HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. Once I killed the system processes, even if I got the order right (and I believe you can buy more time by killing smss.exe first), you still need a shell to I didn't understand how this was possible, but didn't care, it was time to bring out the chainsaw. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. have a peek here

Characteristics: Trojan.Vundo.H was made to deploy threats. Webroot Antispyware/Antivirus My first response was to try Webroot Antispyware with Antivirus, or whatever its called. If the problem persists, please contact your domain administrator.< End of report > Edited by smithboy, 14 May 2009 - 10:26 AM. Then, Trojan.Vundo.H will open a connection so that it can download other threats from the remote computer. https://forums.malwarebytes.com/topic/41459-cant-get-rid-of-trojanvundoh/?do=email&comment=207305

New update came up for malwarebytes, ran it

This is a sad statement about Microsoft engineering and security, and I will be buying a Mac next time around the block, if I am able to.

Summary Well, I suppose I could have just written the last section. So, what was causing it to run? It correctly said I would need a reboot, which I did. Visit Website HKEY_CLASSES_ROOT\CLSID\{9663616a-804a-4c8d-9a8e-6950d5b77d56} (Trojan.Vundo.H) -> No action taken.

There is a utility called taskkill, mentioned above, that will kill anything; unfortunately, it doesn't come will all versions of XP, including mine.

I used Trend Micro PC-cillin and it detected nothing.

After a bit of searching, I found another dll with identical binary, so I used the same technique on it.

Anyway, I downloaded this package from here -- http://www.microsoft.com/downloads/details.aspx?familyid=15491F07-99F7-4A2D-983D-81C2137FF464&displaylang=en because there is a utility that will convert this floppy bootset and burn a bootable CD, which I downloaded from here -- You also must know the Administrator password on the system being booted.

At first it opens up endless blank popups, but was later on blocked by my Webroot Firewall. At the time of writing, it has been over 120 hours, without even the courtesy of a response. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.

windows-virus This question has already been answered. by le_Claire » March 7th, 2010, 3:44 pm Thanks for the reply ! Hope that helps. 7 January 2009 at 2:01 pm 3 } ElstonOBG said: The way I found to clean out the trojan.vundo.H issue was to boot into safe mode and run I don't know what they were for, as I close all pop-ups instantly.

I went on with my life, and everything was fine. Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 boopme boopme To Insanity and Beyond Global Moderator 67,076 posts OFFLINE Gender:Male Location:NJ USA Local I you personally did not add these then they should be fixed using HiJackThis. this contact form Multiple linked Gmail accounts.

