Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: cannot permanently kill vundo

  1. #11
    Junior Member
    Join Date
    Mar 2009
    Posts
    6

    Default Vundo/virtumonde removed

    I have been going through the cleanup steps and reviewing the many excellent links provided in your last post from yesterday afternoon. I got a bit of a scare at one point, but I think it was a false alarm. Here is a summary of events.

    As I was reading your links yesterday, McAfee started it's regular scheduled scan in the background and gave me the following "Virus Alert" in a popup...

    Excerpt from McAfee Scan log...

    3/12/2009 4:17:39 PM Deleted NT AUTHORITY\SYSTEM C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP2\A0000225.dll Vundo.gen.aj

    ... end log excerpt.

    I quickly disconnected and shut down. But on starting up, I saw that the bad file was apparently in one of the System Restore files - I had not yet flushed these files per your directions, so I did that and figured that was that.

    Just to be sure, I then did another Spybot update & scan, followed by a MBAM update & scan. Both came out clean.
    Finally, another McAfee update & full scan. The McAfee scan log then showed...

    Scan log excerpt...

    12/03/2009 8:20 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\bekozije.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:20 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\bekozije.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:20 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\biwohojo.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:20 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\biwohojo.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:20 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\bowewore.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\bowewore.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\dezupiye.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\dezupiye.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\eufowd.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\eufowd.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\fejuvn.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\fejuvn.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\fsrfkm.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\fsrfkm.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\malesiba.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\malesiba.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\monept.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\monept.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\rozodobu.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\rozodobu.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\tigahifa.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:21 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\tigahifa.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:21 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\wisolike.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:22 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\wisolike.dll.vir File was deleted as part of Cleaning it
    12/03/2009 8:22 PM Infected GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\yidopamo.dll.vir Vundo.gen.aj (Trojan) (Removable)
    12/03/2009 8:22 PM Deleted GBW-LAPTOP\Gary C:\Qoobox\Quarantine\C\WINDOWS\system32\yidopamo.dll.vir File was deleted as part of Cleaning it

    ... end of excerpt.

    I've never seen the folder "Qoobox" before but my guess is it was created by one of the cleanup programs I ran (Combofix maybe?). Anyway, McAfee deleted the bad files, and even the Qoobox folder was gone when I booted up this morning, so all seems well. If you agree, then I guess our work is done, although I am continuing to implement several of your good tips while I'm still highly motivated.

    And I have to finish by expressing my sincere thanks and appreciation for the work that you and your colleagues are doing in this forum. It is a rare and pleasant experience to find things like this going on; it reminds us of what the internet could and should be, but too often is not.

    Somewhere else in the forum I saw a mention of ways to donate, which I will also be visiting.

  2. #12
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    C:\Qoobox\Quarantine <<< this is where combofix puts the bad stuff it removes. The reason why I posted closing instructions was to first remove combofix (and that stuff would have been removed with it) and second to clean the System Restore files as you understood. If the first two instructions were followed, that stuff should not have been there for MBAM or McAfee to find. To be sure, look on the C:\ drive and delete that folder and contents if it is still there.

    C:\Qoobox <<< that one...all of combofix should have been remove with these instructions:
    Click START then RUN
    Now type or copy Combofix /u in the runbox and click OK.
    Note the space between the X and the U, it needs to be there.
    If there were not followed exactly, then delete any of combofix you see on the computer. Make sure the Recycle Bin on the Desktop is emptied also.
    I'll keep the thread active for a couple of days in case another question comes up.

    Thanks...Phil
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •