Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 15-04-2008, 01:49 PM   #1 (permalink)
Can you hear it..??
 
windchimes's Avatar
 
Join Date: May 2005
Location: In my own corner of my room
Posts: 262
Unhappy How to remove these trojans..??

Hi,

I am using BitDefender Free Edition, Adware, and Spybot..Still my machine is infected with Trojan.Vundo.EGL . It is associated with the file fccyaYSM.dll in Windows/System32

What is this stuff..?? My machine is a bit slow..Earlier Spybot detected almost 16 entries under the same name and fixed it..but a recent scan with bitdefernder shows the presence of above entry.It can't disinfect,delete or move it to quarantine...

Anyone knows how to fix it..??
windchimes is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 15-04-2008, 01:51 PM   #2 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

you should scan in safe mode...

if still doesn't work out, download pc doctor from pack.google.com and scan in safe mode.

_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 15-04-2008, 02:30 PM   #3 (permalink)
Right Off the Assembly Line
 
Join Date: Apr 2008
Posts: 40
Default Re: How to remove these trojans..??

How about deleteting the file manually ?
janki2008 is offline  
Old 15-04-2008, 02:34 PM   #4 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

^^^
wont work as they will be already loaded and cos of that there will be a lock on the file


_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 15-04-2008, 02:58 PM   #5 (permalink)
Legen-wait for it-dary!
 
dheeraj_kumar's Avatar
 
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
Default Re: How to remove these trojans..??

Use Unlocker http://ccollomb.free.fr/unlocker/ to unlock locked files
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
dheeraj_kumar is offline  
Old 15-04-2008, 04:24 PM   #6 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

^^^^
yeah (process explorer will also be useful in this case) but you dunno for sure which all are virus files


_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 15-04-2008, 09:31 PM   #7 (permalink)
Can you hear it..??
 
windchimes's Avatar
 
Join Date: May 2005
Location: In my own corner of my room
Posts: 262
Default Trapped Again

Thanks for the reply guys..But not yet..
I fixed it using Symantec FixVundo 1.5
The report generated said :

The total number of the scanned files: 157302
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral processes suspended: 1
The number of viral threads terminated: 0
The number of registry entries fixed: 0

Well, I restarted my machine and then came the error message from windows saying that two modules couldn't be started because
ssvtvnko.dll and suhvafoh.dll were missing.

Few hours back I started my browser and was writing to you guys and again suddenly browser automatically closed...the system turned slow too

Back to Spybot scan and again found that the machine is infected with Vundo and two more new malware .Fixed it and scanned it again to show it's presence again.

Any idea how to fix this PERMANENTLY..?? Things have gone to that extent that I am suspecting even spybot and adaware (I can't format my machine at this point Plenty of data scattered across)

Here I am attaching the Spybot report

Anyone plz help
Attached Files
File Type: zip SpybotSD.Results.zip (22.4 KB, 0 views)
windchimes is offline  
Old 15-04-2008, 10:18 PM   #8 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

can you please say whether did you scan in safe mode ???


_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 15-04-2008, 10:23 PM   #9 (permalink)
Can you hear it..??
 
windchimes's Avatar
 
Join Date: May 2005
Location: In my own corner of my room
Posts: 262
Default Re: How to remove these trojans..??

Quote:
Originally Posted by DigitalDude View Post
can you please say whether did you scan in safe mode ???


_
No digital dude.. lt wasn't mentioned in FixVundo 1.5 ..And they said it did the job succesfully..Anyway I am checking the safe mode option..Talk to u soon.
windchimes is offline  
Old 15-04-2008, 10:34 PM   #10 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

just reboot and press F8 man (right after the BIOS post screen) you will get options to boot windows in safe mode.. choose that and you will boot into windows safe mode... then run the scan now it will clean everything


_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|
DigitalDude is offline  
Old 16-04-2008, 12:47 AM   #11 (permalink)
Can you hear it..??
 
windchimes's Avatar
 
Join Date: May 2005
Location: In my own corner of my room
Posts: 262
Unhappy Re: How to remove these trojans..??

I know that digital dude. and I did it.. Ran FixVundo from Symantec in Safe Mode but sadly it couldn't find any. Now I have to tell you i tried PC Tools Spyware Doctor before tring safe mode which detected a few after Spybot fixing. Interestingly when fixed you can see several command windows opening in random and closing...They are so fast so I couldn't get any details
The machine is slow now...

.Anyway I am attaching the FixVundo Log.
Attached Files
File Type: txt FixVundo.txt (373 Bytes, 1 views)
windchimes is offline  
Old 16-04-2008, 01:33 AM   #12 (permalink)
|| तमसो मा ज्योतिर्गमय ||
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,204
Default Re: How to remove these trojans..??

sorry mate just posted cos some ppl might not know that also
and this is a pretty old trojan virus

sadly theres no trace of finding it in the log

try the following link:
http://forums.techguy.org/malware-re...ndo-virus.html


btw for me a safe-mode scan with spybot and norton virus scan will remove everything... dunno much about stuff which doesn't go easily even after this step

_
__________________
|U2311H|i5-760|P7P55D-E LX|Blackline 4X2GB DDR3|Callisto 60GB|2 X WD1002FAEX|GTX460 HAWK TA|S12II 520W|
|PC-9F|HD201|Abyssus|Blackwidow|Ikari Opti|Vespula|WD10EARS|Inspiron 640M|

Last edited by DigitalDude; 16-04-2008 at 01:39 AM.
DigitalDude is offline  
Old 16-04-2008, 01:56 AM   #13 (permalink)
Can you hear it..??
 
windchimes's Avatar
 
Join Date: May 2005
Location: In my own corner of my room
Posts: 262
Default Re: How to remove these trojans..??

thanks dude..tired now...will check after a few hours
windchimes is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
infected pc with trojans heartripple Software Q&A 14 17-04-2008 04:47 PM
trojans and hack problems Tech_Wiz Software Q&A 4 11-08-2007 08:56 AM
~**~ How Can You Get Infected by Trojans?~**~ jrkraj Tutorials 1 07-02-2007 03:59 PM
Trojans... Lord Vader Software Q&A 4 18-11-2006 01:48 AM
Autopatcher infected with trojans??? drvarunmehta QnA (read only) 14 20-07-2005 07:54 AM


All times are GMT +5.5. The time now is 04:06 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2