Computing.Net > Forums > Security and Virus > vundo virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

vundo virus?

Reply to Message Icon

Name: annej55
Date: March 22, 2009 at 16:56:35 Pacific
OS: Windows XP
Product: Hewlett-packard / Zv6000
Subcategory: Viruses
Comment:

i had some pop up ads then ran my virus/malware/spyware programs and it found files that say vundo. i downloaded the vundofix program and it didnt find any files. what can i do to fix this?



Sponsored Link
Ads by Google

Response Number 1
Name: annej55
Date: March 22, 2009 at 19:08:32 Pacific
Reply:

this is my malwarebytes after I ran the vundo fix.exe from vundofix.org


Malwarebytes' Anti-Malware 1.34
Database version: 1887
Windows 5.1.2600 Service Pack 3

3/22/2009 8:51:48 PM
mbam-log-2009-03-22 (20-51-48).txt

Scan type: Full Scan (C:\|)
Objects scanned: 185934
Time elapsed: 1 hour(s), 21 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\bowajd.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f700871f-a33c-401e-bd55-e13db59756e9} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f700871f-a33c-401e-bd55-e13db59756e9} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{04f1db7b-ed0e-4e7a-a40c-2806a059cdd9} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04f1db7b-ed0e-4e7a-a40c-2806a059cdd9} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04f1db7b-ed0e-4e7a-a40c-2806a059cdd9} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\75a17511 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm7692468d (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bofinamima (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\bowajd.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\yupabeda.dll (Trojan.Vundo) -> Quarantined and deleted successfully.


0

Response Number 2
Name: Jennifer SUMN
Date: March 23, 2009 at 08:17:37 Pacific
Reply:

Did you disable System Restore, delete all that Malwarebytes detected and then reboot?

EEOC


0

Response Number 3
Name: annej55
Date: March 23, 2009 at 11:01:13 Pacific
Reply:

i didn't turn off the system restore, i will do that. i have a couple of files i haven't been able to delete, hopefully that will work.


0

Response Number 4
Name: annej55
Date: March 23, 2009 at 13:40:03 Pacific
Reply:

i've got the system restore off and i still have a couple things in my registry that when i delete them and they come back when i refresh, these are the files:

hkcr\clsid\{f700871f-a33c-401e-bd55-e13db59756e9}

hklm\software\microsoft\windows\currentversion\run\
bonfinamima

how can i get rid of these. also when i get online i get messages from my antivirus that things are trying to install on my computer. so i don't know if its because of these files or if the programs i am using are not catching everything.

i have run webroot antivirus w/antispyware, spyhunter and malwarebytes, each of them pick up different files


0

Response Number 5
Name: annej55
Date: March 24, 2009 at 01:52:02 Pacific
Reply:

i have followed the instructions on the www.pcthreat.com and still can't get rid of this. i am not able to delete the files and none of my programs are able to either. is there anything else i can do?


0

Related Posts

See More



Response Number 6
Name: james88
Date: March 25, 2009 at 00:46:17 Pacific
Reply:

try removing vundo manually, follow the manual removal instructions
http://security-threads.com/trojan-...


0

Response Number 7
Name: annej55
Date: March 26, 2009 at 00:40:19 Pacific
Reply:

thanks for the advice. i tried that and it seems like i got everything. i also ran a program called exterminateit and that found mostly everything. my computer seems to be working better now and i was able to delete the files i couldn't get deleted before.

is there anything i can do to make sure everything is gone? i am just worried cause every program i used showed me different results but most of them are coming up as nothing found, except in malwarebytes it says that i have something disabled but isn't listed as the vundo virus


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: vundo virus?

Vundo virus cannot uninstall www.computing.net/answers/security/vundo-virus-cannot-uninstall/20490.html

Trojan.Vundo Virus Unable Repair www.computing.net/answers/security/trojanvundo-virus-unable-repair/16663.html

Vundo Virus And Slow Computer www.computing.net/answers/security/vundo-virus-and-slow-computer/20365.html