Reply
Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: Trojan Vundo help!

[ Edited ]

Hi bohemianbob -

 

I am just logging all of these software tools that Quads is using and how he uses them (to some extent!)

 

Reboot your system and Try running a NAV scan again, followed by Malwarebytes.

 

If clean, then try to enable System Restore again.


 

Quads - is this a trojan carrying a rootkit payload?

 

:smileysurprised:

Message Edited by Compumind on 06-03-2009 12:22 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

delphinium
Posts: 9,680
Kudos: 2,856
Solutions: 283
Registered: ‎11-21-2008

Re: Trojan Vundo help!

Bohemianbob:

 

I can't tell you how pleased I am that all this work paid off for you.  I know Quads will feel very good about it.  Thanks for the photo, we will have to see if we can talk the Mods into a "Rogue's Gallery."

 

Please feel free to call any time if there are any further issues.  Now that you are cleaned out nothing further needs to be done.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Trojan Vundo help!


Compumind wrote:

Hi bohemianbob -

 

I am just logging all of these software tools that Quads is using and how he uses them (to some extent!)

 

Reboot your system and Try running a NAV scan again, followed by Malwarebytes.

 

If clean, then try to enable System Restore again.


 

Quads - is this a trojan carrying a rootkit payload?

 

:smileysurprised:

Message Edited by Compumind on 06-03-2009 12:22 PM
 
I will Not teach anyone over the web how to use the any tools that use scripts or can be dangerous (delete wrong file by mis script Windows won't load).
I do not expect anyone on the Forum to learn by using posters asking for help as Guineia Pigs,  
Use it on your own PC and if something goes wrong with your PC's or friends PC, your problem!!
 
Quads 

 

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Trojan Vundo help!

See if Norton has any "Unresolved Threats" in the history list?? maybe the Qbackup FIX then required

 

I will update a script just with your files.

 

If Vundo doesn't come back over a 24 hour period, then I would say this is solved.

 

Quads 

Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: Trojan Vundo help!

[ Edited ]

Hi Quads -

 

One of the many aspects of this Forum is to learn new techniques for resolving Security issues, such as this.

 

I, for one, appreciate your expertise in this area, with the tools and methods already posted.

 

However, I don't think that it could hurt by hosting a PM "session" to gain some technical insight.

 

Your concerns are quite reasonable, IMHO.

 

Kindly consider it.

 

Thanks :smileyhappy:

Message Edited by Compumind on 06-03-2009 04:16 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

dbrisendine
Posts: 5,562
Kudos: 1,282
Solutions: 263
Registered: ‎10-06-2008

Re: Trojan Vundo help!

You can see these tools being used over various threads here at the Forum.  The real "secret" to the success is not the tools but the craftsman using the tools.  If you don't have the knowledge of what to delete or repair based on the type of variations of the malware being removed than technique is useless.  What worked this time will not work the next time due to each system and user being unique.
Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Trojan Vundo help!


Compumind wrote:

Hi Quads -

 

One of the many aspects of this Forum is to learn new techniques for resolving Security issues, such as this.

 

I, for one, appreciate your expertise in this area, with the tools and methods already posted.

 

However, I don't think that it could hurt by hosting a PM "session" to gain some technical insight.

 

Your concerns are quite reasonable, IMHO.

 

Kindly consider it.

 

Thanks :smileyhappy:

Message Edited by Compumind on 06-03-2009 04:16 PM

There is a difference between learnig about types of malware (not all Viruses) and using a removal method via like say Non Plug N Play in Windows the run SDfix and SAS in safe Mode.
Compared to People Posting Hijackthis logs, PMing me logs to create scripts to remove a rootkit.  Some programs I have are not available for download. People are impressed with Avenger or what has happen, Well due to it being on a forum it is on the conservative side of thing compared to when I am repairing a PC in front of me.
If you want to learn how to do Some major stuff go do the like of an A+ N+ course.
Its' like when something is wrong with your car, if the likes of Spark Plugs, you can replace yourself, but if a camshaft, you go to a Mechanic.
I am sure if using other posters as guinea pigs and things go wrong with peoples PC's all the time Norton Staff /Mods wont be happy!!
Oh and no point you or Pexley PMing me asking to learn programs, that won't work.
I am sure (and I do get PMs) that once other members realise that a poster has a Rootkit or Trojan buried deep, or not removing etc. they will wait or contact me.  I will get there had a few over ther last 2 weeks.
Quads  

 

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Trojan Vundo help!


dbrisendine wrote:
You can see these tools being used over various threads here at the Forum.  The real "secret" to the success is not the tools but the craftsman using the tools.  If you don't have the knowledge of what to delete or repair based on the type of variations of the malware being removed than technique is useless.  What worked this time will not work the next time due to each system and user being unique.
Yep that to, the level of the user at the other end, OS, different Software/ Hardware, as I learned with Tea Timer, different malware, even though it could have the same symptoms.
 
maybe the last few posts need to be in there own thread.
Quads 

 

CPA
Contributor
CPA
Posts: 21
Registered: ‎06-02-2009

Re: Trojan Vundo help!

Hello quads,

 

I have been monitoring these posts and I think that both you and compumind have valid points.

 

It would be interesting to know who would be able to address posts like this, should you decide to retire.

 

No reason that knowledge should be shared, in the proper hands, I think.

 

Marty

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Trojan Vundo help!


CPA wrote:

Hello quads,

 

I have been monitoring these posts and I think that both you and compumind have valid points.

 

It would be interesting to know who would be able to address posts like this, should you decide to retire.

 

No reason that knowledge should be shared, in the proper hands, I think.

 

Marty


Only if you split the programs talked about.
If I was actually there with the person in front of the PC slowly yea I would teach them, as I can see what is typed and stop them if need be before "executing"  But not over the forum.
Even Gurus do get hold of me for this sort of thing. Maybe that is part of being a guru, knowing limitations and not doing something like scripting that you have not done before.
Help Gurus
Quads