Thread: Browser Hijacks
View Single Post
Old 11-24-2006, 12:09 PM   #4 (permalink)
Linkmaster
Analyst, Security Team
 
Linkmaster's Avatar
 
Join Date: Jul 2006
Location: Arkansas, USA
Posts: 299
OS: XP Pro


Open Windows Explorer, locate and Delete the following folders or files in RED : (if present)

C:\WINDOWS\system32\tmp39B.tmp.dll

Empty your Recycle Bin

Run VundoFix
Double-click VundoFix.exe
Click the Scan for Vundo button.
When it finishes scanning, Right Click inside the listbox (white box) and click add more files
Copy&Paste the following files in the 2 boxes :

BOX 1 : C:\WINDOWS\system32\cam3d9.dll

BOX 2 : C:\WINDOWS\SYSTEM32\9d3mac.*

Click Add Files and Click Close Window
The files will be added to the Scan results list
Click the Remove Vundo button
You will receive a prompt asking if you want to "remove the files", click YES
Once you click yes, your desktop will go blank as it starts removing Vundo
When completed, it will prompt that it will reboot your computer, click OK
The .txt file will be in C:\Vundofix.txt

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot

Please run Panda's ActiveScan and perform a full system scan.
Once you are on the Panda site click the Scan your PC button (be sure to disable your popup blocker first )
A new window will open...click the big Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
Click on Local Disks to start the scan
Click on see report Then click Save report

Post a fresh HijackThis log, the Panda Active Scan log and the vundofix.txt file here

Thank you !
__________________
Linkmaster
If I can't find it, it doesn't exist !!


UNITE Member
Linkmaster is offline