Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vundo.trojan?


  • This topic is locked This topic is locked
3 replies to this topic

#1 hellokitty94

hellokitty94

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:51 PM

Posted 03 August 2008 - 08:24 PM

I've been busy all weekend to find out what is wrong with my PC. I couldn't navigate on the internet, strange popups appeared about antivirus2009 and that my computer was infected, and I couldn't turn on automatic windows updates. After investigating on the net (from another PC) I found it probably was infected with vundo.trojan. I scanned with several antimalware, with Malwarebytes antimalware I got rid of about 15 items of vundo.trojan. This got me back navigating, but I still cannot turn on automatic updates.

I attached a Hijackthis logfile, hoping you can help me out with this problem. Thanks in advance!

Attached Files



BC AdBot (Login to Remove)

 


#2 htv8

htv8

  • Members
  • 1,694 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:51 PM

Posted 09 August 2008 - 05:37 AM

Hello hellokitty94, and welcome to BleepingComputer.com! I will be handling your log to help you get cleaned up.

Please take note of the following:
  • I will start working on your malware issues, this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clean. Just because a symptom disappears does not mean your system is clean.
  • If you have circumstances that you are aware of that will delay your response, then please let me know. This is to ensure that your topic remains open and I don't close it to start a new post.
  • Please set aside enough time to complete all the steps in each post and follow the instructions in the order stated.
  • Please don't run any extra scans or fix programs not requested by me as it could change the results in the reports I request.
  • If there's anything that you don't understand, stop and ask your question(s) before proceeding with the fixes.
  • Please reply to this thread. Do not start a new topic.
Please give me some time to look over your log and I will get back to you as soon as possible.

Thanks,

htv8
If I have not posted back within 24 hours, feel free to send me a PM with your topic link.

Posted Image

#3 htv8

htv8

  • Members
  • 1,694 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:51 PM

Posted 09 August 2008 - 06:29 AM

Hello, hellokitty94.

First of all: When posting your logs, please post them directly into the reply. Please do NOT attach logs unless specifically requested.



Before we begin, you should save these instructions in Notepad to your Desktop, or print them, for easy reference and to make sure you don't get lost.
Make sure to work through the fixes in the exact order in which they are mentioned below and do not miss any steps out. If at any point you have questions, or are unsure of the instructions, do not hesitate to post here and ask for clarification before proceeding with the fixes.


Your log shows that your HijackThis is an old version.
Please delete all copies of HijackThis.zip or HijackThis.exe you have saved.
We will download and install a HijackThis copy of the latest release with Deckard's System Scanner (see instructions below). Make sure you answer Yes when Deckard's System Scanner prompts you to download and install HijackThis.

We need to create a Deckard's System Scanner (DSS) log.

Please download Deckard's System Scanner (DSS) from one of the links below and save to your Desktop.
(1) Download Deckard's System Scanner (dss.exe)
(2) Download Deckard's System Scanner (dss.exe)

DSS will do the following:

  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for an analyst to review.
  • Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your Desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer Yes.
You must be logged onto an account with administrator privileges when using Deckard's System Scanner.

To run the program:
  • Close all applications and windows so that you have nothing open and are at your Desktop.
  • Double-click on dss.exe to run DSS, and follow the prompts.
  • If your antivirus or firewall complains, please allow this script to run as it is not malicious.
  • When the scan is complete, two text files will open in Notepad (if not, they both can be found in the C:\Deckard\System Scanner folder):
  • main.txt <- will be maximized
  • extra.txt <- will be minimized;
copy (Ctrl + A then Ctrl + C) and paste (Ctrl + V) the entire contents of main.txt and the extra.txt in your next reply.
NOTES:
** When running DSS, some firewalls may warn that it is trying to access the Internet (especially if your asked to download the most current version of HijackThis); please ensure that DSS is given permission to access the Internet. **
** If you get a warning from your antivirus while DSS is scanning, please allow DSS to continue as the scan is not harmful. **


If I have not posted back within 24 hours, feel free to send me a PM with your topic link.

Posted Image

#4 htv8

htv8

  • Members
  • 1,694 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:09:51 PM

Posted 18 August 2008 - 05:12 AM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, PM a staff member with the address of this thread. This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
If I have not posted back within 24 hours, feel free to send me a PM with your topic link.

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users