Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vundo Malware Removal


  • This topic is locked This topic is locked
5 replies to this topic

#1 zsemki

zsemki

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:12 AM

Posted 26 January 2010 - 05:21 PM

Hey all,

Using WinXP (SP3) here and came across some malware. This computer has multiple users and is experiencing pop-ups (I believe they're being run through Win Explorer).

I found and attempted to remove fawedevi.dll, wakozawa.dll & fawedevi.dll using HijackThis & KillBox.

I logged on this morning and found that the pop-ups were still occurring. I took a SS and attached it.

I've also attached my DDS log in hopes that someone can shed some light how to on cleaning up this system.

Edit: Attached RootRepeal Report as well.

Attached Files


Edited by zsemki, 26 January 2010 - 05:38 PM.


BC AdBot (Login to Remove)

 


#2 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:12:12 PM

Posted 02 February 2010 - 03:04 PM

Hello, zsemki.
My name is aommaster and I will be helping you with your log.

I apologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.
If you have since resolved the original problem you were having, I would appreciate you letting us know. If not please perform the following below so I can have a look at the current condition of your machine.

Thanks

Please note that I am in the process of my training so it may take a while for me to get back to you, as each of my fixes need to be checked by a coach first.

We need to run RSIT
  1. Download random's system information tool (RSIT) by random/random and save it to your desktop.
  2. Double click on RSIT.exe.
  3. Click Continue at the disclaimer screen.
  4. Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

In your next reply, please include the following:
  • Log.txt
  • info.txt

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#3 zsemki

zsemki
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:12 AM

Posted 02 February 2010 - 06:02 PM

QUOTE(aommaster @ Feb 2 2010, 12:04 PM) View Post
Helpful info.


Thanks for helping out aommaster,

The problems are still persisting on this particular machine. I'll get those two logs attached to this thread tomorrow (Wednesday) afternoon PST.

Thanks again. thumbup2.gif

#4 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:12:12 PM

Posted 02 February 2010 - 09:27 PM

No problem! Thanks for letting me know smile.gif

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#5 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:12:12 PM

Posted 05 February 2010 - 07:41 AM

Hello zsemki
Are you still with us?

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,708 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:10:12 AM

Posted 07 February 2010 - 01:37 PM

This thread will now be closed due to lack of activity.

If you should have the same or a new issue, please start a new topic.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users