Spyware / Malware / Virus Removal
Vundo Removal/Malwarebytes
8 min read
Tim F.
Topic Starter
Hello,
I picked up the Vundo trojan on my PC (as identified from Malwarebytes Anti-Malware utility). In order to end the Vundo processes, I ran rkill.com, and without restarting the PC, downloaded a fresh version of Malwarebytes anti-malware utility from another PC, saved it to a flashdrive, then ran it on the infected PC. This is my Malwarebytes log:
Malwarebytes' Anti-Malware 1.44
Database version: 3885
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
3/20/2010 10:01:20 AM
mbam-log-2010-03-20 (10-01-06).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 289486
Time elapsed: 1 hour(s), 8 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 3
Registry Values Infected: 4
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\donikibi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dawesiye.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pesovafo.dll (Trojan.Vundo.H) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8f520f46-b3ef-40eb-88fa-e6b34d62fb52} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8f520f46-b3ef-40eb-88fa-e6b34d62fb52} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{024b7101-a635-470f-9be7-10120c5551d9} (Trojan.Vundo.H) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zobuvusah (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{024b7101-a635-470f-9be7-10120c5551d9} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\letanumed (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\seforuduva (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: sesomowo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\pesovafo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\pesovafo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\donikibi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dawesiye.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gemuyisu.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\hobobamo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pesovafo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\sesomowo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\teliwoje.dll (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\TIM\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> No action take
I did not remove/quarrantine ANYTHING awaiting a response from you to make sure deleting or qaurantining the infected registry files is OK.
Can you please help? I appreciate it.
I am using a Dell Dimension PC with Windows XP Pro, SP2. I have up-to-date McAfee anti-virus and Super Anti-Spyware loaded on the PC.
Again, thank you in advance for the help.
MrCharlie
Welcome to the forum.
Yes you can have MBAM remove/quarrantine them.
Then see if you can run ComboFix:
Download ComboFix here :
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
The complete tutorial on ComboFix can be found HERE
MrC
Yes you can have MBAM remove/quarrantine them.
Then see if you can run ComboFix:
Download ComboFix here :
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you don't know how to disable them then just continue on.
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
The complete tutorial on ComboFix can be found HERE
MrC
Tim F.
Hi Mr. C - Thanks so much for your response. Should I restart after running the Malwarebytes removal, or do the ComboFix thing immediately afterward? Thanks again.
MrCharlie
Please restart the computer before running ComboFix, MBAM will most likely ask you to reboot the computer anyway.
MrC
MrC
Tim F.
Mr. C, It's too late. I had to go somewhere tonight. By the time I returned and read your response, I looked at my PC screen and it was locked. I had no choice but to power down. When the PC powered up, I got a blue screen. This doesn't look good. It was straightforward before, but now it probably is gonna be more of a challenge. The blue screen read:
A problem has been detected and Windows has been shut down to prevent damage to your computer.
The problem seems to be caused by the following files: iastor.sys.
PAGE_FAULT_IN_NONPAGE_AREA
If this is the first time that you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:
Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any windows updates you might need.
If problems continue, disable or remove any any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup options, and then select Safe Mode.
Technical information:
*** STOP: 0x00000050 (0xA23BE72B,0x00000000,0xF7BDC589,0x00000000)
*** iastor.sys - Address F7BDC589 base at F7B0A000, DateStamp426d0c8c
I attempted to restart, then got a screen explaining that windows was shutdown prematurely and asked if I wanted to boot in Regular or Safe Mode. I chose Regular Mode and received this message again. I have not installed ANYTHING on the PC, except maybe the virus that I caught and the prgrams/utilities used to clean the PC, as I described earlier.
I wish I would have just deleted everything as Malwarebytes suggested and restarted, but I had to leave to do some family stuff. I returned home, saw your email and here I am. I am very disappointed and frustrated. I hope you can help me out of this, Mr. C.
Thanks for your time. 
MrCharlie
That sound more like a hardware problem, I actually have the same problem on one of my computers.
Try restoring the computer to Last Known Good Configuration, the link below describes how to do it:
http://support.microsoft.com/kb/307852
Let me know, MrC
Try restoring the computer to Last Known Good Configuration, the link below describes how to do it:
http://support.microsoft.com/kb/307852
Let me know, MrC
Tim F.
Hi Mr. C, Sorry to bother you on a Sunday about this. With your PC, what ended up being the problem? Could the virus have caused some sort of failure with the hardware? I know that may be a stupid question, but it's a little coincidental that all hack has broken loose at once. Bottom line, IF I can boot up using the previous version of the registry, do I still perform the steps as previously described, or should I take other actions when I boot up? THanks again for your time.
MrCharlie
iaStor.sys is a driver for Intel:
http://www.file.net/process/iastor.sys.html
I'm still working on my problem but it's not related to iaStor.sys as yours is.
Try doing as suggested.
What kind of computer is this?
Let me know how you make out, MrC
http://www.file.net/process/iastor.sys.html
I'm still working on my problem but it's not related to iaStor.sys as yours is.
Try doing as suggested.
What kind of computer is this?
Let me know how you make out, MrC
Tim F.
Well, Mr. C - I didn't make out at all. I am running a Dell Dimension 8400 desktop (no longer under warranty). I tried booting up using the "last known good configuration" and got the same screen. I tried again and attempted to boot up in the Safe Mode - same thing. I read the Iastor documentation that you provided a link for. Unfortunately, if I can't boot up into Windows, I really can't do much. How can I diagnose what the problem is? Thanks again.
I know that you probably can't answer this, but could I have picked up a VERY BAD virus that totally wiped out my drives? It's better to know now and prepare me…. I'm not only talking about my C drive, but I also have a D drive that contains LOTS of important information on it.
Please let me know where to go from here.
MrCharlie
Apparently this has been a problem with those Dells:
http://support.dell.com/support/topics/glo…clang=en&cs
http://en.community.dell.com/forums/p/19303109/19584219.aspx
——————————-
Let me run this by the Tech guys and see what the best way to proceed is.
MrC
http://support.dell.com/support/topics/glo…clang=en&cs
http://en.community.dell.com/forums/p/19303109/19584219.aspx
——————————-
Let me run this by the Tech guys and see what the best way to proceed is.
MrC
MrCharlie
OK…this is from Ztruker, one of the tech guys:
Maybe setting the BIOS to RAID Autodetect/ATA will allow him to boot, then do an immediate System Restore.
Once that completes and he reboots, he can go back and set BIOS back to RAID Autodetect/AHCI if that's how it was set originally.
Here's the article:
http://en.community.dell.com/forums/p/19303109/19584219.aspx
Is this something you can handle?
Let us know, MrC
Maybe setting the BIOS to RAID Autodetect/ATA will allow him to boot, then do an immediate System Restore.
Once that completes and he reboots, he can go back and set BIOS back to RAID Autodetect/AHCI if that's how it was set originally.
Here's the article:
http://en.community.dell.com/forums/p/19303109/19584219.aspx
Is this something you can handle?
Let us know, MrC
Tim F.
Hi Mr. C,
Al I can do is try.
My concern is that I don't have the System Restore option available. I've never heard of it, nor do I know if it is loaded on my PC. By your previous comments, it sounds like ComboFix would have installed it for me.
Again, I'll ask this. If I can restore, what would the first step be to get rid of the Vundo or whatever other virus I may have OR will the System Restore get me to the point of a time long long ago when I didn't have a virus?
Thanks again,
Tim
MrCharlie
Tim first of all…please relax.
It's not listed but there's ways to get to it.
Yes ComboFix would have created a new restore point and backed up the registry for safety.
Lets get it back up and running first, there's plenty of programs available to deal with Vundo.
I don't know when the last restore point was made so I can't answer that right now.
Try what was suggested for now…..take your time and follow the directions carefully, MrC
My concern is that I don't have the System Restore option available. I've never heard of it, nor do I know if it is loaded on my PC. By your previous comments, it sounds like ComboFix would have installed it for me.
It's not listed but there's ways to get to it.
Yes ComboFix would have created a new restore point and backed up the registry for safety.
Again, I'll ask this. If I can restore, what would the first step be to get rid of the Vundo or whatever other virus I may have OR will the System Restore get me to the point of a time long long ago when I didn't have a virus?
Lets get it back up and running first, there's plenty of programs available to deal with Vundo.
I don't know when the last restore point was made so I can't answer that right now.
Try what was suggested for now…..take your time and follow the directions carefully, MrC
Tim F.
Hi Mr. C, I am relaxed. I'm just a worrier. I'll let you know if it works. Thanks again. 
Tim F.
Mr. C - I tried changing the bios setting for the drive. It was set to RAID Autodetect/AHCI, so I changed it to RAID/Autodetect/ATA. It didn't make a difference. I also tried booting into the Safe Mode after the change, with the same results. You're right, I have bigger fishes to fry than the System Restore. Any other suggestions, or is it time to take it to the shop?
Thanks again to you and Ztruker. Tim
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI