Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Avg Won't Delete This Infections Please Help?


  • Please log in to reply
1 reply to this topic

#1 Curious Guy

Curious Guy

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:49 AM

Posted 24 June 2007 - 03:58 PM

It won't delete them they're trojans and are in:
C:\WINDOWS\System32\pmnlm.dll is infected with TR/Vundo.Gen

C:\WINDOWS\System32\jdqyiidb.d... infected with:
TR/Juan.E

C:\WINDOWS\System32\groygqgr.d... infected with
TR/Vundo.Gen

C:\Program Files\VSAdd-in.dll infected with:
TR/Agent.ACL

It won't delete the files (I know that VSAdd-in is a virus/spyware(?) itself) and I'm starting to doubt if the first are actual windows files(if they are real I have the Windows XP CD so I can replace them) in any case how can I delete them,I would leave them in quarantine but they keep popping up like if I didn't move them(Now I have 3 copies of the files in quarantine),help and sorry if it was a mouthful.

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,516 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:49 AM

Posted 24 June 2007 - 04:09 PM

Please download http://www.atribune.org/content/view/24/2/
to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.

Use Virtumundobegone if Vundofix doesn't work.
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
Download VirtumundoBegone and save it to your desktop.


Now reboot into Safe Mode.


This can be done tapping the F8 key as soon as you start your computer


You will be brought to a menu where you can choose to boot into safe mode.


Select safe mode with networking using your arrow keys on the keyboard and then press enter.


When you computer reaches the desktop make sure you log in as the same user which you had performed the previous steps,


Once you are logged into safe mode, double-click VirtumundoBeGone.exe file you just downloaded and follow the instructions.


Exit when it has finished, and reboot back to normal mode.


Install Super Antispyware. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/

Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.
http://www.bitdefender.com/scan8/ie.html

--------------------------------------------------------------------------------

Post a Hijack This log in the Hijack This Forum by following the directions in the link below if the programs above have not removed ALL malware. DO NOT post the log in this forum.
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
--------------------------------------------------------------------------------

How To start Windows in Safe Mode
http://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users