Vundo -- help please -- 8 steps question

Status
Not open for further replies.

loudcherokee

Posts: 6   +0
Vundo -- *update* logs attached

Hello,

I've just found out that I have a vundo infection, and my Mcafee cannot remove it. Through google, I found this site.

I've read through and printed the 8 steps, and I am ready to begin, but i have a question about the CCleaner program.

The checkboxes in the applications folder---is checking these boxes going to remove these programs? Will i need to download and re-install these programs after running the Ccleaner program?

I just wanted to make sure what this program is doing before I get started.

Thank you,

LC
 
No it doesn't remove the applications themselves

Here is the guide again:

And here is a bit of info on how to attach the logs:


Thank you. Hopefully, i will report back soon with some logs.

LC

Here are the three logs requested in the 8 steps. I guess I should say that I use Firefox, if that's important.

I could not complete the java step. I downloaded the newer version, but it would not install, and kept giving me server errors. This is the only step I did not complete.

I do have a couple of questions. I am using a wired router, and I have a Playstation 3 connected to the same router. Is my PS3 at risk for infection, or do they not use the same type of files as a windows system?

Thank you,

LC

Also, after running the SuperAntiSpyware program, upon re-booting, the computer froze on a black screen, and indicated it could not fun "pinazilo.dll", specified module could not be found, and "could not open lssee.exe".

after clicking ok on both these items, it immediately took me to the user log on screen.

Please let me know if there are any further details I need to add.

THank you,

LC
 
Well according to that SuperAntiSpyware log you have re-visited sites with "ZEDO Ad Serving" Malware

You will need to run all scans again as you have re-infected yourself (including doing CCleaner first

It is possible that the real fault is your browsing habits. Where exactly do you go? I ask this because even if support clean your infection, it may be a waste of time as you might just re-infect yourself again :suspiciou
 
Well according to that SuperAntiSpyware log you have re-visited sites with "ZEDO Ad Serving" Malware

You will need to run all scans again as you have re-infected yourself (including doing CCleaner first

It is possible that the real fault is your browsing habits. Where exactly do you go? I ask this because even if support clean your infection, it may be a waste of time as you might just re-infect yourself again :suspiciou

I havn't visited any more sites. My browser home page is yahoo.com, and upon opening my browser, i open my bookmarks list, and then come straight to this site.

I wonder if my girlfriend used the computer this morning :mad: I know she frequents facebook, myspace, and yahoo mail. She also accessed a site called "appointments plus" for her work.

LC
 
Here's a further 8-Steps: (bassically making 16 in whole :D)

Download the following 4 tools, and print these instructions

1. Download VundoFix; Trojan.Vundo Removal Tool; VirtumundoBeGone and ComboFix.
2. Go Offline - pull the cable network, turn off wireless card, turn off your modem.
3. Restart computer and press F8 to run Windows in Safe Mode
4. Run VundoFix.. Click on the Scan for Vundo. Scanning will begin, which takes a long time. In the white box will display the names of infected files. After the scan is complete click Remove Vundo, removal will begin. Confirm by clicking Yes. The application should ask for permission to restart your computer - click Yes. Start Windows in Safe Mode again.
5. Run FixVundo. Click Start, and then follow the instructions. It should be noted that this application can deal only with older mutations Vundo (Virtumonde).
6. Run VirtumondoBeGone. Click Continue and wait for the report.
7. Run ComboFix. Then, in the two windows that appear click Yes, and start scanning and removal of any Vundo (Virtumonde) infection. During this operation, you are not allowed to move the mouse or perform other actions. After the scan is complete, program will show a text file - a report from the program's action.
8. Restart computer and run Windows normally.

But here's the one we ask you to do before doing anything else:
UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions

I'd say do both :grinthumb
 
Question :

for this step --
7. Run ComboFix. Then, in the two windows that appear click Yes, and start scanning and removal of any Vundo (Virtumonde) infection. During this operation, you are not allowed to move the mouse or perform other actions. After the scan is complete, program will show a text file - a report from the program's action.

My computer screensaver automatically turns on after about 10 minutes. should I disable this function before going forward?

LC
 
Yes

Sorry for the delay in responding by the way.

But whilst I'm replying I may as well add something else I feel strongly about

Uninstall your McAfee Antivirus
Then run the McAfee Removal Tool

Install Avira free AntiVirus

Obviously "McAfee" has not saved you from this infection, nor is it a good Antivirus software anyway !
 
no problem at all for the slow response. I appreciate you taking the time to help me.

I'm off to do the 8 steps again, and then the new 8 steps. I suspect this will take some time, so it may be tomorrow before I post updated logs. I'll try to keep the girlfriend off the computer in the meantime.

LC
 
That's fine :)

Pretty sure doing the above 99% (if not all) Malwares will be removed
Oh I always recommend Avira Antivirus as the best one to use :grinthumb
 
Updated logs are now complete. The java was successfully installed this time. Also, i did not get the error windows with startup that I received the first time (pinazilo.dll and lsse.exe ??).

Everything seems to be running smoothly. I have not performed the additional 8 steps at this time. I will probably need to do this on Saturday, when I can make sure the g/f doesn't use the computer. She'll need it tomorrow morning for her email and work applications.
 
Status
Not open for further replies.
Back