Hi! is this tutorial safe ? * first post for me =) *

Discussion in 'Malware Help (A Specialist Will Reply)' started by 3rdan, Jul 29, 2008.

  1. 3rdan

    3rdan Private E-2

    Hi, :wave
    i am not sure if i am allowed to put other sites in topics and posts here, but if i am not please tell me!
    ___________________
    I have been cleaning my computer in the last few days and I found many many infections and stuff like that, it seems that I am getting close to an average clean computer :)
    now I ran my ie and it works fine,
    then i ran my firefox and it doesnt load some heavy trafic sites such as yahoo, google, and others, so I searched and I found out from there own site that if it is those sites (they are listed) then its a vundo virus in most cases, I remember from the various virus scans and clean ups I finished that there was a load of vundo viruses and trojans, and they seem to be cleaned up since i am not getting any advertisement any more. so i found this "manual" way of cleaning them up, i am not sure if it safe or true, and your site seem to have a lot of geeks, from the name :-D
    ____________________
    http://www.2-spyware.com/remove-vundo.html
    ___
    it asks me to try vundofix then do this manual cleaning:
    ___
    Vundo manual removal:
    Delete registry values:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\*WinLogon
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\*[filename]
    HKEY_CLASSES_ROOT\CLSID\{2316230A-C89C-4BCC-95C2-66659AC7A775}
    HKEY_CLASSES_ROOT\CLSID\{8109AF33-6949-4833-8881-43DCC232B7B2}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents.1
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316230A-C89C-4BCC-95C2-66659AC7A775}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8109AF33-6949-4833-8881-43DCC232B7B2}
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
    ___
    Unregister DLLs:
    vzbb.dll, vturr.dll
    ___
    Delete files:
    vzbb.dll, vturr.dll
    ___
    Misc:
    [filename] is a name of the trojan's main file.
    The parasite creates infected executable files with random names. These files can be found in different folders inside C:\Windows or C:\Winnt directory.
    Remove Vundo by following there steps. Manual and automated Vundo Fix.
    ___
    is vundofix safe to try? and is it useful?
    and are those things i am going to delete from the registry and so safe to do?
    I have also found your full guide of removing malware
    but i am very very busy and it is pretty long, please tell me if there is a fast way or good program that will do it, this doesnt have to be something like 99% sure, but something that will remove the vundo thingy in most cases, if it doesnt work then i will do your full malware removing tutorial:zzz
    thank you very much ;)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    That procedure is for old versions of Vundo and will not help at all for current versions. In addition it was even incomplete for old versions.

    If you have Virtumonde (aka Vundo) problems, please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. 3rdan

    3rdan Private E-2

    sorry for posting this, all i needed was a restarts, hehe
    i feel so dumb now, )=
    i will check that read and run me first when i need to,
    thank you for your time
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds