Removing Trojan Vundo with VundoFix.exe from Atribune.org

Q

Removing Trojan Vundo with VundoFix.exe from Atribune.org

✍: Guest

A

1. Downloaded VundoFix.exe from http://www.atribune.org/ccount/click.php?id=4
11/04/2006 09:56 AM 88,576 VundoFix.exe
File properties:
File version: 6.2.0.6
Copyright: (C) atribune.org

2. Ran VundoFix and clicked "Scan for Vundo". It scanned only the system directories and returned the results in a few minutes:
jkkjj.dll
vtsts.dll
ststv.ini
ststv.bak1
ststv.bak2
ststv.ini2
ststv.tmp
vtsts.dll
drivers\dp.sys
ststv.ini
ststv.bak1
ststv.bak2
ststv.ini2
ststv.tmp
ststv.ini
ststv.bak1
ststv.bak2
ststv.ini2
ststv.tmp


3. Restarted the system in safe mode (Safe mode with command line prompt).

4. Ran VundoFix.exe again from the command line and clicked "Scan for Vundo".

5. Clicked "Remove Vundo". It did some work and displayed a message saying: "vtsts.dll could not be deleted. VundoFix will load on reboot to attempt removal. Please click Remove Vundo when rebooted".

6. Clicked OK to let the system to reboot. VundoFix.exe started by itself. I clicked "Remove Vundo". It did some work and closed itself.

7. I Ran VundoFix.exe and did scan again. Surprisingly, it still reported two Vundo files:
vtsts.dll
ststv.ini

8. This time, I clicked "Remove Vundo" right in the normal mode, no restarting in safe mode.

9. VundoFix.exe closed all other running processes, only leaving the desktop background image on the screen. After a couple of minutes, it shows a message saying "Done. Click OK to reboot the system".

10. Clicked OK. System rebooted without any problem.

2013-02-06, 5813👍, 1💬