Vundo virus - some assistance required

Discussion in 'Malware Help (A Specialist Will Reply)' started by stewieandco, Aug 5, 2008.

  1. stewieandco

    stewieandco Private E-2

    Well, i have finally found a formidable adversary to myself - the Vundo virus. I've been able to remove all other viruses without drama, but this one has me stumped. I believe it was last night, the virus entered my computer. I logged on at 3:30pm this afternoon, and i noticed that certain pages were loading and certain pages were hanging (for example, hotmail, Skyscrapercity.com and google worked, while Myspace, Giveaway of the Day and Bigpond hanged). I've had problems with the LAN and this could happen. Rebooting had always solved the problem. So i rebooted, and logged in, before getting a userinit.exe error. (code 0xc000005). I clicked ok to terminate application, and got it again. i eventually made it to where my desktop is, but got only my background. So i used task manager to load explorer.exe and got my desktop back. I knew i had a problem, so i ran a SuperAntiSpyware and a Bitdefender scan, and it identified a Vundo trojan. I checked the internet and saw that the symptoms matched what i have, with internet hanging, boot troubles, ...... So i spent several hours trying different programs (RogueRemover, Vundofix, one by Trend Micro, and those listed on MG. I've attached a few of the log files from those listed, but Combofix would not run due to a rundll error (same as userinit.exe error).
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you run MalwareBytes and not fix all that it found?

    Please re-run it and fix the issues that it reports. Then attach the new log and also the log from running MGTools.exe (from the READ & RUN ME FIRST. Malware Removal Guide).
     
  3. stewieandco

    stewieandco Private E-2

    Hi
    The Malawarebytes log file is before the items were fixed. How do you save a log file for it as when it finishes taking action it closes?

    Cant run MGtools.exe. Comes up with error message similar to #4 (Rundll error) but have .Net Framework 3.5.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We want to see what was fixed....if you open MalwareBytes...there is a tab for the logs.

    Give me the exact error message....

    Go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  5. stewieandco

    stewieandco Private E-2

    Hi
    Have managed to rid my computer of the virus. I found the infected file in the Windows folder but it would not let me delete it. It kept saying that the file was in use. I then installed Creative Elements Power Tools and set it to delete files in use. Deleted the file and rebooted. It was gone.
    Thanks for all your help
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Very well .....If you are not having any other malware problems, it is time to do our final steps:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds