again? Your last logs that you attached looked clean.

    I prefer PCTools firewall which you can download HERE

    I am not familiar with either of the programs you mentioned.....I don't see the need for any registry programs. Running the "issues" section of CCleaner is about all you need ( and of course making the backup when prompted).
     
  36. chix2k8

    chix2k8 Private E-2

    Check these out please. Scary amount of infections.
     

    Attached Files:

  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you are severely infected again......so I will repeat what I said in post #3:

     
  38. chix2k8

    chix2k8 Private E-2

    Thanx
     

    Attached Files:

  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please don't make me come over there and ........nevermind.

    You need to stop downloading warez programs!

    Use windows explorer to find and delete:
    C:\Program Files\315265.exe
    C:\Program Files\(99Ways)Kaspersky 8.0.torrent
    C:\Program Files\(99Ways)Kaspersky 8.0 [mininova].torrent
    C:\Program Files\"++Demonoid.com++-Kaspersky_Internet_Security_8_0_0_357_2538917.0674 [mininova].torrent"
    C:\WINDOWS\SYSTEM32\eysmgcqh.tmp

    Now download and install a real anti-virus program from HERE

    What problems are you now having?

    Did you run MWB's and SAS on the "kids" user account?
     
  40. chix2k8

    chix2k8 Private E-2

    Damn! It took my AGES to find this post! was all arse backwards:confused to get a bollocking :-D Yes you're right. Somebody else told me that i needed to delete my limewire and install that bitcomet thing. Well... once there, I was like a kid in a sweet shop! only, a poor kid in a sweet shop:yum:-D Well i guess you can say i have learned my lesson. Vundo came and arrested me on theft charges:eek:
     
  41. chix2k8

    chix2k8 Private E-2

    I forgot to say that i had deleted those files and rescanned
     

    Attached Files:

  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....the only thing that MWB's found was two files in your system restore files....you need to toggle system restore to remove them.

    We can do a few things:

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 10"
    Java(TM) 6 Update 4"
    Java(TM) 6 Update 7

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Delete this:
    C:\Temp

    Reboot and install:
    Java Runtime 6

    Tell me what malware issues you still have. :)
     
  43. chix2k8

    chix2k8 Private E-2

    I'm not sure what problems i have,but i have them. My system keeps shuttin down and telling me that its recovered from a serious error.
    This is the error report contents.

    C:\DOCUME~1OWNER~1.FAM\LOCALS~1\Temp\WER8856.dir00\Mini081208-01.dmp
    C:\DOCUME~1OWNER~1.FAM\LOCALS~1\Temp\WER8856.dir00\sysdata.xml
     
  44. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are where the error messages are stored.

    You need to right click My computer / advanced / startup and recovery / settings .... uncheck the box for automatic restart ....this will then give you a BSOD when it crashes. We will need the exact error message from that.
     
  45. chix2k8

    chix2k8 Private E-2

    It seems to be running fine, although i have noticed in firewall that firefox is connecting to other sites that i am not on. spyware?
     
  46. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What exactly is it reporting? What sites?
     
  47. chix2k8

    chix2k8 Private E-2

  48. chix2k8

    chix2k8 Private E-2

    In activity tab it says i am connected to internet explorer? I try not to use ie and it isn't in use now.
     
  49. chix2k8

    chix2k8 Private E-2

    I be I'm makin a right tit of myself here lol:-D:eek::p
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming that you are referring to your firewall report....this is an issue you need to address in the software forum .....you can block the ones that you don't recognize. If things don't run correctly, unblock them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds