Southern Maryland Online - Serving Calvert, Charles, & St. Mary's Counties.  Click here to go to the Front Page of somd.com.
 
| Write Us | Help | Sponsors | Classifieds | Employment | Forums | MarketPlace | Calendar | Headlines | Announcements | Weather | More... |


Go Back   Southern Maryland Community Forums > General Interest > Computers, Technology, & the Internet
Register Blogs FAQ Members List Calendar Chat Search Today's Posts Mark Forums Read Wireless

Computers, Technology, & the Internet Talk about computers, the net and the latest technology, e.g. music, video, wireless, you name it. Who do you love more? Your wife or your Tivo?

Reply
 
LinkBack Thread Tools Display Modes
Old 12-09-2008, 05:47 PM   #1 (permalink)
Just play
 
PsyOps's Avatar
 
Member Since: Sep 2006
Posts: 10,299
Trojan.vundo

This is an old piece of malware and my daughter got it on her PC. It adware causes a cascading problem with pop-ups. Symantec claims they have a fix (FixVundo.exe) that doesn't work. There are a couple other fixes that out there that also didn't work. She also ran a full scan (in safe mode) with Symantec AV, Adaware, AVG and Spybot and none of them seem to clean the problem.

Do any of you techies have any info on a fix for this? Any specific registry entries that need to be cleared out; any programs that would have installed as a result?

TIA
__________________
My relationship to music is a very personal one.
PsyOps is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 06:40 PM   #2 (permalink)
tickled~pink
 
lam2's Avatar
 
Member Since: Aug 2007
Posts: 435
I just had the same issue on my computer last week.

I ran malwarebytes' anti-malware

Malwarebytes' Anti-Malware - Free software downloads and reviews - CNET Download.com

Then ran ccleaner

CCleaner - Home


Only took about an hour and now all is good!
lam2 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 07:29 PM   #3 (permalink)
Just play
 
PsyOps's Avatar
 
Member Since: Sep 2006
Posts: 10,299
Quote:
Originally Posted by lam2 View Post
I just had the same issue on my computer last week.

I ran malwarebytes' anti-malware

Malwarebytes' Anti-Malware - Free software downloads and reviews - CNET Download.com

Then ran ccleaner

CCleaner - Home


Only took about an hour and now all is good!
Cool. We'll give that a try. Thanks.
__________________
My relationship to music is a very personal one.
PsyOps is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 09:39 PM   #4 (permalink)
Flame Tamer
 
G1G4's Avatar
 
Member Since: Jul 2008
Location: SMC
Posts: 1,583
Malwarebytes should fix it. However, scan through the registry and look for any entries containing the word(s) 'MS Juan.' Also, make sure any and all programs you don't know are deleted. Common entries in the registry are:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
HKEY_CURRENT_USER SoftwareMicrosoftWindows CurrentVersionRunOnce*WinLogon
HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunOnce*[filename]
HKEY_CLASSES_ROOTCLSID{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_CLASSES_ROOTCLSID{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainActive State

Hope it helps.
G1G4 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 10:17 PM   #5 (permalink)
RadioPatrol
 
Posts: n/a
Quote:
Originally Posted by PsyOps View Post
This is an old piece of malware and my daughter got it on her PC. It adware causes a cascading problem with pop-ups. Symantec claims they have a fix (FixVundo.exe) that doesn't work. There are a couple other fixes that out there that also didn't work. She also ran a full scan (in safe mode) with Symantec AV, Adaware, AVG and Spybot and none of them seem to clean the problem.

Do any of you techies have any info on a fix for this? Any specific registry entries that need to be cleared out; any programs that would have installed as a result?

TIA

Try Counter Spy / Vipre from Sunbelt Software ....
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 10:21 PM   #6 (permalink)
Just play
 
PsyOps's Avatar
 
Member Since: Sep 2006
Posts: 10,299
Quote:
Originally Posted by G1G4 View Post
Malwarebytes should fix it. However, scan through the registry and look for any entries containing the word(s) 'MS Juan.' Also, make sure any and all programs you don't know are deleted. Common entries in the registry are:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
HKEY_CURRENT_USER SoftwareMicrosoftWindows CurrentVersionRunOnce*WinLogon
HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunOnce*[filename]
HKEY_CLASSES_ROOTCLSID{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_CLASSES_ROOTCLSID{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainActive State

Hope it helps.
This is what I was looking for. I couldn't find any of this on the web. I knew there were registry entries, just didn't know what they were. Thanks.

__________________
My relationship to music is a very personal one.
PsyOps is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-09-2008, 10:21 PM   #7 (permalink)
Just play
 
PsyOps's Avatar
 
Member Since: Sep 2006
Posts: 10,299
Quote:
Originally Posted by RadioPatrol View Post
Try Counter Spy / Vipre from Sunbelt Software ....
It's a shame you have to run 50 scanning products to remove a stinking intrusion on your PC.
__________________
My relationship to music is a very personal one.
PsyOps is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-10-2008, 08:02 AM   #8 (permalink)
RadioPatrol
 
Posts: n/a
Quote:
Originally Posted by PsyOps View Post
It's a shame you have to run 50 scanning products to remove a stinking intrusion on your PC.



sorry that was funny .... I know what your talking about, I only use the one, now ... since Sunbelt upgraded CS to include Viruses .... I only need the one app ...
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-10-2008, 10:38 AM   #9 (permalink)
Nothing at the moment...
 
clevalley's Avatar
 
Member Since: Aug 2007
Location: Bryantown MD
Posts: 13,240
Quote:
Originally Posted by RadioPatrol View Post



sorry that was funny .... I know what your talking about, I only use the one, now ... since Sunbelt upgraded CS to include Viruses .... I only need the one app ...
We are migrating to Symantec Endpoint Protection (11) as we redo machines. It seems like REALLY good stuff.
__________________
Quote:
Originally Posted by GypsyQueen View Post
im not dum, you are dubmer than me so there.
Quote:
Originally Posted by Mojo View Post
Oh come on, that would be a hot 3some! Imagine Toppick railroading you while screaming "WHOSE LAWNMOWER IS THIS, WHOSE LAWNMOWER IS THIS"
clevalley is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-10-2008, 12:23 PM   #10 (permalink)
.
 
GWguy's Avatar
 
Member Since: Sep 2007
Location: I got nuttin.
Posts: 13,314
Quote:
Originally Posted by clevalley View Post
We are migrating to Symantec Endpoint Protection (11) as we redo machines. It seems like REALLY good stuff.
We just migrated AWAY from Symantec to Sophos for AV and firewall. It has caused us techs nothing but grief.
__________________
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday

There is no "Someday".
GWguy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 08:53 PM.



| Home | Help | Contact Us | About somd.com | Privacy | Advertising | Sponsors | Newsletter |

| What's New | What's Cool | Top Rated | Add A Link | Mod a Link | Link to Us |

| Announcements | Bookstore | Chat | Calendar | Classifieds | Community |
| Contests & Surveys | Culture | Dating | Dining | Education | Employment | Entertainment |
| Forums | Free E-Mail | Games | Gear! | Government | Guestbook | Health | Marketplace | Mortgage | News |
| Organizations | Photos | Postcard | Real Estate | Relocation | Sports | Survey | Travel | Wiki | Weather | Worship |

Brought to you by Virtually Everything, Inc.   ©1996-2009, All rights reserved.


SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.