also @ TechSpot: Weekend Open Forum: Google Chrome OS and the future of cloud computing
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Vundo virus

Closed Thread
Page 2 of 4 1 2 34
Bookmark Thread Tools
  #21  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Go to Add/Remove programs uninstall old HJT.

Reboot

Run CCleaner again both Temp and Registry until the come up clean.

Now install new HJT.

What were the results of the DAF and JavaRa operations?

Mike
  #22  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
BTW,

DAF, gave me this error....

2147319780 encountered trying to register c:\windows\system32\shdocvw.dll
error accesing OLE registry
To remove this ad, sign in. To register for a new account, click here.
  
  #23  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
Java log cleared ...
  #24  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
OK Due to items in your new HJT log we need to run another cleaner.

ComboFix

NOTE: If you have had ComboFix more than a few days old delete and re-download.

Get it here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Or here: http://subs.geekstogo.com/ComboFix.exe

Double click combofix.exe follow the prompts.

When finished, it will open a log.
Attach the log and a new HJT log in your next reply.

Note: Do not click combofix's window while its running. That may cause it to stall.

Mike

EDIT: We will handle the DAF errors after the comob fix.
Do you have or had a Norton product on this computer?

Last edited by mflynn; 11-23-2008 at 01:04 PM..
  #25  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
MIke,

attached logs as rqstd...

combo seemed to run ok..
Attached Files
File Type: txt log.txt (18.0 KB, 4 views)
File Type: log hijackthis.log (6.1 KB, 0 views)
  #26  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
had norton ages ago....

been deleted for some time !
caused more probs than it solved to be honest
  #27  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Oh yeah!

Reboot run it again post new log and neew HJT log!

You were eat up!

See edit in my last post!

Mike
  #28  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
run combo again and HJT..??

whats "eat up"
  #29  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Totally infested like a dog with so many fleas it is being "eat up"!

An American saying!

Mike

EDIT: yes both!
To remove this ad, sign in. To register for a new account, click here.
  
  #30  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
Mike,

rebooted,

ran Combofix again

then HJT...

results attached
Attached Files
File Type: log hijackthis.log (6.1 KB, 1 views)
File Type: txt ComboFix.txt (17.9 KB, 3 views)
  #31  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
One more thing I am surprised is still there.

So 1 more tool!

Download SD Fix to Desktop among other things Catchme to look for RootKits.

http://downloads.andymanchesta.com/R...ools/SDFix.exe

On Desktop run SDdFix It will run (install) then close.

Then reboot into Safe Mode

As the computer starts up, tap the F8 key several times.

On the Boot menu Choose Safe Mode.

Click thu all the prompts to get to desktop.

At Desktop
My Computer C: drive. Double-click to open.

Look for a folder called SD Fix. Double-click to enter SD Fix.

Double-clickto RunThis.bat. Type Y to begin.

SD Fix does its job.

When prompted hit the enter key to restart the computer

Your computer will reboot.

On normal restart the Fixtool will run again and complete the removal process then say Finished,
Hit the Enter key to end the script and load your desktop icons.

Once the desktop is up, the SDFix report will open on screen and also be saved to the SDFix folder as Report.txt.
Copy and paste the Report.txt file to your next post.

Mike
  #32  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
Mike,

here is SDfix log...

please tell me i'm fixed !!

wife to be threatennig divorce already ! lol !
Attached Files
File Type: txt Report.txt (14.6 KB, 4 views)
  #33  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Hopefully after I see a new HJT log.

Have you had a Norton - Symantec product before?

And a status report how is it running.

mike
  #34  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
I had Norton over 2yrs ago and delted it due to errors....

HJT attached...

just found out, i got now system restore point...

no entry in regedit either...
linked to vundo you think ?
Attached Files
File Type: log hijackthis.log (6.2 KB, 2 views)
  #35  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
HJT remove below
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/tech...l/SymAData.cab

Ahhh

Copy all in box then paste to open command prompt!


Still have a bad file.
Code:
cd\
attrib /s qnlifb.dll >"%USERPROFILE%"\Desktop\attrib.txt
exit
exit
Now paste me the attrib.txt from on desktop.

Mike

See edit above

Last edited by mflynn; 11-23-2008 at 03:15 PM..
  #36  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
Mike,
bit lost on that paste bit you posted...
deleted the cab fiel from HJT ref symantec..
  #37  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
""
File not found - qnlifb.dll

"
that was response from paste to desktop !
  #38  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Ok

HJT Remove below

O20 - AppInit_DLLs: qnlifb.dll

OK for wife to go now but you and I will finish a few detials tommorow.

I will post.

Run another MBAM and SAS but only while sleeping or at work!

Mike
  #39  
Old 11-23-2008
TechSpot Member
 
Location: UK
Member since: Nov 2008, 64 posts
System specs
just deleted another 1 from HJT...
refernce to BTinternet...
old service provider..!!

now gonna run MAM n SAS....

Wife 2 B can hang slack bud..

this pc is linked to ptr for daughters homework on printer..
i want it running tip top !
  #40  
Old 11-23-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
We will get it that way but for now i am headed to Dinner and a movie!

It has a few performance issues but you should be clean.

I will look at new logs when I return.

Mike
Closed Thread
Page 2 of 4 1 2 34

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Mal vundo-4 virus removal Virus & Malware removal 0 05-08-2008 07:17 AM
Persistent vundo virus Virus & Malware removal 8 04-25-2008 01:36 AM
Vundo Virus - please help Virus & Malware removal 18 04-19-2008 08:58 AM
Removing Vundo Virus Virus & Malware removal 2 04-17-2008 11:02 AM
Trojan.Vundo Virus lo1[1] Virus & Malware removal 1 06-07-2007 09:20 PM


All times are GMT -4. The time now is 05:19 PM.