Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 01-20-2008, 11:03 AM   #1 (permalink)
Registered User
 
Join Date: Dec 2007
Location: Phoenix
Posts: 254
OS: winxp


Dropper, vundo and perhaps maybe more?

Hey all,

Three days ago I became infected with both Dropper and Vundo (thanks wifey and limewire.... *sighs*)

Anyways, I used AVG, Combofix, Adaware 07, Spybot 1.5, Hijackthis, Vundofixer, TrendMicro Housecall, Spybot Bazooka, and one other program I can't remember.

I basically attacked my computer when these things arrived.

The first thing I noticed was that my C:\ drive and both user accounts on my pc were filled with these files which were named, "p01.tmp" all the way to "p900.tmp". They were all about 1.3 megs in size so you can imagine the amount of space it took up when in all three places.

Combofix apparently deleted those permentally. So I'm good on that!

However, all the fixes for the "Vundo" trojan didn't work,and I knew I had it due to having the program, "pmkjj.exe" in my C:\Windows\System32 folder.

The pmkjj.exe and it's buddy pmkjj.dll continually come back to my drive.

I have tried running all said programs again with no avail. The only file I can manage to delete; even while in safe mode; is pmkjj.exe. The dll file will not be deleted.

I can however go into the command prompt, rename the dll and move it and then delete. But then upon reboot hello respawn!

At this point I am not experiencing any issues as I was before, IE. files spawning all over my drives, excessive pop-ups, continuous freezes of any programs, programs uninstalling themselves, etc.

I just can't bare to think that the ******* is still sitting there. Reformat is an obvious choice but I'm looking for perhaps a way where I can avoid losing some files. No matter how long I spend backing something up I always lose something. And it always ends up being something critically annoying. Like discovering I have to start Oblivion over, from the begining. That's always awesome! Haha!

My hijackthis! log is clean as well as combofix.

FYI: Windows is 100% updated as of 1/19/2008 Windows XP SP2
and there are no "suspicious programs in my add/remove (ah if only it were that simple!)

Last edited by supermep; 01-20-2008 at 11:08 AM.
supermep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-20-2008, 05:29 PM   #2 (permalink)
Moderator Networking Team
 
Cellus's Avatar
 
Join Date: Aug 2006
Location: Canada
Posts: 2,664
OS: Windows Vista Business SP1, Windows XP Professional SP3

My System

Re: Dropper, vundo and perhaps maybe more?

Please take a look at our HijackThis 5 Step Process and post your HijackThis log in our HijackThis Log Help board. A member of our security team will be able to assist you further in cleaning out your machine.

While it may look like your HJT log and combofix appear clean, I would definitely run through the 5 Step Process and post in our HJT help board. We have some very experienced malware fighters in our security team, and they use more than HJT and combofix to make sure you are going strong. Highly recommended.
__________________
TSF Networking Team

Virus/Trojan/Spyware Removal Help
Donate!
Cellus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 01:12 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85