The code in the Vundo trojan is so badly written, that many users cant go into safe mode because "explorer.exe" is occupied trying to execute these codes and occupies 100% of the CPU capacity.
Please use these revised instructions..
Do this now..
Go to Start > Run - type
msconfig <Press Enter> (
this opens the system configuration utility)
Under the
General Tab, select
Diagnostic Startup & click OK
Reboot your computer when prompted.
* * * * * * * * * * * * * * * *
After you have rebooted, Go to Start > Run - type
msconfig <Press Enter> (
this opens the system configuration utility)
Under the
General Tab, select
Normal Startup & click OK
DO NOT reboot your computer when prompted.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Uninstall the following programs, if present, using Control Panel->Add/Remove Programs:
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Open the
VundoFix folder and doubleclick on
KillVundo.bat
At the introductory screen, press <Enter> to proceed.
When asked to type in a filepath, please key this in:
- C:\WINDOWS\system32\vtsqn.dll
Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Next you will be asked to type in a second filepath.
At this point please type the following file path (make sure to enter it exactly as below!):
- C:\WINDOWS\system32\nqstv.*
Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
The fix should then automatically launch HijackThis. (if it doesn't, you'll have to do it manually)
In HiJackThis, please place a check next to the following items and click
FIX CHECKED:
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEHooks Class - {00000000-0000-0000-0000-000000000240} - blank (file missing)
O2 - BHO: (no name) - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4...23/cpbrkpie.cab
O20 - Winlogon Notify: vtsqn - C:\WINDOWS\system32\vtsqn.dll
After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
Pressing any key will cause a
"Blue Screen of Death" this is normal, do not worry!
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
After rebooting, continue with the instructions below.
If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools>Folder Options> View tab.
- Tick - Show hidden files and folder
- Untick - Hide file extensions for known types
- Untick - Hide protected operating system files
Click Yes to confirm & then click OK
Locate and delete the following folders, if present:
- C:\Program Files\Viewpoint\
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download and install
CleanUp!
Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "
Options..."
Move the arrow down to "
Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
Click
OK
Press the
CleanUp! button to start the program.
It may ask you to reboot at the end, click NO.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Then, perform an online scan with Internet Explorer with
Panda ActiveScan- Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
- Click Scan Now
- Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting
My Computer- If it finds any malware, it will offer you a report.
- Click on see report. Then click Save report
Copy the
results of the ActiveScan and paste them here along with a new
HiJackThis log and the
vundofix.txt file from the vundofix folder into this topic.
__________________
Question - what have you done for the community today?