Trojan.Vundo - Newdotnet - PLEASE HELP! [RESOLVED]
Started by
MsHelpless
, Nov 15 2005 08:00 PM
#16
Posted 25 November 2005 - 05:37 PM
#17
Posted 25 November 2005 - 08:59 PM
Hi again,
I ran Panda Activescan, but it came up completely clean, so it didn't generate a report. I would run TrojanHunter or Ewido, but my trial period has run out. I would be willing to buy one of them if you think it would be a good idea.
Is there some other program I should run? Is Vundo hidden somewhere on my machine?
Thanks so much for all of your help. I really appreciate it.
Tracy
I ran Panda Activescan, but it came up completely clean, so it didn't generate a report. I would run TrojanHunter or Ewido, but my trial period has run out. I would be willing to buy one of them if you think it would be a good idea.
Is there some other program I should run? Is Vundo hidden somewhere on my machine?
Thanks so much for all of your help. I really appreciate it.
Tracy
#18
Posted 25 November 2005 - 09:05 PM
Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
- Click the Free Trial link under to "SpySweeper" to download the program.
- Install it. Once the program is installed, it will open.
- It will prompt you to update to the latest definitions, click Yes.
- Once the definitions are installed, click Options on the left side.
- Click the Sweep Options tab.
- Under What to Sweep please put a check next to the following:
- Sweep Memory
- Sweep Registry
- Sweep Cookies
- Sweep All User Accounts
- Enable Direct Disk Sweeping
- Sweep Contents of Compressed Files
- Sweep for Rootkits
- Please UNCHECK Do not Sweep System Restore Folder.
- Click Sweep Now on the left side.
- Click the Start button.
- When it's done scanning, click the Next button.
- Make sure everything has a check next to it, then click the Next button.
- It will remove all of the items found.
- Click Session Log in the upper right corner, copy everything in that window.
- Click the Summary tab and click Finish.
- Paste the contents of the session log you copied into your next reply.
#19
Posted 25 November 2005 - 10:14 PM
I tried this, but I forgot, I had the trial version before I found Geekstogo, so it is expired as well. Is this something I should purchase?
I have had System Restore turned off since I contracted Trojan.Vundo, is that how it should be until my computer is completely clean?
Thanks again
I have had System Restore turned off since I contracted Trojan.Vundo, is that how it should be until my computer is completely clean?
Thanks again
#20
Posted 25 November 2005 - 10:23 PM
Try deleting the file C:\WINDOWS\Cursors\hardnet.dll then seing if norton keeps poping up.
#21
Posted 25 November 2005 - 10:29 PM
sorry, I cannot delete the darn thing. Access is denied.
#22
Posted 25 November 2005 - 10:32 PM
Hmm ok I will post something tommorow im off for the nite 4:33 am here.
#23
Posted 25 November 2005 - 10:33 PM
Thanks!! You sure work a lot! :-)
#24
Posted 26 November 2005 - 06:58 AM
Click here to download Pocket Killbox by Option^Explicit. Then double-click on Killbox.exe to run Killbox. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:
C:\WINDOWS\Cursors\hardnet.dll
For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.
C:\WINDOWS\Cursors\hardnet.dll
For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.
#25
Posted 26 November 2005 - 03:56 PM
Thank you so much!! I had to remove one more file through Norton, but now everything is clean! Norton finds no threats! I can't tell you how much I appreciate your help. You're a lifesaver. I will happily be donating to the site.
And, Excal too! You got me through so much of the fix. Thank you!!
You guys are the best!
Tracy
And, Excal too! You got me through so much of the fix. Thank you!!
You guys are the best!
Tracy
#26
Posted 26 November 2005 - 07:41 PM
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users