Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Vundo Virus - please help
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Vundo Virus - please help
HI,
My McAfee is telling me that I have a vundo virus. I boot up (normal mode) and can't open Window Explorer, run any programs etc and my virus software pops up constantly. I click "remove" at which point I'm told I need to reboot and it all starts again. There was a point at which I couldn't Ctl Alt Del, but I fiddled around in the Registry and removed some dodgy looking programs. I can boot up in Safe Mode though have similar problems, though was able to download and run SpyDoctor - which removed a number of problems, just not the main one. I have also done a RegClean. Can someone pls help, I don't know what else to try. The error I'm getting from my virus software points to: C:\Windows\System32\qoMdDvSk.dll - which I found in the Registry and deleted but it seems to return. Any assistance would be GREATLY appreciated. KikiB |
|
#2
|
||||
|
||||
|
Download VundoFix: http://vundofix.atribune.org/
And do a full scan |
|
|
|
#3
|
||||
|
||||
|
^^
Quote:
|
|
#4
|
|||
|
|||
|
Thanks, did this and it didn't return any errors, so nothing to fix.
|
|
#5
|
||||
|
||||
|
no probs :P congrats
|
|
#6
|
|||
|
|||
|
No, no - the virus is still a problem but Vundo fix didn't "fix" my problem, it didn't return any results.
|
|
#7
|
||||
|
||||
|
ohhhhhhhh my bad, umm then download 'adaware'. its a good anitvirus program, try n see if that detects anything.
|
|
#9
|
||||
|
||||
|
Quote:
Ad-Aware was originally made for Advertisements removal ie Adds It has now expanded to many differents threats including some virus detection (but very minimal) To remove a virus, you will need AntiVirus protection like AVG (and hundreds of others) |
|
|
|
#10
|
|||
|
|||
|
All seems to be OK
kritius, you are a genius. Followed instructions and don't seem to have any further symptoms.
Panda Antirootkit didn't return any results VundoFix didn't return any results The only thing out of the ordinary is that McAfee now alerts me to two programs: - PRC Viewer - Generic Pup g I select "Remove" these and they seem to go away. Though, I think I've done this about three times now (over the past 12 hrs). I have attached the HijackThis and ComboFix log. Someone removed all my AVG quarantined items so I don't have a log for this one. Do you recommend re-running and posting? thanks again for your help, I was about to have a breakdown. |
|
#11
|
||||
|
||||
|
COMBOFIX-Script
|
|
#12
|
|||
|
|||
|
ComboFix Log
Hi, thanks, here is the log.
|
|
#13
|
||||
|
||||
|
I would like you to do an online scan so that we can what else may be in your system,
Run Kaspersky online scanner With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts. Do not go surfing while your resident protection is disabled! Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use. Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
|
|
#14
|
|||
|
|||
|
Kaspersky Report
thanks again, report attached.
|
|
#15
|
||||
|
||||
|
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
For Technical Support, double-click the e-mail address located at the bottom of each menu. Delete the three tools that where used in step 10 of the prelim instructions, smitfraudfix, vundo fix and virtmundobegone, then empty the recycle bin. C:\Documents and Settings\Bowe Family\Local Settings\Temp<====Delete the contents of this folder if not already empty. How is the computer running now? |
|
#16
|
|||
|
|||
|
thanks - all working now
everything is great now - really appreciate your help. K.
|
|
#17
|
||||
|
||||
|
I you post one more HJT log then we'll see if we can finish things off.
|
|
#18
|
|||
|
|||
|
Hijax this log
here you go!
|
|
#19
|
||||
|
||||
|
Fix entries using HiJackThis
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://ssdbsiiam003.in.telstra.com.a...n/Spider90.ocx O21 - SSODL: pmsoarbf - {1BC7AAE6-2682-4539-BE56-70D82823001C} - (no file)
Delete the three tools from step 10 of the prelim instructions by dragging them to the recycle bin and then emptying it. Please download the OTMoveIt2 by OldTimer.
Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.
Re-enable system restore with instructions from tutorial above |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Removing Vundo Virus | Virus & Malware removal | 2 | 04-17-2008 11:02 AM | |
| Help removing Trojan.Vundo virus | Virus & Malware removal | 21 | 02-17-2008 01:33 PM | |
| Virus Sentiments. All Attachments! Vundo, Combo, HJT, BitDefender, VBG. | Virus & Malware removal | 12 | 06-26-2007 07:10 PM | |
| Trojan.Vundo Virus lo1[1] | Virus & Malware removal | 1 | 06-07-2007 09:20 PM | |
| Help needed please with vundo virus | Virus & Malware removal | 23 | 06-04-2007 04:31 PM | |
All times are GMT -4. The time now is 06:32 AM.





