Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Need help on Trojan.Vundo [RESOLVED]


  • This topic is locked This topic is locked

#46
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
You said that you had another account on this computer earlier. Do all the sites work on that account? If so, create a new account and see if you can access all sites from that new account also. If so, just copy over all your files from this user account and delete it. Use the new account...
  • 0

Advertisements


#47
ipeh

ipeh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi,

Yeah, I tried that before, it didn't work on any other user account, including newly created ones.

Sorry, I don't mean to be unappreciative after all your help with Vundo and the other problems so far. But do you think I need to just reformat the OS?

Thanks.

ipeh
  • 0

#48
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
I usually don't suggest formatting. It should be a last solution or if the user (you) don't want to spend any more time trying to resolve the problem, then yes, go with the format. Make sure you backup all your important data first.

Before you do that though, do you have another computer that you can use to test the internet out on? I want to make sure it's the computer that's preventing access to these sites and not something else.
  • 0

#49
ipeh

ipeh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi,

Yeah, actually formatting is also the last option I would take.
I didn't do it.

There are 2 other computers in the network that have no problem accessing those sites or any other sites for that matter. They work just fine.
When I connect my mobile to the network and access those sites, I had no problem too.
(I have a wireless network here at home and it's connected to a cable internet. The router and cable modem are connected to the problematic PC. The other 2 notebooks and mobile phone that I mentioned above are connected via wireless)
I think it's only that particular PC that prevents me from accessing those sites, but I don't know why... :)

Thanks.

ipeh
  • 0

#50
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Run the Hoster program again to reset it to the default HOSTS file. Then do the following:

Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000


[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]


Save the file as "delete.reg". Make sure to save it with the quotes. Close Notepad. Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

Restart the computer and see if you have any luck with it now. If not, do the following:

Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

ipconfig /all > c:\delete.txt
start c:\delete.txt
del delete.txt


Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it to run it. Post the notepad file (which should open automatically).
  • 0

#51
ipeh

ipeh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Oopps!!!

I forgot to run the Hoster and went straight to running the "delete.reg".
Would it cause anything?

Anyway, it's still not working, so I ran the "delete. bat" file.

Here's the delete.txt file:



Windows 2000 IP Configuration



Host Name . . . . . . . . . . . . : patmon
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Mixed

IP Routing Enabled. . . . . . . . : Yes

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : firstmedia.com

Ethernet adapter Cable Modem:



Connection-specific DNS Suffix . : firstmedia.com
Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-11-D8-A3-E5-0A

DHCP Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.102

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 202.155.0.10
202.155.0.15
Lease Obtained. . . . . . . . . . : Sunday, December 02, 2007 9:10:24 AM

Lease Expires . . . . . . . . . . : Monday, December 03, 2007 9:10:24 AM


Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Cable Disconnected

Description . . . . . . . . . . . : Realtek RTL8139(A)-based PCI Fast Ethernet Adapter
Physical Address. . . . . . . . . : 00-80-48-2E-0E-5E


Thx!

ipeh
  • 0

#52
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Can you check your other computers to see if they have the same settings for the DNS Server? I think you might have to remove the DNS settings. They may be blocking the sites.
  • 0

#53
ipeh

ipeh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
Hi greyknight17,

After everything we tried... it turned out the DNS was the culprit!!!

It's working fine now.
I can visit all those sites.

Thanks heaps man.
Really appreciate all your help for this past month.

Anything else I should do next?
Or should I just close the thread?

Take care!

ipeh
  • 0

#54
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Phew, glad we resolved that. Don't know why I didn't pick that up earlier :)

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

No need. I will mark this topic as resolved since it looks like everything is ok now on your end :)
  • 0

#55
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

Advertisements







Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP