also @ TechSpot: Weekend Open Forum: Have you upgraded to Windows 7 yet?
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Vundo Virus Problem w/log

Closed Thread
Page 1 of 2 1 2
Bookmark Thread Tools
  #1  
Old 01-01-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
Vundo Virus Problem w/log

Hey,
What a great way to start off the new year huh?
I've had this thing before but just got it again.
I was gonna do a virus scan but came here instead to see if i could fix it with my log

THANKS A BUNCH IN ADVANCE!

if anything else is need please let me know




Imma follow the very thorough instructions first
Attached Files
File Type: txt hijackthislog1-01.txt (5.7 KB, 2 views)

Last edited by gubhenheim; 01-01-2009 at 08:28 PM.. Reason: politeness
  #2  
Old 01-01-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
Right Click on MyComputer icon and go to properties
Turn Off system restore
open IE and go to TOOLS OPTIONS delete temporary internet files and cookies
do a disk cleanup in your Start/accessories/system tools/ Menu
download malwarebytes and install
run hijackthis and malwarebytes at the same time
select any files and or keys I posted in hijackthis but on both maiwarebytes and hijackthis click fix at the same time.
then reboot immediatly.
if you forget to turn off system restore it will return no matter

reboot once complete, run hijack this and post your log here again
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
Beggining of the End

Ok,
Did what was suggested...
I scanned with SuperAnti, cleaned with CC and
did the thing with Malwarebytes and HiJack
here are my logs

thanks for the help
Attached Files
File Type: txt mbam-log-2009-01-01 (21-32-34).txt (2.3 KB, 1 views)
File Type: txt hijackthis log2.txt (5.7 KB, 1 views)
  #4  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
-> No action taken on MBAM scan, for found issues
Quote:
Download and Run Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected. <========= Not Done
Please re-run Malwarebytes
Confirm updated (third tab)
Then do the above quoted message, but this time "Remove all found issues"

By the way, you will need to then restart, and run (and attach) a new HJT log
  #5  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
Hello,

I've noticed that my Malwarebytes is running on outdated definitions but i wont update,
something about a firewall. However, I changed my firewall settings to allow the program and tried all three mirrors.
Any Suggestions?
  #6  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Special case where after installing MBAM and SAS they will not update or run
Read here: Google Yahoo redirect TDSSserv.sys

Failing that, try here: http://www.techspot.com/vb/post684649-3.html

Then continue: UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions

  #7  
Old 01-02-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
He will need the winsock fix i believe get winsockfix and run it then follow the instruction prior for mawarebytes and hijackthis

Last edited by BlkHeartWolf; 01-02-2009 at 02:24 AM..
  #8  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
yeah,
i tried running the fixit cmd, my computer restarted but Malwarebytes wont update
i was thinking of just reinstalling it, however i cannot access the webpage.

im wondering what my options are, im downloading winsockfix right now, hoping that it will help
thanks

OK- GOT AN UPDATED COPY,
as of now, i am running malwarebytes
will restart and then run hijack.

also, i got a pop up with a url containing the word sagipsul, should i worry or does this come with my problem?

thanks

Last edited by gubhenheim; 01-02-2009 at 02:52 AM..
  #9  
Old 01-02-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
i know it is frustrating but we will work through it
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
So here are the logs hopefully they are correct:

thanks again for the patience and aid
Attached Files
File Type: txt mbam-log-2009-01-01 (23-55-25).txt (5.9 KB, 1 views)
File Type: log hijackthis.log (6.0 KB, 2 views)
  #11  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
A little better
Please update Malwarebytes one more time (again?) Yes again ! Sadly Malwares hide other Malwares, running multiple scans, will find and remove them all (but update it first)

Also try a free AntiVirus like => Avira
  #12  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
ok, will do
have a quick question, i've got SAS and im open to downloading avira
is it fine to have both programs running at the same time along with Malwarebytes?

and just checked, malwarebytes says i have the latest database version
sooo....
  #13  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Yes actually I saw that it looked updated, but that's my standard advice - update first

Regarding SAS; you can un-install it now
And make sure to use one Antivirus, which will be the free Avira

Then with Avira all updated and working
Run Malwarebytes full scan (update first )
  #14  
Old 01-02-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
very well then,
SAS is dead and gone, Avira is my weapon of choice.
i'll start my scan soon and be back after i get some shut eye.

THANK YOU VERY MUCH!
I OWE THIS SITE MY something

ok scanning is done here are my logs, and i think my system is clean, can you do a once over?

im going restart and update with my hijackthis log

here is my hijack this log and scan log

thanks again

is it fine to turn my system restore back one?
Attached Files
File Type: txt mbam-log-2009-01-02 (12-37-02).txt (856 Bytes, 2 views)
File Type: log hijackthiss.log (6.6 KB, 1 views)

Last edited by kimsland; 01-03-2009 at 07:32 AM.. Reason: merged 3 posts
  #15  
Old 01-02-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
NO
Right Click on MyComputer icon and go to properties
Turn Off system restore
open IE and go to TOOLS OPTIONS delete temporary internet files and cookies
do a disk cleanup in your Start/accessories/system tools/ Menu

After the reboot
download malwarebytes www.malwarebytes.org and install
run hijackthis and malwarebytes at the same time
select any files and or keys I posted in hijackthis but on both maiwarebytes and hijackthis click fix at the same time.
then reboot immediatly.
if you forget to turn off system restore it will return no matter

reboot once complete, run hijack this and post your log here again


O20 - AppInit_DLLs: jwapfx.dll
O20 - Winlogon Notify: xxyaxVlM - xxyaxVlM.dll (file missing)
  #16  
Old 01-06-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
Latest Scan and Hijackthis

Hopefully these will be the keys that will solve my dilemma
Attached Files
File Type: txt mbam-log-2009-01-06 (00-30-00).txt (849 Bytes, 1 views)
File Type: log hijackthis1-6.log (6.2 KB, 1 views)
  #17  
Old 01-06-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
You have a number of bad issues

Please run a new scan with HJT and tick and fix the following entries (confirming your Internet browser is first closed)

Quote:
O4 - HKUS\S-1-5-18\..\Run: [msiexec.exe] msiconf.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msiexec.exe] msiconf.exe (User 'Default user')
O4 - S-1-5-18 Startup: Rapid Antivirus.lnk = C:\Program Files\Rapid Antivirus\Rapid Antivirus.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Rapid Antivirus.lnk = C:\Program Files\Rapid Antivirus\Rapid Antivirus.exe (User 'Default user')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
Before restarting, download the following 4 tools, and print these instructions

1. Download VundoFix; Trojan.Vundo Removal Tool; VirtumundoBeGone and ComboFix.
2. Go Offline - pull the cable network, turn off wireless card, turn off your modem.
3. Restart computer and press F8 to run Windows in Safe Mode
4. Run VundoFix.. Click on the Scan for Vundo. Scanning will begin, which takes a long time. In the white box will display the names of infected files. After the scan is complete click Remove Vundo, removal will begin. Confirm by clicking Yes. The application should ask for permission to restart your computer - click Yes. Start Windows in Safe Mode again.
5. Run FixVundo. Click Start, and then follow the instructions. It should be noted that this application can deal only with older mutations Vundo (Virtumonde).
6. Run VirtumondoBeGone. Click Continue and wait for the report.
7. Run ComboFix. Then, in the two windows that appear click Yes, and start scanning and removal of any Vundo (Virtumonde) infection. During this operation, you are not allowed to move the mouse or perform other actions. After the scan is complete, program will show a text file - a report from the program's action.
8. Restart computer and run Windows normally.
9. Attach the report
  #18  
Old 01-06-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
SCANS FOR VUNDO w/REPORTS

Here are my scans and vundo program reports
Attached Files
File Type: txt log.txt (11.7 KB, 1 views)
File Type: txt VBG.TXT (2.5 KB, 1 views)
File Type: log FixVundo.log (193 Bytes, 1 views)
File Type: log hijackthis1-06.log (5.0 KB, 1 views)
File Type: txt mbam-log-2009-01-6 (10-21-25).txt (848 Bytes, 1 views)
  #19  
Old 01-06-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Still exists:
Quote:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
KillBox is a tool to delete in-use files, if the file is running, KillBox will attempt to end the process (close the running file) and delete it.

Download KillBox: http://www.killbox.net/downloads/KillBox.exe
Run it, and copy and paste this line into the path: C:\Program Files\Vongo\Tray.exe
Click the Red X (delete button)

Restart back to SafeMode
Locate: C:\Program Files\Vongo folder and delete it

Startup HJT scan still in Safe Mode
Tick and fix the following entry:
Quote:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
Restart back to Normal mode
Provide another HJT scan log (I want to see if it's now removed )
  #20  
Old 01-06-2009
Newcomer, in training
 
Member since: Sep 2008, 25 posts
im racing against the clock to do all of this before i have to reboot to regain an internet connection,
but KILLBOX states that "C:\Program Files\Vongo\Tray.exe" seems to not exist. So right now im gonna reboot in safe mode and be offline running hijack this after deleting the folder

thanks

UPDATE- ok, will this resolve my problems?
Attached Files
File Type: log hijackthis.log (4.4 KB, 1 views)

Last edited by gubhenheim; 01-06-2009 at 08:38 PM..
Closed Thread
Page 1 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Vundo virus Virus & Malware removal 60 02-11-2009 02:04 PM
Mal vundo-4 virus removal Virus & Malware removal 0 05-08-2008 07:17 AM
Vundo Virus - please help Virus & Malware removal 18 04-19-2008 08:58 AM
Removing Vundo Virus Virus & Malware removal 2 04-17-2008 11:02 AM
Help needed please with vundo virus Virus & Malware removal 23 06-04-2007 04:31 PM


All times are GMT -4. The time now is 07:12 PM.