| Home | Forums | Reviews | Articles | Register |
![]() |
| Thread Tools | Rate Thread |
|
|
|
| |
|
=?Utf-8?B?RW5nZWw=?=
Guest
Posts: n/a
|
Are you unable to read the replies?
Has Plunl's information failed in your case? Engel |
|
||
|
||||
|
plun
Guest
Posts: n/a
|
Hi Dave and Engel
Takes it again then: I would try this but itīs a lot of manual work. http://www.spyware-removal-guideline...nfixer-removal Winfixer must be changed now with new processes but maybe above works ? This is a AndyM case beacuse I cannot find any good advice within any forum without using HijackThis and to be carefully guided. http://www.merijn.org/files/hijackthis.zip -- plun Engel was thinking very hard : > Are you unable to read the replies? > Has Plunl's information failed in your case? > > Engel |
|
||
|
||||
|
plun
Guest
Posts: n/a
|
Hi Dave
Run HijackThis and post a log. The WebUI i much better now to handle these logs. AndyM also probably sees it. -- plun plun presented the following explanation : > http://www.merijn.org/files/hijackthis.zip |
|
||
|
||||
|
Bill Sanderson
Guest
Posts: n/a
|
It's actually better not to post these logs here, WebUI or no.
Go for a specialized forum--if you post here, there are several issues: 1) bad advice--we don't have a log of folks with the skills to analyze the logs and give you the best current advice--Ron Kinner is exceptional, and there are others here, but you'll find more in the private forums such as www.aumha.org 2) The logs are big--there are folks on dialup here. -- "plun" <(E-Mail Removed)> wrote in message news:(E-Mail Removed)... > Hi Dave > > Run HijackThis and post a log. > > The WebUI i much better now to handle these logs. > > AndyM also probably sees it. > > -- > plun > > plun presented the following explanation : >> http://www.merijn.org/files/hijackthis.zip > > |
|
||
|
||||
|
plun
Guest
Posts: n/a
|
![]() Mostly all "helpers" just look for similar HijackThis logs and follows others with "canned" removal messages. In this world we have a few really skilled helpers which can deal with new unknown hijacks as Calamity Jane and a few others. But this was the first time Iīm not recommended to go to a real HijackThis forum ![]() So here they are again: http://www.merijn.org/forums.html ASAP: http://asap.maddoktor2.com/ -- plun After serious thinking Bill Sanderson wrote : > It's actually better not to post these logs here, WebUI or no. > > Go for a specialized forum--if you post here, there are several issues: 1) > bad advice--we don't have a log of folks with the skills to analyze the logs > and give you the best current advice--Ron Kinner is exceptional, and there > are others here, but you'll find more in the private forums such as > www.aumha.org > > 2) The logs are big--there are folks on dialup here. > > -- > > "plun" <(E-Mail Removed)> wrote in message > news:(E-Mail Removed)... >> Hi Dave >> >> Run HijackThis and post a log. >> >> The WebUI i much better now to handle these logs. >> >> AndyM also probably sees it. >> >> -- >> plun >> >> plun presented the following explanation : >>> http://www.merijn.org/files/hijackthis.zip >> >> |
|
||
|
||||
|
=?Utf-8?B?QW5keU1hbmNoZXN0YQ==?=
Guest
Posts: n/a
|
Bill's suggestion would be easier for you as its always better to deal with these problems on a forum and running Hijack This would be alot faster to review but here's a standard fix for Vundo and the file thats causing you problems which is showing in the MS log ![]() Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe Save it in a convenient permanent folder such as C:\HJT\, Make a copy of these instructions so you have them handy as the most steps need to be done in safe mode with IE closed. Please save the VundoFix tool to your desktop : www.atribune.org/downloads/VundoFix.exe Double-click VundoFix.exe to extract the files This will create a folder named VundoFix on your desktop. After the files are extracted, please reboot your computer into Safe Mode. Reboot and Keep tapping F8 then choose safe mode from the list . Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat You will first be presented with a message and a list of forums to seek help at At this point press enter one time. Next you will see: -------------------------------------------------------------------------------- Type in the filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix -------------------------------------------------------------------------------- At this point please type the following file path (make sure to enter it exactly as below!): c:\windows\servicepackfiles\i386\wincr.dll Press Enter, then press the F6 key, then press Enter one more time to continue with the fix. Next you will see: -------------------------------------------------------------------------------- Please type in the second filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix. -------------------------------------------------------------------------------- At this point please type the following file path (make sure to enter it exactly as below!): c:\windows\servicepackfiles\i386\rcniw.* Press Enter, then press the F6 key, then press Enter one more time to continue with the fix. The fix will run then HijackThis will open. In HijackThis, please place a check next to the following items if they exist: O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - c:\windows\servicepackfiles\i386\wincr.dll O20 - Winlogon Notify: wincr.dll -c:\windows\servicepackfiles\i386\wincr.dll With the above checked then press FIX CHECKED After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer. Pressing any key will cause a "Blue Screen of Death" this is normal ! Once your machine reboots Enable Hidden Files and Folder Goto Start Menu and Search then Tools on the Top Bar, Choose Folder Options then goto the view tab make sure that 'Show hidden files and folders' is enabled. 'Display the contents of system folders' is checked & 'Hide extentions for known file types ' is not checked then press apply You can set this back later by opening the same page and pressing 'restore defaults' then pressing apply, Check for these files and delete if found c:\windows\servicepackfiles\i386\wincr.dll c:\windows\servicepackfiles\i386\rcniw.dll c:\windows\servicepackfiles\i386\rcniw.bak1 c:\windows\servicepackfiles\i386\rcniw.bak2 c:\windows\servicepackfiles\i386\rcniw.ini c:\windows\servicepackfiles\i386\rcniw.ini2 c:\windows\servicepackfiles\i386\rcniw.tmp c:\windows\servicepackfiles\i386\rcniw.tmp1 c:\windows\servicepackfiles\i386\rcniw.tmp2 Then please run this online virus scan: ActiveScan http://www.pandasoftware.com/products/activescan.htm Run Ccleaner on the cleaner and issues feature and remove any problems repeat untill they show clear. All The Best Andy |
|
||
|
||||
|
plun
Guest
Posts: n/a
|
Hi Andy
Hmmm? In the past this always seems to have been the "last resort"........ Let MSAS handle it in safe mode. This seems to be the MVP way to deal with this ?! Now we indeed have some really difficult "pests" to deal with so it is probably best to directly "redirect" to a real HijackThis forum for proper careful guidance for removal. It is also not possible to announce or make messages "sticky" about standard "house cleans" for a majority of threats within this UI. The consequense is that users tries every antispyware app and removal tool instead of using HijackThis and withhelp directly see the cause of this "infection". It is easy with HijackThis logs and even more easy if Adawares log is included to see the cause. "In this world we have a few really skilled helpers which can deal with new unknown hijacks as Calamity Jane and a few others." Well Andy, you are probably among these few ![]() Indeed difficult ! best regards plun AndyManchesta was thinking very hard : > Bill's suggestion would be easier for you as its always better to deal with > these problems on a forum and running Hijack This would be alot faster to > review but here's a standard fix for Vundo and the file thats causing you > problems which is showing in the MS log ![]() > > Download 'Hijack This!'. > > http://www.spywareinfo.com/~merijn/files/HijackThis.exe > > Save it in a convenient permanent folder such as C:\HJT\, > > Make a copy of these instructions so you have them handy as the most steps > need to be done in safe mode with IE closed. > > Please save the VundoFix tool to your desktop : > > www.atribune.org/downloads/VundoFix.exe > > Double-click VundoFix.exe to extract the files > > This will create a folder named VundoFix on your desktop. > > After the files are extracted, please reboot your computer into Safe Mode. > > Reboot and Keep tapping F8 then choose safe mode from the list . > > Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat > > You will first be presented with a message and a list of forums to seek help > at > > At this point press enter one time. > > Next you will see: > > -------------------------------------------------------------------------------- > Type in the filepath as instructed by the forum staff > Then Press Enter, Then F6, Then Enter Again to continue with the fix > -------------------------------------------------------------------------------- > > At this point please type the following file path (make sure to enter it > exactly as below!): > > c:\windows\servicepackfiles\i386\wincr.dll > > Press Enter, then press the F6 key, then press Enter one more time to > continue with the fix. > > Next you will see: > > -------------------------------------------------------------------------------- > Please type in the second filepath as instructed by the forum staff > Then Press Enter, Then F6, Then Enter Again to continue with the fix. > -------------------------------------------------------------------------------- > > At this point please type the following file path (make sure to enter it > exactly as below!): > > c:\windows\servicepackfiles\i386\rcniw.* > > Press Enter, then press the F6 key, then press Enter one more time to > continue with the fix. > > The fix will run then HijackThis will open. > > In HijackThis, please place a check next to the following items if they > exist: > > O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - > c:\windows\servicepackfiles\i386\wincr.dll > > O20 - Winlogon Notify: wincr.dll -c:\windows\servicepackfiles\i386\wincr.dll > > With the above checked then press FIX CHECKED > > After you have fixed these items, close Hijackthis and Press any key to > Force a reboot of your computer. > > Pressing any key will cause a "Blue Screen of Death" this is normal ! > > Once your machine reboots Enable Hidden Files and Folder > > Goto Start Menu and Search then Tools on the Top Bar, Choose Folder Options > then goto the view tab make sure that 'Show hidden files and folders' is > enabled. 'Display the contents of system folders' is checked & 'Hide > extentions for known file types ' is not checked then press apply > > You can set this back later by opening the same page and pressing 'restore > defaults' then pressing apply, > > Check for these files and delete if found > > c:\windows\servicepackfiles\i386\wincr.dll > c:\windows\servicepackfiles\i386\rcniw.dll > c:\windows\servicepackfiles\i386\rcniw.bak1 > c:\windows\servicepackfiles\i386\rcniw.bak2 > c:\windows\servicepackfiles\i386\rcniw.ini > c:\windows\servicepackfiles\i386\rcniw.ini2 > c:\windows\servicepackfiles\i386\rcniw.tmp > c:\windows\servicepackfiles\i386\rcniw.tmp1 > c:\windows\servicepackfiles\i386\rcniw.tmp2 > > Then please run this online virus scan: > > ActiveScan > > http://www.pandasoftware.com/products/activescan.htm > > Run Ccleaner on the cleaner and issues feature and remove any problems > repeat untill they show clear. > > All The Best > > Andy |
|
||
|
||||
|
=?Utf-8?B?QW5keU1hbmNoZXN0YQ==?=
Guest
Posts: n/a
|
Hey Plun This isnt Winfixer Plun its Trojan Vundo, If it was Winfixer they wouldnt be getting pop ups to install winfixer, With Vundo it can be a pain as its Usually called from the Winlogon/Notify key and entered as a BHO so standand spyware removers cannot kill it, I posted to a user on one of these groups who just had it entered as a BHO and not showing in the Winlogon/Notify key and took the easy option of attempting to remove the file with killbox on reboot and fixing the entry in hijack this as it was only in one area and didnt look like it had fully infected the system but I decided to use the full canned speech here so they know all possible files and folders. If a spyware remover removed the dll file and its being called from the Winlogon/Notify key there is a chance it will cause conflict if the Notify key isnt also removed. If its pointing to a invalid entry there is a chance the system wil refuse to boot, Its a very small chance but its not one worth risking so the old fix would of been to use killbox and replace the dll with a harmless dummy file then removing that and the 020 line in hijack this, The Blue screen of death isnt a problem here as its just part of the fix and a side effect of stopping winlogon but with this fix it should remove the infection without any issues. The alternative is very complicated using Process Explorer from sysinternals and viewing system processes like explorer and winlogon and using the Threads tab to stop the trojan files from using the genuine files as they are using them to remain on the system and start with windows, They Trojan files will usually be using Winlogon.exe, explorer.exe and iexplore.exe so its not a easy task to kill them I agree with your comments about posting on a hijack this forum but most are getting swamped with requests for help so this was just to really let them know whats involved and the steps they need to take to remove Vundo. Regards Andy |
|
||
|
||||
|
plun
Guest
Posts: n/a
|
Hi Andy
Writing in circles...... ![]() I know that this is the Vundo trojan which often comes with Winfixer (always maybe ? Similar to PS Guard) But this is minor important beacuse this was about principles for removals when it is severe threats which MSAS, Adaware etc cannot handle. I would then suggest that Aumhas quickfix protocol is good and maybe worth to try for all in conjunction with MSAS and safe mode scans. http://www.aumha.org/a/quickfix.htm Step 2 then with CCleaner to save time. Step 5 should then be, scan in safe mode with MSAS and Adaware Sorry Aumha for this maybe unpolite way to make a proposal) ![]() It ends up in HijackThis and saves time for both a user and a helper. Maybe we must take this private but itīs important for all usersto get help as fast as possible and also a solution and HijackThis is the only way for this as I can see it. I takes "milliseconds" to find other similar solved removals with HijackThis logs and to get proper guidance from a "canned" message. Nevertheless itīs important that these logs matches. Trying to be constructive or what the word is ? ![]() best regards plun AndyManchesta expressed precisely : > Hey Plun > > This isnt Winfixer Plun its Trojan Vundo, If it was Winfixer they wouldnt be > getting pop ups to install winfixer, With Vundo it can be a pain as its > Usually called from the Winlogon/Notify key and entered as a BHO so standand > spyware removers cannot kill it, > > I posted to a user on one of these groups who just had it entered as a BHO > and not showing in the Winlogon/Notify key and took the easy option of > attempting to remove the file with killbox on reboot and fixing the entry in > hijack this as it was only in one area and didnt look like it had fully > infected the system but I decided to use the full canned speech here so they > know all possible files and folders. > > If a spyware remover removed the dll file and its being called from the > Winlogon/Notify key there is a chance it will cause conflict if the Notify > key isnt also removed. If its pointing to a invalid entry there is a chance > the system wil refuse to boot, Its a very small chance but its not one worth > risking so the old fix would of been to use killbox and replace the dll with > a harmless dummy file then removing that and the 020 line in hijack this, The > Blue screen of death isnt a problem here as its just part of the fix and a > side effect of stopping winlogon but with this fix it should remove the > infection without any issues. > > The alternative is very complicated using Process Explorer from sysinternals > and viewing system processes like explorer and winlogon and using the Threads > tab to stop the trojan files from using the genuine files as they are using > them to remain on the system and start with windows, They Trojan files will > usually be using Winlogon.exe, explorer.exe and iexplore.exe so its not a > easy task to kill them > > I agree with your comments about posting on a hijack this forum but most are > getting swamped with requests for help so this was just to really let them > know whats involved and the steps they need to take to remove Vundo. > > Regards > > Andy |
|
||
|
||||
|
|
|
| |
![]() |
| Thread Tools | |
| Rate This Thread | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Scan on Document Imager Office 2007, preview shows, scan doesnt | Charlie | Microsoft Word Document Management | 0 | 9th Jan 2010 01:29 AM |
| HP 3050 Scan-the windows fax & scan doesn't have legal size select | =?Utf-8?B?Sk5vdmljZQ==?= | Windows Vista Print / Fax / Scan | 0 | 16th Nov 2007 02:07 AM |
| Could not start scan. Scan engine returned error 0x20000058 (Symantec Antivirus 9.0.0.338) | emartinez.pr1@gmail.com | Windows XP General | 1 | 29th Jun 2006 06:22 PM |
| Problem with "Display the scan results window after a spyware scan | =?Utf-8?B?Q2hhcmxpZQ==?= | Spyware Discussion | 5 | 27th Dec 2005 06:53 PM |
| Viruse scan program freezes at different points durring scan even durring scan from symantec website. | =?Utf-8?B?Sm9uYXRoYW4=?= | Windows XP Performance | 0 | 30th Oct 2003 01:21 AM |
Powered by vBulletin®. Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2010, Crawlability, Inc. |




