Results 1 to 10 of 33

Thread: Please help with Vundo and others

Hybrid View

  1. #1
    Join Date
    Aug 2007
    Location
    Southern California
    Posts
    16
    I ran vundofix twice - no infections found
    I reinstalled Vundofix and ran it 2 more times - no infections found
    I rebooted and ran Vundofix twice more - still no infections found

    Still getting unsolicited popups
    Attached Files Attached Files

  2. #2
    Join Date
    Aug 2007
    Location
    Southern California
    Posts
    16
    oops forgot the vundofix.txt
    Attached Files Attached Files

  3. #3
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    While your VundoFix log shows that previously the computer did contain Vundo, it was removed on the 17th, but the Kaspersky log shows the following still there;
    C:\WINDOWS\system32\fccawtt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp

    1. Download VirtumundoBegone and save it to your desktop
    2. Now reboot into Safe Mode.
      1. This can be done tapping the F8 key as soon as you start your computer
      2. You will be brought to a menu where you can choose to boot into safe mode.
      3. Select safe mode with networking using your arrow keys on the keyboard and then press enter.
      4. When you computer reaches the desktop make sure you log in as the same user which you had performed the previous steps,
    3. Once you are logged into safe mode, double-click VirtumundoBeGone.exe file you just downloaded and follow the instructions.
    4. Exit when it has finished, and reboot back to normal mode.
    Another thing noted in the VundoFix log is the presence of old java version is 1.4.2.3. This really leaves your system at risk as this version is not as secure as the newest. Go to Add/Remove and Uninstall this old version. While you are there search also for SpywareQuake. If you find it, uninstall it, if you don't find it don't worry about it.

    The next thing you need to do are the following steps, I would recommend that you print these out so that you will have these to refer to while completing them, because you won't have internet access at that time.

    Download SmitfraudFix (by S!Ri) to your Desktop
    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named: c:\rapport.txt
    Post back here with that report.

  4. #4
    Join Date
    Aug 2007
    Location
    Southern California
    Posts
    16
    Did all 3 steps you recommended.

    VirtumundoBegone found nothing
    SmartfraudFix took about 3 seconds to complete
    Java removed.
    Attached Files Attached Files

  5. #5
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Download and run this program AnalyzerXP 3.7
    Post the log here.

  6. #6
    Join Date
    Aug 2007
    Location
    Southern California
    Posts
    16
    I ran the utility. I wasn't sure what date to put in so I used August 10, 2007, my system was clean then.
    Log file with "All files created since...." was too big to upload (227K), so I scanned executables only.
    Log attached (18K).
    Attached Files Attached Files

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •