Malware Removal Issues/Questions
First off, I'm computer layperson. I don't know that much about the techinical stuff. I haveXP Proffesional and this is my personal home computer (no network). I haveMcAfee Security Center, continous coverage since computerpurchase. Shows I'm currently protected (firewall protection etc.) and have not known not to ever had a lapse in protection. Ialso have Windows Defender, but it's been turned off, (not by me, but apparently by a trojan in the recent past) Makes sense as I have'ntnoticed any Window updates recently. I have not tried to turn it back on.Starting 10/19/09, recieved many malware/spyware attacks via pop ups, hijackedgoggle searches.I started running McAfee full scans. Each time it was finding different typs of trojans (Vundo, Generic Fake Alert, Artemis, Spy Agent, DNSChanger) Most were quarantined, some repaired, some 'cannot be removed'.After a failed attempt to contact McAfee, I came to this web site (yesterday 10/25).After reseaching, I found my'Windows Automatic Updates' was disabled. After trying to reenable it in Run-Sevices, it would return back to disabled...I then ranthe MS onecare live scan. It deleted:exploit:js/mult.bb (1 item)trojanwin32/vundo.fa (6 items)worm:win32/emold.u (1 item)worm:win32/vundo.b (6 items)Items 'Unable to clean':Trojan:Win32/vundo!bn (1 item)trojan:win32/vundo!g (10 items)Scan summary:Protection- 6 issues found, 25 items deleted and cleaned.objects that couldn't be scanned: 551551 objects couldn't bescanned.I was then able to reactivate my 'Windows Automatic Updates' in Run-Services and have'nt had a 'disabled' problem with it since (knock on wood). Butttt, I'm getting a RUNDLL pop up error now everytme Iturn my computer on and login.The pop up reads:"error loading C\windows\system32\tayanage.dll. The specified module could not be found"Today (Monday 10/26) I read the "How to get rid of malware" thread. I first ran an ESET scan. It found 1 threat: "a variant of win32/kryptic.ahr trojan" and quarantined it. It gave me the option to delete it and I did so.My next step was to follow Vincenzo DiRusso's directions from his 5/9/09 post on ridding my malware problem.Even though his directions didn't mention to reboot my computer in 'safe mode', I tried to and after promting it to do so I got the 'Blue Screen of Death' with the message: "A problem has been detected and Windows has been shut down to prevent damage to your computer. Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run chk/f (which I tried to in the run screen andchk/f couldn't be found) to check for hard drive corruption and then restart your computer...Technical info: ***stop: 0x0000007b(0XF8A0F524,0x0000034,0X00000000,0X00000000".Is it OK to proceed with Mr. Di Russo'smalwareremoval stepswithout mycomputer in safe mode?Should I have any worries about going on secure websites (bank, credit card accounts etc.) before attempting this malware removal process?If I getmy computer rid of this malware problem, should I keep my McAfeecoverage going? I see the free Microsoft Essentials protection option. Is that better? Can I run both on my computer? Or should I go with my currentMcAfee and WindowsDefender (WD)as I had before or, instead of WD, go with McAfeeand something like Previx.Thanks in advance,Jack1 person needs an answerI do too
October 27th, 2009 9:43am

I don't recommend McAfee products. For an antivirus I recommend NOD32 (commercial), Avast or Avira (free versions available). MS Security Essentials is a good, basic antivirus/antispyware program. It's not my first choice but it's OK. However none of these will help right now and you can't install a new antivirus onto an infected machine. You are infected with Vundo trojans. These are often protected by a rootkit and extremely difficult to clean. McAfee cannot do it. I suggest that you either get guided help at one of the specialty forums listed in the link below OR back up your data and do a clean install/factory restore of Windows OR take your computer to a professional. If you go the latter route, don't use a BigComputerStore/GeekSquad type of place. http://www.elephantboycomputers.com/page2.html#HJT-links MS-MVP - Elephant Boy Computers - Don't Panic!
Free Windows Admin Tool Kit Click here and download it now
October 27th, 2009 7:10pm

Thanks Malkeleah,I submitted a helprequest overat one of the speciality forumsat Elephant Boy Computers about 6 hours ago. Randomly chose one of the forums. Assume they are all about the same. Will let all know what happens.
October 28th, 2009 2:23pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics