View Single Post
Old 12-01-2007, 03:37 PM   #4 (permalink)
LonnyRJones
Expert Analyst, Moderator, Security Team
 
Join Date: Sep 2006
Posts: 1,646
OS: xp


Re: vundo removal not possible until yet -

Launch Notepad (Important, not wordpad or other third party text editor), and copy and paste the contents
of the code box below into a new text file. (dont include the word code)
Save it as file name: cfscript.txt
Code:
file::
C:\WINDOWS\SYSTEM32\tuvwxut.dll
C:\WINDOWS\SYSTEM32\pmnnklm.dll
C:\Programme\OiUninstaller.exe
C:\WINDOWS\SYSTEM32\gebxuur.dll
C:\WINDOWS\SYSTEM32\pujgiqdq.dll
registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0c9c1899-4a67-48e4-a3b9-2b4a531c894b}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxuur]
killall::
http://users.pandora.be/bluepatchy/m...s/CFScript.gif
As in the picture above drag and drop cfscript.txt onto combofix.exe
when it is finished a text will open, post it.


"my macaffee said, that I have another trojan called BEA"
We would need to know the files name and location ?
============
Post a scan report from one or both of these free online scans
Panda ActiveScan-Free online scanner,
http://www.pandasoftware.com/products/activescan.htm
Pess "scan your PC now" allow the active x to install (if prompted)
Do a full scan > Click the my computer button
After the scan click see report then Save the report and post it back here please.
If you have problems read the FAQ http://www.pandasoftware.com/actives...q.asp?IdLang=2


http://www.kaspersky.com/virusscanner
Click scan settings and place a check next to use [x]extended database etc etc. Click ok.
Then choose: my computer: scan all your hard drives and mapped disks.
when finished click save as text and post that in your reply.
__________________


Our help is voluntary. But this site needs donations to operate.
LonnyRJones is offline