also @ TechSpot: Cookie-blocking browser plugin Ghostery feeds data to the ad industry

Google redirect - Trojan.Vundo .log/.txt attatched

Discussion in 'Virus and Malware Removal' started by BeachJoshua, May 18, 2010.

  1. Broni Malware Annihilator Posts: 40,051   +187

    Yes, you can remove disk at any time.
    Instead of restart, try to shut down your computer, wait a minute and then start it again.
  2. BeachJoshua Newcomer, in training Posts: 49

    Okay, and when I boot, how exactly do I go about getting the file you need?
  3. Broni Malware Annihilator Posts: 40,051   +187

    When the scan was done (while still booted from the CD), it should have produced a log:
  4. BeachJoshua Newcomer, in training Posts: 49

    It did not show a log, I looked for one, computer is now booted.

    Window named RunDLL popped up and says "Error loading bywuut.dll The specified module could not be found."
  5. BeachJoshua Newcomer, in training Posts: 49

    Will combofix reboot my computer? It said something about cd emulations running and said it needs to disable them I hit okay, and it shut down.
  6. BeachJoshua Newcomer, in training Posts: 49

    Now it has frozen on the Welcome screen.. what is going on?
     
  7. BeachJoshua Newcomer, in training Posts: 49

    Shut down computer waited on minute then started up.

    Computer booted, went to run broni.com before I could run it, the computer went blue screen and restarted I've got it in safe mode now.
  8. Broni Malware Annihilator Posts: 40,051   +187

    Try to restart it again.
    If normal mode will get stuck, try safe mode.
  9. BeachJoshua Newcomer, in training Posts: 49

    please wait combofix is preparing to run.

    a red bar and blue bar load up across the screen, don't have time to read what it says, now it's sitting with the please wait.
  10. Broni Malware Annihilator Posts: 40,051   +187

    Be patient...
  11. BeachJoshua Newcomer, in training Posts: 49

    Oh, well before you said be patient, i stopped it, then got fresh combofix.exe ran as admin, it sat the affiliated website thing and I accepted terms, it asked about back up I agreed, the bars ran, it says please wait combofix is preparing to run. attempting to create a new system restore point now it's just sitting, how long do I need to be patient?
  12. Broni Malware Annihilator Posts: 40,051   +187

    I can't tell you, because it depends on severity of infection. Wait 10-15 minutes and let me know, if it progresses in any way.
  13. BeachJoshua Newcomer, in training Posts: 49

    I've got nothing going on... still the same screen.
  14. Broni Malware Annihilator Posts: 40,051   +187

    OK. We have to establish one important rule.
    You don't do anything, but only what I tell you to do.
    ...and no rush. When fighting serious infection, things can't be rushed, or worse things may happen.
    Delete your Combofix file. Download fresh one, but rename combofix.exe to broni.com BEFORE saving it to the desktop.
    Run rKill first, then broni.com
    It all can be done in Safe Mode with Networking.
  15. BeachJoshua Newcomer, in training Posts: 49

    It's doing... nothing... at all... and it has sat for a long time now.
  16. Broni Malware Annihilator Posts: 40,051   +187

    Stop Combofix.

    Delete your GMER file. Download fresh one, run it and post new log.

    Do you have Vista DVD?
  17. BeachJoshua Newcomer, in training Posts: 49

    I have a DVD that is the install DVD for vista if that's what you're asking. I think that's what it is...
  18. Broni Malware Annihilator Posts: 40,051   +187

    What is the exact name of that DVD?

    What about fresh GMER log?
  19. BeachJoshua Newcomer, in training Posts: 49

    It's the vista install disk.

    I tried to run GMER again, and it quit unexpectedly the first time, then the second time before it opened, I got blue screen and computer shut down.
  20. Broni Malware Annihilator Posts: 40,051   +187

    If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.
    If still a problem, still in Safe mode, run it with only "Sections" checked.