yet another vundo.......

Discussion in 'Malware Help (A Specialist Will Reply)' started by tannis, May 28, 2008.

  1. tannis

    tannis Private E-2

    Hey folks , having found a vundo trojan 2/3 days back i've messed around trying to remove it unsuccessfully , luckily for me i stumbled across this site and have performed all the steps required (to the best of my knowledge) and i was hoping one of the guys on here would be so kind as to analyze the logs i've attached.
     

    Attached Files:

  2. tannis

    tannis Private E-2

    Here's the last one.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having issues? The only thing I am seeing is:
    C:\Documents and Settings\Owner\My Documents\ardamaxkeyloggerv2.8+keygencrude.zip
    C:\Documents and Settings\Owner\My Documents\keygen
    C:\WINDOWS\system32\ddcapi~1.bak
     
  4. tannis

    tannis Private E-2

    Hi thanks for the response , to be honest i've been refraining from using the pc too much until i could be sure that all was clear but there doesn't appear to be any obvious signs of infection , as for the above should i remove them? i purposely use the ardamax due to monitoring young children.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you do have further issues...and yes, I would advise you to remove those three items.

    In the meantime, If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. tannis

    tannis Private E-2

    All seems fine now , thanks for all your help and advice it is much appreciated.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome..safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds