Please Help with Vundu(RESOLVED)
-
re: Please Help with Vundu(RESOLVED)
Hi Neal,
That’s good news! Thank you so much. The computer performed well all day, but unfortunately I still have a couple of worries:
1.) I got another one of those disturbing messages today…. My “Auto Protect Results” indicated:
Risk = “Total Security” (I believe this is Symantec’s word for the vundo trojan)
File = A0037513.exe
Location = C:\System Volume Information\_restore{….}
This looks like some of the related malware files were backed up in one of the restore points? Is there a way to deal with this?
2.) Some people mentioned in other posts that it was not only important to delete Combofix, but it needs to be deleted a special way from the command prompt. Is that true?
Thanks Again. Your time, effort, and patience are much appreciated.
Last edited by Draco; 14-10-2009 at 02:21 AM.
Reason: typo
-
Time for some housekeeping
* Click START then RUN
* Now type Combofix /u in the runbox and click OK
* Notice the space between combofix and the /

The above procedure will:
* Delete the following:
o ComboFix and its associated files and folders.
o VundoFix backups, if present
o The C:\Deckard folder, if present
o The C:_OtMoveIt folder, if present
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Reset System Restore.
-
Thanks Neal. I really appreciate everything. It’s so scary when stuff like this happens to your computer – it’s nice to know that there are kind people out there willing to help. I will continue to spread the word about DAL.