Uncheck 'automaticly restore default without notifiction". Solved: Vundo and Other Trojans, Please help. If you would like a quick scan of your computer using a self contained McAfee, please try the following tool I created. Let me know what to do now. have a peek at these guys

C:\WINDOWS\SYSTEM32\cilcokep.dll C:\WINDOWS\SYSTEM32\cwgxdphd.ini C:\WINDOWS\SYSTEM32\dhpdxgwc.dll C:\WINDOWS\SYSTEM32\dmmeqgij.dll C:\WINDOWS\SYSTEM32\iifgfed.dll C:\WINDOWS\SYSTEM32\pidngcqv.dll C:\WINDOWS\SYSTEM32\tuvtqpp.dll C:\WINDOWS\system32\vtsts.dll Beginning removal... Done! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members. The fix will begin; follow the prompts. https://community.mcafee.com/thread/18674?tstart=0

A text file will open in your default text editor. The specified domain either does not exist or could not be contacted. Over to the left click "shields" and uncheck all there. This is yet another mirror.

Vundo Help Please [Solved] Started by lorrizz , Feb 02 2009 08:28 AM Page 1 of 3 1 2 3 Next This topic is locked #1 lorrizz Posted 02 February 2009 scanning hidden autostart entries ... Data type: LEMF. Please download FixWareout from Here or Here.

Number of bytes printed: 1026899. It's better to be safe than sorry!When posting logs, please ensure Wordwrap is turned off in Notepad (to check, open Notepad click on Format | Uncheck Word Wrap)Please follow the steps o Please highlight everything in the notepad, then right-click and choose copy. · Click close and close again to exit the program. · Please paste that information here for me with So I downloaded Hijackthis...

Disable Autorun functionality This threat tries to use the Windows Autorun function to spread via removable drives, such as USB flash drives. This is a common malware behavior. I will make a contribution in the future to the board. Under Main choose: Select All Click the Empty Selected button. All the application has is heuristics drivers for detection.

I get the fake ads for fake spyware removal, occasional pop-ups from McAfee saying it has solved the problem (yeah, right), and total slowness on Facebook. (That one I can't explain.)I've http://www.techsupportforum.com/forums/f100/solved-mcafee-wont-get-rid-of-vundo-347829.html Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe" O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe O4 - Elapsed time 01:16:41 7:45 AM: File Sweep Complete, Elapsed Time: 01:14:14 7:36 AM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:28 AM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:22 AM: Warning: TCompressedFile.GetStreams(1): Stream read Click "OK" and then click the "Finish" button to return to the main menu.

Scan started at 5:14:37 AM 12/4/2007 Listing files found while scanning.... http://realink.org/solved-vundo/solved-vundo-of-course.html The virus has evolved to a point where the infections load in explorer.exe, lsass.exe, and rundll32.exe in addition to the original winlogon.exe and iexplorer.exe processes. Thank you Here is the HJT LOG Logfile of HijackThis v1.99.1 Scan saved at 10:27:48 AM, on 5/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running We Need to Run ComboFix Note to readers of this post other than the starter of this thread: ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance

If you are using Windows VistaClick the "Start Menu" (or Windows Orb) Click "All Programs" Click "Windows Update" On the left, choose "Change Settings" Ensure that the checkbox "Use Microsoft Update" Under "Script file to execute" choose "Input Script Manually". Using the site is easy and fun.

Win32 error code returned by the print processor: 0. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"O4 - HKLM\..\Run: [DefragTaskBar] o Please leave the others unchecked.

Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:04:21 PM, on 12/5/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe

Total number of pages in the document: 1. Click Close to exit the program. Note: In the event you already have Vundofix, this is a new version that I need you to download. c:\windows\system32\efcBurSi.dll 48128 bytes executable c:\windows\system32\nnnmmlkI.dll 302592 bytes executable scan completed successfully hidden files: 2 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - >

Please re-enable javascript to access full functionality. I don't know how much more spelled out I can get, it's as easy as 1.2.3. This document is a legally binding agreement between you and Clickspring, LLC, and its affiliated companies ("the Company"). http://realink.org/solved-vundo/solved-vundo-help-hjt-log-help.html I will definitely do a paypal donation after this is fixed.

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Microsoft Office.lnk Toolbar"Yahoo! This directory was not added to the list of paths to be scanned. 6:54 AM: Warning: SweepDirectories: Cannot find directory "e:". is infected by the Vundo trojan and cannot be cleaned"

What should I do next?