lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


 Default 

I Can't Get Rid of TROJAN.VUNDO.H from my PC




Reply
 
Thread Tools
  #11  
Old 15th Mar 2009, 16:07
New Member Group
 
Default I Can't Get Rid of TROJAN.VUNDO.H from my PC

ok 007, here are the next 2 logs you requested. the mbr log when ran from c:/windows...

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
malicious code @ sector 0x4c8ed45 size 0x1ae !
copy of MBR has been found in sector 62 !

it looks the same to me...
and the gmer.log directly after the reboot....

GMER 1.0.15.14939 - http://www.gmer.net
Rootkit scan 2009-03-15 18:49:39
Windows 5.1.2600 Service Pack 3

---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 61: malicious code @ sector 0x4c8ed45 size 0x1ae
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
---- EOF - GMER 1.0.15 ----


as for why I didnt think the online scanner finished everything, well I lookd at it right before going outside and it was only at 7%. it had been scanning for almost an hour at that point. I was outside long enough to feed my puppy and change his water, lets say 10 minutes, and when I had returned the scan was completed. just felt that if it took an hour to get to only 7%, then how could it complete the scan in such a short time from that point. just didnt make sense to me.

not sure if I had mentioned before, but one of the anti virus scanners I was using had to be removed and uninstalled in the beginning. Fix-it utilities 8. for some reason I could not disable the program, even from the start up menu or from the program itself. it just didnt give me the option. without that program installed, things seem to be running a little faster, but malwarebytes still shows the vundo h. this scanner (fix-it) however could see it and it always reported it as removed successfully, but it still showed with malwarebytes, though it could never remove it either...

thanks again...
  #12  
Old 16th Mar 2009, 01:01
Malware Group
 
Default I Can't Get Rid of TROJAN.VUNDO.H from my PC

Hi there theprodigycmb

Just to let you know I have not forgetten you....

I am in the process of checking your MBR Boot Record with other experts and will get back to you as soon as permissable.
__________________
Proud member of ASAP & UNITE
__________________

My System: Steves Rig

Processor(s):
AMD Athlon 64x2 6000+
Motherboard:
ASUS M3N78 Pro
RAM Memory:
Corsair 4GB Dual Channel
Graphics Card(s):
NVIDIA GeForce 8400 GS
Sound Card:
Onboard
Hard Drive(s):
640GB Western Digital HD
Optical Drive(s):
LG Lightscribe
Case / PSU:
Cooling:
Stock HSF
Network / Internet:
20Mb Virgin Media Broadband
Monitor(s):
Hanns-G 19" Widescreen
Operating System(s):
Vista Premium 64x
  #13  
Old 16th Mar 2009, 09:57
New Member Group
 
Default I Can't Get Rid of TROJAN.VUNDO.H from my PC

do what you've gotta do my friend. appreciate the info.
  #14  
Old 16th Mar 2009, 16:40
Malware Group
 
Default I Can't Get Rid of TROJAN.VUNDO.H from my PC

Hi there

Your MBR Boot record is clear.

I notice that you have Malwarebytes Antimalware (MBAM) installed
I want you to run a scan for me..
First I want you to update MBAM so we have the latest definitions onboard
Please open Malwarebytes Antimalware
Now click on the update tab
Next - Click on the Check for updates button.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.[/list]

===============================

Please run a fresh scan with combofix. If you get a requester asking to update combofix please allow it to do so.

Post back with both logs in your next reply, also update me on how things are running
__________________
Proud member of ASAP & UNITE
Reply

Register

Bookmarks

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Vundo.H Will Not Go Away. jbrac25 Virus, Spyware & Security 6 15th May 2009 13:12
Need Help... Can't Get Rid of TROJAN.VUNDO.H. sukun Virus, Spyware & Security 1 2nd May 2009 16:27
Need Help w/ Trojan.Vundo H! Nicholas02 Virus, Spyware & Security 22 22nd Dec 2008 17:59
Trojan.vundo.h , trojan.agent , adware.mirar + MORE! :( sillyarfer Virus, Spyware & Security 1 14th Dec 2008 09:59
Whatever I do I can't get rid of TROJAN.VUNDO.H redsowwer Virus, Spyware & Security 25 3rd Nov 2008 18:10
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.