help, outlook and overall hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by gonefishin, Apr 20, 2010.

  1. gonefishin

    gonefishin Private E-2

    yesterday I got a virus/trojan etc that basically has shut the computer down excepting my now status of being in safemode. I am worried about turning on normal mode for fear all will lead to a reformat. I do realize the readme file herein is important however not sure I can do much without your help. Here are the details:

    Either through an outlook or yahoo email or lastly maybe visiting a bad website my computer started running slow so I immediately shut internet explorer down to run symantic and cleaners. all of a sudden outlook began filling my screen up with over 40 outgoing emails that symantic was trying to scan, bogging the whole thing down. I shut down quick and went to safe mode and ran what I could (Symantic, CCleaner, Malwarebytes and Iobit at a minimum). Symantic found a backdoor trojan and a bloodhound that were quarantined and a file asr_vr32.dll that it could not delete. When going back to normal mode the outlook went wild again and then the microsoft security firewall was dismantled. I now cannot run a symantic scan or open SuperAntispyware at all. I did just get Iobit to find a file trojan.win32/vundo that is supposedly deleted. I did also run spybot and it formulated a report somewhat like hijackthis however I cannot load on anything in safe mode? Please help as I am now preparing to record all the software and files that will be lost in event of a total loss! btw I have clicked on override for system reset and offline in outlook to perhaps help. I might be able to get into system recovery if this helps as I do not know that avenue........
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do as much of the Read and Run first instructions as you can in safe mode, transfer the logs via cd ( or thumb drive -- . though you may end up infecting the thrumb drive). Attach the logs to your next reply.
     
  3. gonefishin

    gonefishin Private E-2

    ok, after the vundo was deleted (hopefully) by the iobit security 360 I ran ccleaner again and it found some items on the registry that were deleted. I am walking thru readme and am running malwarebytes again. I cannot download any logs as safemode does not recognize the usb external drive so I will have to reboot and hope it comes back on.........
     
  4. gonefishin

    gonefishin Private E-2

    ok I had Malwarebytes select the vundo (trojan.win32/vundo) file netapi32.dll.vir to delete upon reboot out of safe mode. I did also complete some of the tasks in readme. upon reboot all I can get is the Windows Advanced Options Menu screen as every reboot goes to the black XP screen then turns off, then turns back on and recycles. Help! I am willing to complete the readme detail however must be dead in the water?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    netapi32.dll is a needed system file. Let me get back with you on how we can replace it.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds