also @ TechSpot: ATI Radeon HD 5970 Review: Dual-GPU Graphics
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Help needed please with vundo virus

Closed Thread
Page 1 of 2 1 2
Bookmark Thread Tools
  #1  
Old 05-31-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
Help needed please with vundo virus

I am having problems with my tower computer, when rebooting my anti virus brings up a scan message window that says Vundo is dectected, I am given the option to clean delete or move the file but each time I click an option it just says 'clean failed', 'delete failed' etc. I cannot download any vundo fix as I cannot open windows explorer, it either just will not open or just opens then shuts down again. If I boot up in safe mode I cannot connect to the internet. I have managed to run my AVG, adaware and spybot be it very slowly other applications will open but very very slowly.

Any help will be gratefully received

Could I download the vundo fix onto my laptop and put it on a memory stick to transfer it to my tower computer, if so how should I run the fix?
thanks in advance Linda
  #2  
Old 05-31-2007
CCT CCT is offline
TechSpot Evangelist
 
Location: Canukistan
Member since: Apr 2007, 3,538 posts
Have you tried booting in Safe Mode with Networking (assuming that your OS supports that)?


Send a private message to momok or Howard Hopkinson - they somehow missed you.


To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 05-31-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
yes just worked that out AFTER I had posted on the thread, embarrassed or what, you replied before I reposted, have just managed to download it and got rid of it(I think). Am now working through HH's thread on 'Viruses/Spyware/Malware, preliminary removal instructions' and will post a HJT log to ensure it has gone. Thanks
  #4  
Old 05-31-2007
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Hi

Important: Please read this thread HERE before you decide whether to clean or reformat your system.

Should you decide to clean your computer, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. These are a comprehensive mix of steps to remove common malware, as well as provide us logs of your system to look at so we can further remove any tricky nasties.
Do follow all the instructions exactly.

Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste if not it will be ignored and/or removed.

Also, please let me know the results of the AVG Antirootkit scan


Regards,
Your friendly momok =)

This thread is for the use of lindylou2 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  #5  
Old 06-01-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
Hi here is my HJT file, combofix file and avg spyware scan. The AVG scan and Antirootkit scan was clean. Thanks in advance Linda
Attached Files
File Type: txt combofix log.txt (11.3 KB, 1 views)
File Type: txt hijackthis log file 1.txt (10.8 KB, 1 views)
File Type: txt avg scan report.txt (4.2 KB, 1 views)

Last edited by lindylou2; 06-01-2007 at 08:46 AM..
  #6  
Old 06-01-2007
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Hi,

Please download and run CCleaner via step 9 of the instructions HERE.

You may wish to copy and paste these instructions on notepad for easier reference later.

Boot into safe mode under your normal user name. See how HERE

Next turn on "Show all files and folders, including hidden and system". See how HERE

Open your task manager by pressing holding ctrl, alt and pressing del. Alternatively, use ctrl + shift + esc. Go to the processes tab, and end the following processes, if found:

gog.exe
bbb.exe
uuu.exe


After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

Close HJT.


Navigate in Windows Explorer and delete the following files and folders in bold.

C:\WINDOWS\system32\mljgf.dll
C:\DOCUME~1\Megan\gog.exe
C:\DOCUME~1\Megan\bbb.exe
C:\DOCUME~1\Megan\uuu.exe
C:\WINDOWS\system32\F87783B3D3.sys
C:\Program Files\MSN Messenger\msrr.exe

Reboot into normal mode and rehide your protected OS files.

Thereafter, please post fresh HJT and ComboFix logs from normal mode as attachments into this thread.


Regards,
Your friendly momok =)

This thread is for the use of lindylou2 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  #7  
Old 06-01-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
Hi thanks for your reply, am following your instructions, did not find any files with the gog.exe etc.

I am struggling to find "Navigate in Windows Explorer and delete the following files and folders in bold.

C:\WINDOWS\system32\mljgf.dll
C:\DOCUME~1\Megan\gog.exe
C:\DOCUME~1\Megan\bbb.exe
C:\DOCUME~1\Megan\uuu.exe
C:\WINDOWS\system32\F87783B3D3.sys
C:\Program Files\MSN Messenger\msrr.exe"

How do I locate these folders in windows explorer, please could you give me more detailed instructions.
Many thanks Linda
  #8  
Old 06-01-2007
Banned
 
Member since: Aug 2004, 25,945 posts
momok isn`t around at the moment, so in the meantime, please do the following.

[b]In Windows Explorer, turn on "Show all files and folders, including hidden and system".[/b] See how [URL="http://www.bleepingcomputer.com/forums/tutorial62.html"]HERE[/URL].

1. Please download The Avenger by Swandog46 from [URL="http://swandog46.geekstogo.com/avenger.zip"]HERE[/URL]. Save it to your Desktop and extract it.

2. Download the attached avengerscript.txt and save it to your desktop. [b]The Avenger script is attached to the bottom of this post.[/b]

[b]Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.[/b]

3. Now, start The Avenger program by double clicking on its icon on your desktop.

Under "Script file to execute" choose "Load script from file".
Now click on the folder icon which will open a new window titled "open Script File"
navigate to the file you have just downloaded, click on it and press open
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

5. Please attach the content of c:\avenger.txt into your reply, as well as fresh HJT and Combofix logs.

Regards Howard

[color=red][b]This thread is for the use of[/color] lindylou2 [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
Attached Files
File Type: txt avengerscript.txt (261 Bytes, 12 views)

Last edited by howard_hopkinso; 06-02-2007 at 08:45 AM..
  #9  
Old 06-02-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts

Sorry but I don't seem to be able to open the avenger file, is unzipped, but won't 'load script from file' just gives me error code. What am I doing wrong

My desktop now has that many icons to 'fix-it programmes' on it now I am loosing the background (and the will to live!!!) :giddy:
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 06-02-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Delete the Avenger you downloaded and try again.

Regards Howard

[color=red][b]This thread is for the use of[/color] lindylou2 [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #11  
Old 06-02-2007
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Hi,

Did you unzip the files (both avenger program and the script from howard) to desktop? You need to open the avenger program first, and then choose to "load script from file".


Regards,
Your friendly momok =)

This thread is for the use of lindylou2 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  #12  
Old 06-02-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
:giddy: Thats what I can't find the script from Howard.
Have now totally lost the will to live:giddy: :giddy:

Linda
  #13  
Old 06-02-2007
Banned
 
Member since: Aug 2004, 25,945 posts
It`s attached to my post#8

Regards Howard

[color=red][b]This thread is for the use of[/color] lindylou2 [color=red]only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #14  
Old 06-02-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
just found it now, and realised why it wouldn't work, please be aware that I need simple step by step, details, you experts forget us lay people are thick its workin its magic now, onto the next bit! I remain ever hopeful that one day I will get a simple virus that I can just delete normally!!

Last edited by lindylou2; 06-02-2007 at 08:18 AM..
  #15  
Old 06-02-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Don`t be so hard on yourself.

I did try and give you step by step instructions.

If you ever have any difficulty in following any of the instructions, just ask and tell us which bit you don`t understand.

Regards Howard
  #16  
Old 06-02-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
Thank for sparing my blushes, I followed your instructions but what you didn't say was "put in text that I have attached to bottom of this message into Avenger' pointed out with a big arrow! only saw it later thought the script was in the avenger file and was looking for it there.

Attached Avenger file, combo file and HJT file
Need a strong drink and a lie down now
Attached Files
File Type: txt combofix.txt 3.txt (11.1 KB, 2 views)
File Type: txt avenger.txt 1.txt (2.3 KB, 3 views)
File Type: txt hijackthis.log 3.txt (10.8 KB, 2 views)

Last edited by lindylou2; 06-02-2007 at 08:54 AM..
  #17  
Old 06-02-2007
Banned
 
Member since: Aug 2004, 25,945 posts
I have altered the instructions for the Avenger script and will always use them from now on. Thanks for pointing it out.

Your logfiles look clean. How`s your system running?

Regards Howard

[color=red][b]This thread is for the use of[/color] lindylou2 [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #18  
Old 06-02-2007
momok's Avatar
TS Special Forces
 
Location: Singapore
Member since: Mar 2007, 2,269 posts
Hi,

Your logs look clean now.

Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

Turn off system restore (XP/ME only). Learn how to do that HERE.
This will remove all the remaining nasties from your old restore points.

After that turn system restore back on.
This would have created a new safe and clean restore point for your system.

Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
May I recommend you to read this article.
This can help to prevent future infections.

Should you have any further problems, please post in this thread.


Regards,
Your friendly momok =)

This thread is for the use of lindylou2 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.

Last edited by momok; 06-02-2007 at 09:02 AM..
  #19  
Old 06-02-2007
lindylou2's Avatar
Newcomer, in training
 
Location: Burnley
Member since: Mar 2007, 23 posts
Computer seems fine now, how long it remains so is debatable, I am sure its that msn/windows messenger used by daughter that lets all the creepy crawlies in. I have more spyware and virus checkers and cleaners etc than ever before, especially after what you said last time when I had problems with the laptop compter.

Thank you all for your help.

So computer is ok now, no nasties on it?

Will now spend the next hour removing some of the icons so I can find my desktop again!
Linda
ps will read suggested articles
  #20  
Old 06-02-2007
Banned
 
Member since: Aug 2004, 25,945 posts
You can remove all the tools that have been used.

I suggest you keep the following.

[URL="http://www.safer-networking.org/en/download/index.html"]Spybot Search & Destroy[/URL].

[URL="http://www.majorgeeks.com/download506.html"]Ad-Aware se personal.[/URL]

[URL="http://www.javacoolsoftware.com/downloads.html"]Spyware Blaster.[/URL]

[URL="http://free.grisoft.com/doc/5390/lng/us/tpl/v5"]AVG Antispyware.[/URL]

[URL="http://www.filehippo.com/download_ccleaner/"]Ccleaner[/URL].

Regards Howard

[color=red][b]This thread is for the use of[/color] lindylou2 [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
Closed Thread
Page 1 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Vundo Virus & Malware removal 3 03-22-2007 09:18 PM
Symantec Vundo pop ups Virus & Malware removal 4 12-19-2006 09:45 PM
B.Exe and Vundo problems Virus & Malware removal 15 12-09-2006 12:22 PM
Virus/spyware Problem help needed, please. Virus & Malware removal 11 07-18-2006 03:08 AM
Help needed -- virus/trojans will not go away! Virus & Malware removal 2 03-10-2006 10:24 PM


All times are GMT -4. The time now is 11:56 AM.