geek ('gēk), noun.
1. Obsessive Computer User: somebody who enjoys or takes pride in using computers or other technology, often to what others consider an excessive degree
2. Someone with greater than normal computer skills.

Geeks To Go - Free Computer Help
Welcome Guest ( Log In | Register ) to Geeks to Go Computer Help Forum! Here you'll find free, friendly help and support for all your computing questions. Once registered - you'll have the ability to post your question in the appropriate category below. Additionally, if you can assist another member by sharing your computing knowledge, please feel free to post a reply! Best of all - Registration and all assistance, is FREE! Once you've completed registration, simply click the appropriate category below, click on the "new topic" button, and post your question! What are you waiting for? (registering removes advertising)
Recommended: Click Here for a Free Registry Scan [Sponsored Link]
      
3 Pages V   1 2 3 >  
Reply to this topicStart new topic
> How-to remove Winfixer, Virtumonde, Msevents, Trojan.vundo, ATLDistrib, using Atribune's VundoFix removal tool
admin
post Jan 13 2006, 09:40 AM
Post #1


Site Administrator
Group Icon

Group: Admin
Posts: 16,277
Joined: 21-May 03
Member No.: 1
Operating System:
Windows Vista Ultimate




Do not run this tool on Asian Operating Systems!!! It has bugs with them on it will damage your PC!

How-to remove Winfixer, Virtumonde, Msevents, and Trojan.vundo (ATLDistrib Object) using Atribune's VundoFix removal tool

WinFixer:
Attached Image


Attached Image


Credit: Atribune

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please save the contents of C:\vundofix.txt in case the infection is not removed, it will need to be posted with your HijackThis log in the malware forum.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

If the infection(s) are still present, please post the contents of C:\vundofix.txt and a HiJackThis log in the Malware Removal Forum.

Have you've found the VundoFix removal tool useful? Please consider a donation to the author: Atribune.org.

Alternate fix: (use only if the above fix didn't work)
1) Download VirtumundoBegone
2) Save VirtumundoBeGone.exe to your desktop.
3) Run VirtumundoBeGone.exe and follow the instructions. Do not worry if you see a BLUE SCREEN "Fatal Error" Message, this is normal and expected.
4) When it has finished, reboot.

It will create a log on your desktop called VBG.TXT, if the infection is still present, post this log and a HiJackThis log in the Malware Removal Forum.

=====================================================================
This is a self-help guide. Use at your own risk.

Important Note: If you need assistance, please start a new topic in our Malware Removal Forum. This topic is also open for comments, but not all will receive a reply.

This post has been edited by therock247uk: Yesterday, 06:59 PM


--------------------
Please do not PM me asking for support. Post on the forums instead :)
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!
HijackThis Guide | Free Antivirus Tools | Link to Us

Search the Forums | Terms of Use | Forum Help
Go to the top of the page
 
+Quote Post
admin
post Jul 12 2007, 04:17 PM
Post #2


Site Administrator
Group Icon

Group: Admin
Posts: 16,277
Joined: 21-May 03
Member No.: 1
Operating System:
Windows Vista Ultimate




This topic has been left open to allow specific questions and comments related ONLY to this guide. It's NOT for posting HJT logs, links to your logs, or any other general malware help. Replies not following these rules will be deleted. Thanks for your cooperation.


--------------------
Please do not PM me asking for support. Post on the forums instead :)
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!
HijackThis Guide | Free Antivirus Tools | Link to Us

Search the Forums | Terms of Use | Forum Help
Go to the top of the page
 
+Quote Post
Frusratedgmb
post Jul 24 2007, 11:02 PM
Post #3


New Member
*

Group: Member
Posts: 4
Joined: 8-January 06
Member No.: 154,215
Operating System:
Windows XP



The self-help guide to remove Vundo appears to have cleared up the my problems loading IE and Firefox! Many thanks!

Gina
Go to the top of the page
 
+Quote Post
supermd
post Aug 21 2007, 12:54 AM
Post #4


New Member
*

Group: Member
Posts: 1
Joined: 21-August 07
Member No.: 222,299
Operating System:
Windows XP



I think I have the WinAntiVirus virus. I looked it up on wikipedia and said its similar to winfixer. I ran a Vundo Removal software and it didn't detect it. I've ran numerous antivirus scans and it still does not go away! I just have new infections that pop up. I need help please!!! And I'm new to this, so I'm not sure what you guys mean when you say HiJack This. And I saw on one forum to mess with my regedit-- but that seems risky!
Go to the top of the page
 
+Quote Post
don77
post Aug 21 2007, 05:48 AM
Post #5


Malware Expert
Group Icon

Group: Geek U Moderator
Posts: 18,588
Joined: 5-July 04
From: Boston Ma.
Member No.: 2,804
Operating System:
XP Pro,ME, 98



Hello Supermd and welcome
Have a read Here

That will get you started and someone will be along to help you in the malware forum smile.gif


--------------------
Please do not PM me asking for support. Post on the forums



Don77 Malware Page <--Have I helped you? Please consider donating to help me continue the fight against malware, Thank you

Go to the top of the page
 
+Quote Post
RatHat
post Oct 3 2007, 07:10 PM
Post #6


GeekU Mod
Group Icon

Group: Geek U Moderator
Posts: 3,470
Joined: 26-October 06
From: Lake Mabprachan, Thailand
Member No.: 198,237
Operating System:
XP SP2 ~ IE 7 ~ Firefox ~ Opera



bldu8042,

Please post these logs in a single post, in the Malware Forum.

One of our staff members will pick it up and help you with the malware removal process.

Regards,
RatHat


--------------------
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Want to join the fight against Malware? Click here to find out how.

Please do not PM me asking for support. Post on the forums instead :)
Please post the final results, good or bad. We like to know!




If you feel I have helped you and would like to make a small donation, please click here
Go to the top of the page
 
+Quote Post
zudplucker
post Oct 23 2007, 10:44 PM
Post #7


New Member
*

Group: Member
Posts: 2
Joined: 23-October 07
Member No.: 227,366
Operating System:
xp



This took 5 minutes to fix what I've been struggling with for weeks. Thanks!
Go to the top of the page
 
+Quote Post
don77
post Oct 24 2007, 04:55 PM
Post #8


Malware Expert
Group Icon

Group: Geek U Moderator
Posts: 18,588
Joined: 5-July 04
From: Boston Ma.
Member No.: 2,804
Operating System:
XP Pro,ME, 98



Thanks for taking the time to let us know zudplucker
Glad to hear its all sorted out thumbsup.gif


--------------------
Please do not PM me asking for support. Post on the forums



Don77 Malware Page <--Have I helped you? Please consider donating to help me continue the fight against malware, Thank you

Go to the top of the page
 
+Quote Post
zudplucker
post Oct 26 2007, 12:22 PM
Post #9


New Member
*

Group: Member
Posts: 2
Joined: 23-October 07
Member No.: 227,366
Operating System:
xp



Hey guys,

After I ran this fix, it got rid of the VirtuMode virus which caused all my problems to go away.....but now, when I start my computer, I get a pop up error that says can't find c\windows\system32\scttwewc.dll

Is this a whole new problem I have or do you think this is related to the virus I had. It looks suspiciously like some of the files that my Symantec was quaratining related to the VirtuMode thing.
Go to the top of the page
 
+Quote Post
MoNsTeReNeRgY22
post Oct 26 2007, 12:43 PM
Post #10


Member
*****

Group: Member
Posts: 2,264
Joined: 28-January 07
From: Classified, CA
Member No.: 206,834
Operating System:
Windows XP Media Center Editon SP2



Hi zudplucker and welcome to Geeks to Go!

Please follow the instructions HERE and then post your log in the Malware Removal forum.



Go to the top of the page
 
+Quote Post
BT_RN
post Nov 13 2007, 09:33 PM
Post #11


New Member
*

Group: Member
Posts: 1
Joined: 12-November 07
Member No.: 228,854
Operating System:
XP



I just registered as a new member to Geeks to Go.

I have what I believe is the Virtumonde Malware. As a new member I started to follow the instructions as outlined under the self-help removal guides for "How-to remove WInfixer, Virtumonde, Msevens, ...". Everything was going well until I came to the section that had me reboot my notebook into SafeMode and start a scan using AVG anti-spyware. The program shows that it have 5 objects. I then try to "Apply all Actions" as instructed but receive an error message on the right side of the window which reads, "Errors have been occurred while applying the actions, please inspect the list on the left." When I review each line item the Action column reads "Error while quarantining", for one of the five items. The other 4 items show "Error while deleting!". I have tried this twice with the same results. Could I have a bad copy of the AVG Anti-Spware? Should I try to reinstall AVG and re-run the scan?

Any assistance would be greatly appreciated.


Thanks in advance,
Go to the top of the page
 
+Quote Post
SNOWHITE
post Nov 17 2007, 08:04 AM
Post #12


Trusted Helper
Group Icon

Group: Malware Staff
Posts: 1,325
Joined: 5-September 06
From: Macedonia
Member No.: 191,884
Operating System:
XP Pro, W2K, W98SE



Hello BT_RN,

Please follow steps described here : > You Must Read This Before Posting A Hijackthis Log, Malware Cleaning Guide

Then post HijackThis report at the following forum : Malware Removal - HijackThis™ Logs Go Here

If you don't receive response in no less then 3 days, post at this forum : The Waiting Room


Best regards,


--------------------
SNOWHITE


Go to the top of the page
 
+Quote Post
didit
post Nov 24 2007, 02:52 PM
Post #13


New Member
*

Group: Member
Posts: 1
Joined: 24-November 07
Member No.: 230,013
Operating System:
xp



hello all i ran both vundofix and virtumundobegone but still my malwarebot says i have a vundo downloader in my c:\WINDOWS\system32\vtstq.dll and 2 vundo adwares in my Hkey_local_machine\software\microsoft ... i do not know how i got these and ofcourse would love to remove them
Thanks for your time .
Done
Go to the top of the page
 
+Quote Post
Thunderbird1988
post Nov 25 2007, 03:43 AM
Post #14


Trusted Helper
Group Icon

Group: Malware Staff
Posts: 656
Joined: 8-April 06
From: The Netherlands
Member No.: 170,506
Operating System:
Windows XP/Vista Dualboot



Hello didit and welcome at Geekstogo,

Please read and follow the steps discribed here.

Then post a HijackThislog in the Malware Forum.

This post has been edited by Thunderbird1988: Nov 25 2007, 03:46 AM


--------------------
Please read this before posting a Hijackthislog.
Please do not PM me asking for support. Post on the forums instead :)
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!




Go to the top of the page
 
+Quote Post
jacquelyn
post Dec 2 2007, 09:54 AM
Post #15


New Member
*

Group: Member
Posts: 4
Joined: 2-December 07
Member No.: 230,841
Operating System:
Windows XP



Hello, I believe I have Virtumonde on my computer. I tried Vundofix and Virtumundobegone. And I also used Norton 2008, SpySweeper, and Ad-Aware. And nothing has removed it. Spysweeper detects Adware: Virtumonde but can't remove it. I also found these and I think they are related to the problem: awtqn.dll and gebayyw.dll
If you could help me I'd really appreciate it. Thanks
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Reply to this topicStart new topic
3 User(s) are reading this topic (3 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 16th May 2008 - 02:15 AM
The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.

© Geeks To Go, Inc. | All Rights Reserved | Link to Us!