Unsolved
This post is more than 5 years old
9 Posts
0
6206
February 17th, 2006 21:00
Trojan.Vundo?
I ran the Symantec virus scanner as suggested in the FAQ and got the following:
C:\WINDOWS\SYSTEM32\yabaa.dll is infected with Trojan.Vundo
C:\WINDOWS\ServicePackFiles\i386\tcpacc.dll is infected with Trojan.Vundo
C:\WINDOWS\Downloaded Program Files\bridge.inf is infected with Adware.WinFavorites
C:\Documents and Settings\Kate\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-53b42299-18bf6259.zip is infected with Adware.Winpup
I downloaded FixVundo from Symantec, ran it, and it said that Trojan.Vundo was not found on my computer. Being a rather technologically inept person, I'm confused. Did I do something wrong, and if so, what? Suggestions?
Thanks. :)
C:\WINDOWS\SYSTEM32\yabaa.dll is infected with Trojan.Vundo
C:\WINDOWS\ServicePackFiles\i386\tcpacc.dll is infected with Trojan.Vundo
C:\WINDOWS\Downloaded Program Files\bridge.inf is infected with Adware.WinFavorites
C:\Documents and Settings\Kate\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-53b42299-18bf6259.zip is infected with Adware.Winpup
I downloaded FixVundo from Symantec, ran it, and it said that Trojan.Vundo was not found on my computer. Being a rather technologically inept person, I'm confused. Did I do something wrong, and if so, what? Suggestions?
Thanks. :)
No Events found!



ky331
3 Apprentice
•
15.6K Posts
0
February 18th, 2006 11:00
Rather than FixVundo from Symantec, try running VundoFix from Atribune:
Download VundoFix.exe from http://www.atribune.org/public-beta/VundoFix.exe and save it to your desktop. Make sure it's version 4.2.21 [or later].
See if your Symantec scanner still picks on the two trojan vundo items, or if they're "gone" now...
Inonuffink
2 Posts
0
February 18th, 2006 20:00
TheArrowPen
9 Posts
0
February 18th, 2006 20:00
ky331
3 Apprentice
•
15.6K Posts
0
February 19th, 2006 13:00
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
* Save it to your Desktop
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Follow the directions as indicated
please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.
just reboot if your system "jams"*********************
I have to reiterate that VBG only fixes the VUNDO-based version of WinFixer. If that's what you had, then you should notice an immediate difference after you reboot your system: you should no longer be receiving WinFixer popups, nor any warning messages about trojan vundo/virtumundo. And if so, you've fixed the WinFixer problem.
But if WinFixer is still present after running VBG (or VundoFix), that means you have a different version of WinFixer (such as SurfAccuracy, an installer, or a rootkit), in which case, further analysis [starting with HiJackThis] is required.
I also want to stress that VBG will not solve your other problems (Trojan.download.Conhook, and Dialer.BT.d), but that again, HiJackThis is the prudent way to proceed. If you wish to try this:
Click on Do a System Scan and Save a LogFile
This will automatically open NotePad
Copy the entire file from NotePad: EDIT/SelectAll, EDIT/Copy
Then go to the new forum dedicated for HiJack This logs (**NOT** back here), and PASTE the results there:
http://forums.us.dell.com/supportforums/board?board.id=si_hijack
Be sure to include a detailed description of any problems/errors/warnings you are encountering.
Hopefully, one of the HJT experts will get to it as quickly as possible.
Message Edited by ky331 on 02-19-2006 10:50 AM