Canreef Aquatics Bulletin Board  

Go Back   Canreef Aquatics Bulletin Board > Other > Lounge

Reply
 
Thread Tools Display Modes
  #1  
Old 01-04-2009, 07:15 AM
midgetwaiter midgetwaiter is offline
Member
 
Join Date: Nov 2005
Location: Calgary
Posts: 546
midgetwaiter is on a distinguished road
Default

Mark sent me a PM with a screenshot of what is going on when he tries to update spybot and I think you guys are right it is this vundo thing. I checked it out, it's a bastard.

For the techie types that may be interested, it works by using a Browser Help Object to snag requests to anti spyware sites and redirect them to localhost. This is especially evil because any spyware definition update that use a dll from the standard microsoft network package seem to be also redirected by the BHO.

Hijack This! is probably the best tool for getting rid of this kind of thing but like Snaz says it isn't exactly simple to use.

Mark, I'll put the Vundofix program from Atribune on my site and send you a link.
Reply With Quote
  #2  
Old 01-04-2009, 07:19 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

was able to get Vundofix v7.0.6 fr Softpedia.com.

It didn't find anything.
Reply With Quote
  #3  
Old 01-04-2009, 04:40 PM
Aquattro's Avatar
Aquattro Aquattro is offline
Just a guy..
 
Join Date: Aug 2001
Location: Victoria, BC
Posts: 18,053
Aquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the rough
Default

Can the BHO be unloaded from within IE? If not, can dll or ocx be renamed before launching IE?
__________________
Brad
Reply With Quote
  #4  
Old 01-04-2009, 04:47 PM
Snaz's Avatar
Snaz Snaz is offline
Member
 
Join Date: Aug 2008
Location: Surrey, BC
Posts: 1,034
Snaz is on a distinguished road
Default

If it is a Browser Helper Object(BHO) that is doing the redirect then Hijackthis should clean that up.
http://www.download.com/Trend-Micro-...-10227353.html

Close all other programs, install HJT and then click "Do System Scan and Save a Log file"

It will list all kinds of switches and programs that determine how your computer behaves. As a start, select all BHO and click "FIXED CHECKED". Becareful with the other items HJT finds as some of them are needed for your computer to run. Removing all BHO should not an issue but yahoo toolbars etc will be missiing but you can always install them again as needed. The object today is to get you browser to goto your AV home to update definitions. If your current AV does not fix it try AVG Free AV at:

http://grisoft.com and search there site for "FREE" and try the free version, very nice.

If that does not work and you have the time, try the HJT upload service, it may take you further.

Keith
__________________

Last edited by Snaz; 01-04-2009 at 04:51 PM.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 08:27 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.