Trojan Vundo Again!


Let it run unhindered until it finishes.

Distribution Method Spam emails (via mass-mailing worms) p2p file sharing, drive-by downloads (compromised pages).

Trojan Vundo Removal

In the latters case, it's because of a exploit with a bundled Tea program.

  Save it to your desktop, or somewhere you can find it easily.
  According to security research, the infamous Vundo malware may be active again.
  Trojan.Vundo Technical Resume Trojan.Vundo has been monitored to drop malicious executables on targeted systems.

Contents of the 'Scheduled Tasks' folder 2009-01-10 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57] . - - - - ORPHANS REMOVED - - - - MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\bak\qttask.exe Here's the MB log: Malwarebytes' Anti-Malware 1.33 Database version: 1701 Windows 5.1.2600 Service Pack 3 4/27/2009 2:16:52 AM mbam-log-2009-04-27 (02-16-52).txt Scan type: Quick Scan Objects scanned: 61456 Time elapsed: 5 minute(s), Also i can not navigate to that folder on my computer. Please do not PM me for HJT help, we all benefit from posting on the open board.Want to help others?

This tool is not designed to run on Novell

FYI - When fixing it the second time, I noticed when using a FixVundo tool from symantec that the log said the System Volume Information folder was not scanned. Then save the Chktrust.exe file to the root of C as well.(Step 3 to assume that both the removal tool and Chktrust.exe are in the root of the C drive.) Click Click the System Restore tab. Contents of the 'Scheduled Tasks' folder 2009-01-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57] . - - - - ORPHANS REMOVED - - - - BHO-{ADC377BE-7908-4408-BB6D-EDACB6181D72} - c:\windows\system32\awtuvSll.dll . -------

Trojan.vundo Download

Trojan Vundo Removal When the removal of infected objects process is complete, "Restart your system to remove all active threats properly"

Press “Scan”. 4. http://gsdclb.org/trojan-vundo/trojan-vundo-need-help-getting-rid-of-it.php HKEY_CLASSES_ROOT\toolbar.tb (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wuvuhime.dll (Trojan.Vundo.H) -> Delete on reboot. Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-07-16 4670704] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-27 68856] "igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2008-08-01 1103216] "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-17 2356088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] c:\documents and settings\All Users\Start Menu\Programs\Startup\ VAIO

Send email Mail X Share this Subject: Message: Hey !, I found this information for you: "Remove Trojan.Vundo and Terminate is154522.exe, Install.exe". Then, go to Start >Run and enter: cleanmgr Select the drive to clean: C:\ Check the following boxes and then press OK to remove: Temporary Files Temporary Internet Files RecycleBin Agree c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak c:\program files\Adobe\Reader 8.0\Reader\bak c:\program files\AIM\bak c:\program files\ATI Technologies\ATI.ACE\bak c:\program files\Common Files\Real\Update_OB\bak c:\program files\Grisoft\AVG7\bak c:\program files\Java\jre1.6.0_02\bin\bak c:\program files\QuickTime\bak c:\program files\Winamp\bak c:\program files\Yahoo!\Messenger\bak c:\windows\system32\vkyotymd.ini . ((((((((((((((((((((((((( Files Created his comment is here Under Temporary Internet Files, click Delete files...

Terminate.Antivirus Version Update Result AhnLab-V3 2007.6.9.0 06.08.2007 no virus found AntiVir 06.09.2007 no virus found Authentium 4.93.8 05.23.2007 no virus found Avast 4.7.997.0 06.09.2007 no virus found AVG 06.10.2007 Close any programs you may have running - especially your web browser. I've also got an ewido report available if needed.

Click the Remove or Change/Remove button.

Modern forms use a recognition software that looks for that or variations of those names, so call it something completely different. Set it up so it runs in compatibility mode, Windows 2000. Basically, this prevents your computer from connecting to those sites by redirecting them to which is your local computer

or via another and transfer it over.-Name the program something completely different. Sign in Share More Report Need to report the video? Please do not PM me for HJT help, we all benefit from posting on the open board.Want to help others? weblink Completion time: 2009-01-15 15:03:43 ComboFix-quarantined-files.txt 2009-01-15 20:03:03 ComboFix2.txt 2009-01-05 21:19:47 Pre-Run: 52,489,797,632 bytes free Post-Run: 52,797,485,056 bytes free 179 --- E O F --- 2009-01-14 08:02:27 Kaspersky log: -------------------------------------------------------------------------------- KASPERSKY ONLINE