Go Back   TechArena Community > Technical Support > Computer Help > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Trojan Horse Vundo.KA and .JW

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 22-01-2010
T-fit Admin
 
Posts: n/a
Trojan Horse Vundo.KA and .JW

Hi,

running Vista Homebasic on dell 1545 with 4gb ram, had Mcafee installed when
purchased and changed to avg 9 for trial, in between this running out and
deciding on using zonealarm extreme security, something has got in as
initially noted Google search redirects then attempts to lock out my
internet banking (their security measures worked!!) I now have AVG 9 and
Stopzilla running, AVG has listed the Trojan shown above on a daily basis in
csrss.exe and smss.exe, both running from %windir%\System32, nothing seems
to be able to remove this critter!! tried rkill but Stopzilla treats it as a
Trojan too...any thoughts/ help greatly appreciated?

also as a side note when running rootkit scan in AVG9, it reboots laptop
after 2/3 sec and today I now get DCOM service failures which boots the
machine...getting to be a bit of an issue as it is my percy work lap.

Reply With Quote
  #2  
Old 22-01-2010
PsiloKephalos.MegaloGaster
 
Posts: n/a
Re: Trojan Horse Vundo.KA and .JW

Am 22.01.2010 13:21, schrieb T-fit Admin:
> ...getting to be a bit of an issue as it is my percy work lap.
>

Hopefully you've got BackUps to restore your system after reformatting... .

Reply With Quote
  #3  
Old 22-01-2010
Peter Foldes
 
Posts: n/a
Re: Trojan Horse Vundo.KA and .JW

T-fit Admin

First of all replace your User Profile which is corrupt most probably as per your
csrss.exe and smss.exe error indicates and next get rid of Stopzilla and Zone Alarm
which are nothing but useless and trouble makers and replace them with something
like the built in Windows Firewall . Also use the below tool to uninstall Mcafee
correctly which you probably did not and remnants of it are still at work
(Guaranteed)

Mcafee removal Tool
http://service.mcafee.com/FAQDocumen...33&id=TS100507

After run the following two free apps

SuperAntiSpyware
http://www.superantispyware.com/
MalwareBytes
http://www.malwarebytes.com/

When done reboot and post back on how your system stands after


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"T-fit Admin" <admin@tfitinc.co.uk> wrote in message
news:%23S0Ik11mKHA.1552@TK2MSFTNGP04.phx.gbl...
> Hi,
>
> running Vista Homebasic on dell 1545 with 4gb ram, had Mcafee installed when
> purchased and changed to avg 9 for trial, in between this running out and deciding
> on using zonealarm extreme security, something has got in as initially noted
> Google search redirects then attempts to lock out my internet banking (their
> security measures worked!!) I now have AVG 9 and Stopzilla running, AVG has listed
> the Trojan shown above on a daily basis in and smscsrss.exe s.exe, both running
> from %windir%\System32, nothing seems to be able to remove this critter!! tried
> rkill but Stopzilla treats it as a Trojan too...any thoughts/ help greatly
> appreciated?
>
> also as a side note when running rootkit scan in AVG9, it reboots laptop after 2/3
> sec and today I now get DCOM service failures which boots the machine...getting to
> be a bit of an issue as it is my percy work lap.


Reply With Quote
  #4  
Old 23-01-2010
David H. Lipman
 
Posts: n/a
Re: Trojan Horse Vundo.KA and .JW

From: "T-fit Admin" <admin@tfitinc.co.uk>

| Hi,

| running Vista Homebasic on dell 1545 with 4gb ram, had Mcafee installed when
| purchased and changed to avg 9 for trial, in between this running out and
| deciding on using zonealarm extreme security, something has got in as
| initially noted Google search redirects then attempts to lock out my
| internet banking (their security measures worked!!) I now have AVG 9 and
| Stopzilla running, AVG has listed the Trojan shown above on a daily basis in
| csrss.exe and smss.exe, both running from %windir%\System32, nothing seems
| to be able to remove this critter!! tried rkill but Stopzilla treats it as a
| Trojan too...any thoughts/ help greatly appreciated?

| also as a side note when running rootkit scan in AVG9, it reboots laptop
| after 2/3 sec and today I now get DCOM service failures which boots the
| machine...getting to be a bit of an issue as it is my percy work lap.



Go into Safe Mode.

Restore the PC to a restore point prior to the attempted fix or infection.

Hopefully upon reboot the PC will be functioning, albeit probably infected, without DCOM
errors/failures.

Make sure McAfee is FULLY uninstalled.

Uninstall StopZilla.

Download, install, update and then execute, Malwarebytes' Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Trojan Horse Vundo.KA and .JW"
Thread Thread Starter Forum Replies Last Post
Trojan Horse Vundo.KE infection Hajra Networking & Security 5 04-02-2010 09:56 AM
How to delete Trojan vundo PsYcHo 1 Networking & Security 2 24-02-2009 03:22 PM
Trojan Vundo Mhaxx AntiVirus Software 11 01-10-2008 08:00 AM
Removing Trojan.Vundo Neil Windows Security 3 08-01-2008 07:18 AM
trojan.vundo KJB AntiVirus Software 13 07-01-2008 12:33 PM


All times are GMT +5.5. The time now is 01:02 PM.