Vundo check please and why the registry change

Discussion in 'Malware Help (A Specialist Will Reply)' started by Banquo1, Dec 27, 2008.

  1. Banquo1

    Banquo1 Private E-2

    Hello,

    Thank you for the clear directions on the fix. I think I have finally removed all the Vundo and Trojan.Agent.

    Random websites would occur when I clicked on a link in Firefox. I tried several different website fixes, but upon restart I would always get this message:

    Rundll
    Error loading c:\Windows.0\ovewiroz.dll
    The specified module could not be found.

    Ovewiroz.dll was the infected trojan that was removed. Running Malwarebytes and Spybot would delete the registry key, but on restart it would reappear.

    I followed all your directions on Malware removal, and it seems to have finally been removed. Can check these logs to make sure for me?

    Problem: Now that it is removed, when I type Msconfig in the run window from start I get a missing file. I can still run msconfig by browsing and double clicking, but I'm worried about the changed registry key:

    HKLM\Software\Microsoft\Windows\CurrentVersion\AppPaths\MSConfig.exe

    is now

    \pchealth\helpctr\Binaries\MSConfig.exe

    should be

    c:\Windows\pchealth\helpctr\Binaries\MSConfig.exe

    I'm sure the changed registry key for MSConfig is the result of the fixes I did for the Malware. Do I need to be worried? If I change this registry key will I get reinfected?

    Thank you in advance
     

    Attached Files:

  2. Banquo1

    Banquo1 Private E-2

    last log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.....let's do this to fix the msconfig issue:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you get a success message.

    If you are not having any other malware issues, then:

     
  4. Banquo1

    Banquo1 Private E-2

    Working good now, thank you very much!

    Happy New Year
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds