From: "Philip Michener" <Byesville, Ohio>
| I was recently infected with the Vundo Trojan and have had problems
| ridding myself of it.
|
| Windows Malicious Software Removal finds the trojan, but gives the
| message that it was only partially removed. Then tell me to run a
| full scan with antivirus software to complete the removal.
|
| I have tried McAfee, XSoft, Lavasoft, and Spydoctor, but they all fail
| to find the remaining files.
|
| Meanwhile, system gets reinfected, and popups start all over again.
|
| Anyone have suggestions as to how I can finally kill this bastard!
Perform the following...
If that does not work post in an Expert Forum as Malke suggested.
4 phase answer...
Perform Part 1, Part 2 and Part 3 and alternately part 4
It is suggested that you execute each tool in Normal Mode then in Safe Mode.
If you are using any version of Sun Java that is prior to JRE Version 6.0,
then you are strongly urged to remove any/all versions.
There are numerous vulnerabilities in them and they are actively being exploited.
It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
Version 6.0 update 6 (jre 6u6)
Simple check, look under...
C:\Program Files\Java
The only folder under that folder should be the latest version.
Such as...
C:\Program Files\Java\jre1.6.0_06
http://java.sun.com/javase/downloads/index.jsp
http://www.java.com/en/download/manual.jsp
FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1
Part 1
------------
Download Adware-Virtumundo Removal Tool --
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
Part 2
------------
Download Atribune's VUNDOFIX.EXE
http://www.atribune.org/ccount/click.php?id=4
Save VUNDOFIX.EXE to "C:\" ( C:\VUNDOFIX.EXE ) and execute it from there.
Part 3
------------
Malwarebytes Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Part 4
------------
Norman Vundo removal tool.
http://download.norman.no/public/Norman_Vundo_Cleaner.exe
http://www.norman.com/Virus/Virus_removal_tools/52658/en
* * * Please report back your results * * *
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV -
http://www.pctipp.ch/downloads/dl/35905.asp