
Need help on Trojan.Vundo [RESOLVED]
Started by
ipeh
, Oct 30 2007 08:44 AM
#46
Posted 24 November 2007 - 12:17 PM

#47
Posted 26 November 2007 - 01:27 AM

Hi,
Yeah, I tried that before, it didn't work on any other user account, including newly created ones.
Sorry, I don't mean to be unappreciative after all your help with Vundo and the other problems so far. But do you think I need to just reformat the OS?
Thanks.
ipeh
Yeah, I tried that before, it didn't work on any other user account, including newly created ones.
Sorry, I don't mean to be unappreciative after all your help with Vundo and the other problems so far. But do you think I need to just reformat the OS?
Thanks.
ipeh
#48
Posted 27 November 2007 - 10:30 AM

I usually don't suggest formatting. It should be a last solution or if the user (you) don't want to spend any more time trying to resolve the problem, then yes, go with the format. Make sure you backup all your important data first.
Before you do that though, do you have another computer that you can use to test the internet out on? I want to make sure it's the computer that's preventing access to these sites and not something else.
Before you do that though, do you have another computer that you can use to test the internet out on? I want to make sure it's the computer that's preventing access to these sites and not something else.
#49
Posted 29 November 2007 - 07:27 AM

Hi,
Yeah, actually formatting is also the last option I would take.
I didn't do it.
There are 2 other computers in the network that have no problem accessing those sites or any other sites for that matter. They work just fine.
When I connect my mobile to the network and access those sites, I had no problem too.
(I have a wireless network here at home and it's connected to a cable internet. The router and cable modem are connected to the problematic PC. The other 2 notebooks and mobile phone that I mentioned above are connected via wireless)
I think it's only that particular PC that prevents me from accessing those sites, but I don't know why...
Thanks.
ipeh
Yeah, actually formatting is also the last option I would take.
I didn't do it.
There are 2 other computers in the network that have no problem accessing those sites or any other sites for that matter. They work just fine.
When I connect my mobile to the network and access those sites, I had no problem too.
(I have a wireless network here at home and it's connected to a cable internet. The router and cable modem are connected to the problematic PC. The other 2 notebooks and mobile phone that I mentioned above are connected via wireless)
I think it's only that particular PC that prevents me from accessing those sites, but I don't know why...

Thanks.
ipeh
#50
Posted 01 December 2007 - 03:23 PM

Run the Hoster program again to reset it to the default HOSTS file. Then do the following:
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
Save the file as "delete.reg". Make sure to save it with the quotes. Close Notepad. Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.
Restart the computer and see if you have any luck with it now. If not, do the following:
Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:
ipconfig /all > c:\delete.txt
start c:\delete.txt
del delete.txt
Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it to run it. Post the notepad file (which should open automatically).
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
Save the file as "delete.reg". Make sure to save it with the quotes. Close Notepad. Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.
Restart the computer and see if you have any luck with it now. If not, do the following:
Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:
ipconfig /all > c:\delete.txt
start c:\delete.txt
del delete.txt
Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it to run it. Post the notepad file (which should open automatically).
#51
Posted 01 December 2007 - 08:20 PM

Oopps!!!
I forgot to run the Hoster and went straight to running the "delete.reg".
Would it cause anything?
Anyway, it's still not working, so I ran the "delete. bat" file.
Here's the delete.txt file:
Windows 2000 IP Configuration
Host Name . . . . . . . . . . . . : patmon
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Mixed
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : firstmedia.com
Ethernet adapter Cable Modem:
Connection-specific DNS Suffix . : firstmedia.com
Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-11-D8-A3-E5-0A
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 202.155.0.10
202.155.0.15
Lease Obtained. . . . . . . . . . : Sunday, December 02, 2007 9:10:24 AM
Lease Expires . . . . . . . . . . : Monday, December 03, 2007 9:10:24 AM
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Cable Disconnected
Description . . . . . . . . . . . : Realtek RTL8139(A)-based PCI Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-80-48-2E-0E-5E
Thx!
ipeh
I forgot to run the Hoster and went straight to running the "delete.reg".
Would it cause anything?
Anyway, it's still not working, so I ran the "delete. bat" file.
Here's the delete.txt file:
Windows 2000 IP Configuration
Host Name . . . . . . . . . . . . : patmon
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Mixed
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : firstmedia.com
Ethernet adapter Cable Modem:
Connection-specific DNS Suffix . : firstmedia.com
Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-11-D8-A3-E5-0A
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 202.155.0.10
202.155.0.15
Lease Obtained. . . . . . . . . . : Sunday, December 02, 2007 9:10:24 AM
Lease Expires . . . . . . . . . . : Monday, December 03, 2007 9:10:24 AM
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Cable Disconnected
Description . . . . . . . . . . . : Realtek RTL8139(A)-based PCI Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-80-48-2E-0E-5E
Thx!
ipeh
#52
Posted 02 December 2007 - 05:55 PM

Can you check your other computers to see if they have the same settings for the DNS Server? I think you might have to remove the DNS settings. They may be blocking the sites.
#53
Posted 02 December 2007 - 07:04 PM

Hi greyknight17,
After everything we tried... it turned out the DNS was the culprit!!!
It's working fine now.
I can visit all those sites.
Thanks heaps man.
Really appreciate all your help for this past month.
Anything else I should do next?
Or should I just close the thread?
Take care!
ipeh
After everything we tried... it turned out the DNS was the culprit!!!
It's working fine now.
I can visit all those sites.
Thanks heaps man.
Really appreciate all your help for this past month.
Anything else I should do next?
Or should I just close the thread?
Take care!
ipeh
#54
Posted 05 December 2007 - 07:46 PM

Phew, glad we resolved that. Don't know why I didn't pick that up earlier 
To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.
No need. I will mark this topic as resolved since it looks like everything is ok now on your end

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.
No need. I will mark this topic as resolved since it looks like everything is ok now on your end

#55
Posted 05 December 2007 - 07:46 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. 
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Similar Topics
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
As Featured On:






