Discussion in 'Majorgeeks Welcome Center' started by Zyxx, Apr 2, 2008.

  1. Zyxx

    Zyxx Private E-2

    Don't know whether this goes in Malware removal or Software related forums. Feel free to move this to the right place.

    Here comes the problem.

    My PC was infected with the famous Vundo trojan.

    When VundoFix and other similar programs reported they didn't find any threats I searched the web for solutions. And I found them, so I manually removed the threat.

    I turned off System restore.
    I managed to delete all the related files from /system32 directory.
    I searched for references to these files in the registry, and deleted them as well.

    Then I rebooted, and ... instead of going directly into Windows as usual the password screen appeared. I never installed a password.

    Back to the web, on another PC. New websearch revealed others with the same problem. Found this site, and decided to create a Petter Nordahl-Hagen's Offline NT Password & Registry Editor disk. With that I reset the password to no password. Reboot. Still the password login screen. I hit Enter, because I set it to no password. A message appears: Unable to log you on because of an account restriction. Again, I use Petter's CD to set the password to something substantial ("123"). Reboot. Back to the password screen, and nothing works, not even the 123. In short, Vundo has locked me out.

    I figured it must be some traces left in the registry.
    So I built a BartPE bootable CD, with a RegEdit plug-in. Now I can get access to the registry on my infected PC, but I haven't got a clue what I'm looking for.

  2. wildwolf220

    wildwolf220 Oracle of Doom

    :wave and welcome to MG's..

    As kes mentioned a visit to malware would be advised.

    Good luck:major
  3. Zyxx

    Zyxx Private E-2

    Thanks for your reactions. I posted it in Malware removal.
    Now we sit back and wait.
  4. wildwolf220

    wildwolf220 Oracle of Doom

    Just be patient.:)

    The malware forum is realy busy and the posts are answered from oldest to newest.

    But they will get round to answering your post.

    Good luck:major
  5. wildwolf220

    wildwolf220 Oracle of Doom

    Just one more thing to add.

    Have a look at THIS LINK while you are waiting for a reply

    The malware guys will probably need you to go through it so you might like to get a head start..

