Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Trojan.Vundo Removal

Networking & Security



Reply
 
Thread Tools Search this Thread
  #1  
Old 21-10-2005
Member
 
Join Date: Oct 2004
Posts: 47
Trojan.Vundo Removal

hi can someone help me remove Trojan.Vundo unable to remove this virus
Reply With Quote
  #2  
Old 21-10-2005
Puneet_'s Avatar
Member
 
Join Date: Jul 2004
Location: in dreams
Posts: 2
Re: Trojan.Vundo Removal

did you search google for an answer ?
http://securityresponse.symantec.com...oval.tool.html
__________________
"You can fight without ever winning, but never win without a fight."
-Neil Peart of RUSH
Reply With Quote
  #3  
Old 21-10-2005
Member
 
Join Date: Oct 2004
Posts: 47
Re: Trojan.Vundo Removal

hey already searched a lot but still not able to remove this trojan.vundoo
geez that fix is not working
Reply With Quote
  #4  
Old 21-10-2005
vikas.pal's Avatar
Super Moderator
 
Join Date: Aug 2004
Location: Mumbai
Posts: 24
smile Re: Trojan.Vundo Removal

hi itrama
use the FixVundo.exe in the attachment below
symantec link above has an old version for file.
__________________
www.indiagarage.com
Reply With Quote
  #5  
Old 21-10-2005
vikas.pal's Avatar
Super Moderator
 
Join Date: Aug 2004
Location: Mumbai
Posts: 24
Re: Trojan.Vundo Removal

follow this important steps:
Close all the running programs.

If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.

If you are running Windows Me or XP, turn off System Restore.

Run FixVundo.exe file to start the removal tool in safe mode, once you fiinish scan restart and run this tool again to ensure that the system is clean.

When the tool has finished running, you will see a message indicating whether the threat has infected the computer. The tool displays results similar to the following:
Total number of the scanned files
Number of deleted files
Number of repaired files
Number of terminated viral processes
Number of fixed registry entries

What the tool does:
The Removal Tool does the following:
Terminates the associated processes
Deletes the associated files
Deletes the registry values added by the threat
__________________
www.indiagarage.com
Reply With Quote
  #6  
Old 21-10-2005
Member
 
Join Date: Oct 2004
Posts: 47
cool Re: Trojan.Vundo Removal

thanks a billion vikas finally able to remove in safe mode now re-running the scan

here is the log report.

Symantec Trojan.Vundo Removal Tool 1.3.1
The process "IEXPLORE.EXE" might be affected by the threat. It has been suspended.
The process "winlogon.exe" contained a viral thread (00000494). The thread was terminated.
The process "winlogon.exe" contained a viral thread (00000564). The thread was terminated.
The process "winlogon.exe" contained a viral thread (00000568). The thread was terminated.
The process "explorer.exe" contained a viral thread (0000063C). The thread was terminated.
The process "explorer.exe" contained a viral thread (00000640). The thread was terminated.
The process "explorer.exe" contained a viral thread (00000644). The thread was terminated.
The process "explorer.exe" contained a viral thread (00000648). The thread was terminated.
The process "IEXPLORE.EXE" might be affected by the threat. It has been terminated.

Process: 704 'winlogon.exe'. Module: 'C:\WINDOWS\System32\awvtq.dll' is malicious. Module desactivated!
Process: 1532 'explorer.exe'. Module: 'C:\WINDOWS\System32\awvtq.dll' is malicious. Module desactivated!
Winlogon plugin 'awvtq' -> dll file: 'C:\WINDOWS\System32\awvtq.dll' - is infected!
Deleted the registry key
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvtq".
C:\System Volume Information: (not scanned)
C:\WINDOWS\system32\awvtq.dll: (will be deleted on next reboot)
D:\System Volume Information: (not scanned)
registry: HKEY_CLASSES_ROOT\MSEvents.MSEvents (key deleted)
registry: HKEY_CLASSES_ROOT\MSEvents.MSEvents.1 (key deleted)
registry: HKEY_CLASSES_ROOT\CLSID\{827DC836-DD9F-4A68-A602-5812EB50A834} (key deleted)
registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{827DC836-DD9F-4A68-A602-5812EB50A834} (key deleted)


The Trojan.Vundo removal was successful.
The system will delete 1 Trojan.Vundo files from your PC on next reboot.

Here is the report:

1 file(s) could not be deleted.
They will be deleted on next reboot.

The total number of the scanned files: 83395
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral processes suspended: 1
The number of viral threads terminated: 7
The number of registry entries fixed: 4

The tool initiated a system reboot.
Reply With Quote
  #7  
Old 12-04-2008
unidentified's Avatar
Member
 
Join Date: Sep 2005
Posts: 976
search for tags next time

How to remove TROJAN.VUNDO -- pmkji.dll
Reply With Quote
  #8  
Old 01-10-2008
Member
 
Join Date: Oct 2008
Posts: 3
hey, also try following instructions from this link

How to remove TROJAN.VUNDO -- pmkji.dll

good luck!!!
Reply With Quote
  #9  
Old 01-10-2008
unidentified's Avatar
Member
 
Join Date: Sep 2005
Posts: 976
Quote:
Originally Posted by punkdude600 View Post
hey, also try following instructions from this link

How to remove TROJAN.VUNDO -- pmkji.dll

good luck!!!
What are you trying to prove. I posted the same link long time back?
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads for: "Trojan.Vundo Removal"
Thread Thread Starter Forum Replies Last Post
Vundo/Virtumonde trojan removal geir.moi@gmail.com Security Virus 10 18-03-2009 05:40 AM
Trojan Win32/Vundo.Gen! SamDust Networking & Security 3 15-01-2009 12:20 PM
Trojan Vundo Mhaxx AntiVirus Software 11 01-10-2008 07:00 AM
Removing Trojan.Vundo Neil Security Home Users 3 08-01-2008 06:18 AM
trojan.vundo KJB Security Systems 13 07-01-2008 11:33 AM


All times are GMT +5.5. The time now is 12:39 PM.