Vundo Virus alert

Discussion in 'Malware Help (A Specialist Will Reply)' started by einarr99, Oct 11, 2005.

  1. einarr99

    einarr99 Private E-2

    Hello all,

    First time trying to beat a nasty virus. I am constently getting a Norton popup detecting Trojan.Vundo.
    Specifically C:\WINDOWS\system32\jkkjh.dll

    I have tried running the 2 fixes i found both for vundo and vundo.b but it says it doesnt find it.

    I have followed all the read me's and have created a HJT log.

    TrojanScan: C:\WINDOWS\Downloaded Program Files\popcaploader.dll Riskware.Downloader.Win32.PopCap.b I'm assuming this is for popcap games unless someone knows if this is bad.

    Bitdefender cleared a couple things but didnt find vundo.
    I ran Ccleaner, ad-aware, spybot, and microsoft antispyware.

    I have been reading some similar threads but i want to be sure before I try and fix anything.

    I can see this file in O2 and O20 but wanted to see if anything else may be showing up and also to be sure i do this right.

    I have attched my HJT log

    Thank you for your time if anyone can help.

    -Einarr
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the steps in this generic thread for fixing vundo: Virtumonde aka Trojan Vundo Fix w/ Tool


    And yes popcaploader.dll is for Popcap games and it is considered risky to use. Many people suggest removing it, but many users windup still using it (not necessarily a good idea). The decision is yours.
     
    Last edited: Oct 11, 2005
  3. einarr99

    einarr99 Private E-2

    I'm at work so i cant post a new HJT but I think it worked.

    The files are gone no more pop up and my CPU usage is back to normal instead of jumping all over.

    If I did want to remove that popcap loader. Is there a specific procedure or would it show up in add remove or something obvious?

    Thanks for the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you post the followup HJT log we will know for sure but it sounds like it is gone.

    Popcap is usually seen in an O16 line and that line can be removed. The file it downloads must be removed from a command prompt window because it cannot be seen using Windows Explorer. You O16 line was:

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds