Trojan horse

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chasrowe, Sep 19, 2007.

  1. chasrowe

    chasrowe Private E-2

    Okay guys haven't needed you for some time but always appreciate your help. My daughter is away at college and her laptop is infected with Trojan Horse named "Vundo" she tried removing it with mcafee but it won't let her because it says the file is write protected. file name is ljjkiig.dll. The path is is in c:\\windows\system32 message from mcafee says "can not be cleared". Please help, thanks as always.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Vundo cannot be completely removed by any commercial application so don't waste your time. It would actually be easier for your daughter to come here and post so we can work with her on removing this infection since it requires a bunch of work.

    She should start with the below.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( c:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    And then she should continue on to the steps here:Using MGtools and attach the requested MGLogs.zip file here afterwards. Vundo often puts a lot of stuff onto a PC and after we get the logs, we can create a procedure to help her remove everything.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds