Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

3726

April 1st, 2009 16:00

cannot remove apparent trojan - keeps adding entries to registry

I am working on a Dell 2400 that was not ( until recently) updated or protected properly with firewalls / virus protection.

I tried the demo copy of Norton Antivirus and it had detected I believe:
trojan.fakeavalert and another that was either trojan.vundo or trojan virtumundo ( I forgot the name)

I recently de-installed NAV installed the following:

ZoneAlarm Internet Security ( and is all up to date )
Adaware 2008 - free version ( and it too is up to date )

Both ZoneAlarm & AdAware run fairly clean with the exception of the cookies, etc ( low priority stuff)

My problem at this time is that there is something that is adding entries to the registry ( even when in safe mode) , and it causes numerous web pages to pop up when running IE7 or FireFox. 
The entries I find in the registry are :
\HKLM\software\microsoft\windws\currentversion\run
rundll32.exe "c:\windows\system32\rulufutu.dll",a
rundll32.exe "c:\windows\system32\piyudijo.dll",a
rundll32.exe "c:\windows\system32\kitehuvu.dll",a

When I delet these entries ( even in safe mode) they are added back in a few seconds.

3 Apprentice

 • 

20.5K Posts

April 1st, 2009 17:00

Try scans with these two programs in the following order:

Please disable other security software that may cause conflicts with the scans. (Don't forget to enable it afterward.)

Instructions on how to do that are HERE.

Please download to your desktop Malwarebytes' Anti-Malware from Here or Here 

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checkedPhotobucket
    Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Extra Notes:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

**If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from http://www.malwarebytes.org/mbam-clean.exe

 

Download and scan with Super Anti-Spyware Free for Home Users. It is available HERE:
*Double-click SUPERAntiSypware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):

Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.

* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".

If that does not fix the problem, it might be good to post a log for review on the Malware Removal Forum.

Be sure to read instructions at the top of the forum.

 

9 Posts

April 1st, 2009 19:00

Yep!  Malwarebytes found and fixed trojan.vundo.h

Many thanks for the help :emotion-21:

3 Apprentice

 • 

20.5K Posts

April 1st, 2009 21:00

Glad to hear that solved the problem.:emotion-1:

No Events found!

Top