vundu is it gone?

Discussion in 'Malware Help (A Specialist Will Reply)' started by huntilla, Oct 28, 2008.

  1. huntilla

    huntilla Private E-2

    trying to get rid of a vundo trojan
    it was also in some .dat files that were purged
    will attach the other logs soon
     

    Attached Files:

  2. huntilla

    huntilla Private E-2

    more logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and use the version of MGtools given in the READ & RUN ME and attach a new log. Also please install and run SUPERAntiSpywre which was the first scan tool you were suppose to run and attach the requested log from SUPERAntiSpyware. We do not need you to attach separate HJT logs.
     
  4. huntilla

    huntilla Private E-2

    ran super spyware and found no infections and also was clean on TrendMicro, Bitdefender, and Spybot
    Thanks for the reply
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the READ & RUN ME, we still want to see the logs. It lets us know that the proper version with updates has been run.

    Also you still need to run the current version of MGtools and attach the new log so we can make sure all Vundo files have been removed.
     
  6. huntilla

    huntilla Private E-2

    here are the new logs with the current versions used for MGtool also I could not get combofix to run Basically said to close all programs and reboot
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still do not have the current version of MGtools. You need to always click the link in the READ & RUN ME and download the current version from that link. The program changes frequently to keep up with malware changes. You are out of date since you are running a version from August 2008.
     
  8. huntilla

    huntilla Private E-2

    Thanks, I have been downloading from the read me run me link in the forum and the only version I have been able to obtain is 2.13 released 10/10/08
    If there is a newer version I cannot locate it.
     
  9. huntilla

    huntilla Private E-2

    here is what I think is a current log
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you were not running the new version. Now you have run it because your last log just attached has the correct versions. You can compare the program versions listed for runkeys.txt and newfiles.txt to the previous logs yourself and you will see what I mean.

    Your logs are clean but you need to do the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Delete the below folder from ComboFix:
    C:\327882R2FWJFW

    Delete the below files from running ComboFix multiple times and possibly failing:
    Code:
    "C:\WINDOWS\system32\"
    cf11454.exe   Nov  2 2008      375808  "CF11454.exe"
    cf11617.exe   Nov  2 2008      375808  "CF11617.exe"
    cf12045.exe   Nov  2 2008      375808  "CF12045.exe"
    cf13074.exe   Nov  2 2008      375808  "CF13074.exe"
    cf13123.exe   Nov  2 2008      375808  "CF13123.exe"
    cf13208.exe   Nov  2 2008      375808  "CF13208.exe"
    cf30315.exe   Nov  2 2008      375808  "CF30315.exe"

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\BANT\Local Settings\temp


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Nov 4, 2008
  11. huntilla

    huntilla Private E-2

    Appreciate all your help and I am looking at switching over to a linux system totally but have yet to develop all the know-how. I cleaned up the combofix files and removed the Messenger auto load as described in the link. Your site is always a great resource and I am grateful for MajorGeeks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds