Canreef Aquatics Bulletin Board  

Go Back   Canreef Aquatics Bulletin Board > Other > Lounge

Reply
 
Thread Tools Display Modes
  #11  
Old 01-04-2009, 04:55 AM
Powertec Powertec is offline
Member
 
Join Date: Jan 2008
Location: Airdrie
Posts: 153
Powertec is on a distinguished road
Default

Mark did you try to get to that site in Safemode?
I had an issue the other day which makes me wonder if i had the same problem but i went in with safemode with networking and managed to get whatever it was off.
Reply With Quote
  #12  
Old 01-04-2009, 06:00 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

still blocked in safemode
Reply With Quote
  #13  
Old 01-04-2009, 06:34 AM
KrazyKuch's Avatar
KrazyKuch KrazyKuch is offline
Member
 
Join Date: Dec 2004
Location: Calgary S.W
Posts: 656
KrazyKuch is on a distinguished road
Send a message via MSN to KrazyKuch
Default

Can you get to this website???
http://vundofix.atribune.org/

that should get ride of the trojan
__________________
500G Mixed Reef



__________________________________
Electrician, Electronics Technician, I can help with any electrical questions you might have!!
__________________________________

Kevin
Reply With Quote
  #14  
Old 01-04-2009, 06:53 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

Quote:
Originally Posted by KrazyKuch View Post
Can you get to this website???
http://vundofix.atribune.org/

that should get ride of the trojan
blocked in both IE and Firefox.

At least Canreef is still here.
Reply With Quote
  #15  
Old 01-04-2009, 07:15 AM
midgetwaiter midgetwaiter is offline
Member
 
Join Date: Nov 2005
Location: Calgary
Posts: 546
midgetwaiter is on a distinguished road
Default

Mark sent me a PM with a screenshot of what is going on when he tries to update spybot and I think you guys are right it is this vundo thing. I checked it out, it's a bastard.

For the techie types that may be interested, it works by using a Browser Help Object to snag requests to anti spyware sites and redirect them to localhost. This is especially evil because any spyware definition update that use a dll from the standard microsoft network package seem to be also redirected by the BHO.

Hijack This! is probably the best tool for getting rid of this kind of thing but like Snaz says it isn't exactly simple to use.

Mark, I'll put the Vundofix program from Atribune on my site and send you a link.
Reply With Quote
  #16  
Old 01-04-2009, 07:19 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

was able to get Vundofix v7.0.6 fr Softpedia.com.

It didn't find anything.
Reply With Quote
  #17  
Old 01-04-2009, 04:40 PM
Aquattro's Avatar
Aquattro Aquattro is offline
Just a guy..
 
Join Date: Aug 2001
Location: Victoria, BC
Posts: 18,053
Aquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the rough
Default

Can the BHO be unloaded from within IE? If not, can dll or ocx be renamed before launching IE?
__________________
Brad
Reply With Quote
  #18  
Old 01-04-2009, 04:47 PM
Snaz's Avatar
Snaz Snaz is offline
Member
 
Join Date: Aug 2008
Location: Surrey, BC
Posts: 1,034
Snaz is on a distinguished road
Default

If it is a Browser Helper Object(BHO) that is doing the redirect then Hijackthis should clean that up.
http://www.download.com/Trend-Micro-...-10227353.html

Close all other programs, install HJT and then click "Do System Scan and Save a Log file"

It will list all kinds of switches and programs that determine how your computer behaves. As a start, select all BHO and click "FIXED CHECKED". Becareful with the other items HJT finds as some of them are needed for your computer to run. Removing all BHO should not an issue but yahoo toolbars etc will be missiing but you can always install them again as needed. The object today is to get you browser to goto your AV home to update definitions. If your current AV does not fix it try AVG Free AV at:

http://grisoft.com and search there site for "FREE" and try the free version, very nice.

If that does not work and you have the time, try the HJT upload service, it may take you further.

Keith
__________________

Last edited by Snaz; 01-04-2009 at 04:51 PM.
Reply With Quote
  #19  
Old 01-04-2009, 09:06 PM
DanG's Avatar
DanG DanG is offline
Member
 
Join Date: Mar 2005
Location: Peg City
Posts: 609
DanG is on a distinguished road
Default

Quote:
Originally Posted by mark View Post
Using Superantispyware and Spybot (all freeware).

Thing with this is just tried the malwarebytes site and was blocked;

With Firefox get:

Failed to Connect

The connection was refused when attempting to contact www.malwarebytes.org.


Though the site seems valid, the browser was unable to establish a connection.

* Could the site be temporarily unavailable? Try again later.

* Are you unable to browse other sites? Check the computer's network connection.

* Is your computer or network protected by a firewall or proxy? Incorrect settings can interfere with Web browsing.

See if you can get it from http://www.download.com/Malwarebytes...=dl&tag=button
Reply With Quote
  #20  
Old 01-05-2009, 03:34 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

Quote:
Originally Posted by DanG View Post
Looks like I got it with Malwarebytes.

A big thanks to all.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 12:02 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.