Welcome to the { mindfrost82.com } forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows XP > More Help & Support

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-06-2008, 10:33 PM
Michael
 
Posts: n/a
Can't remove Vundo/MS Juan trojan

I tried 5 different apps but I can't keep this removed. It keeps reappearing
in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is there a
fix to remove this permanently?



Reply With Quote
  #2 (permalink)  
Old 07-06-2008, 11:08 PM
=?Utf-8?B?bmFzcw==?=
 
Posts: n/a
RE: Can't remove Vundo/MS Juan trojan



"Michael" wrote:

> I tried 5 different apps but I can't keep this removed. It keeps reappearing
> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is there a
> fix to remove this permanently?


Read these info:
http://www.castlecops.com/t224702-He...o_MS_Juan.html

http://www.bleepingcomputer.com/forums/topic135123.html

http://forums.techguy.org/malware-re...-sorry-ms.html
http://forum.avast.com/index.php?topic=36067.15

Right click on the subfolder on that Key and select permissions and assign
yourself a full control on that key then try the deletion, does it help?

Start in safe mode and try the deletion.
Try this tool:
http://www.ccleaner.com
HTH.
nass
---
http://www.nasstec.co.uk

Reply With Quote
  #3 (permalink)  
Old 07-06-2008, 11:31 PM
Michael
 
Posts: n/a
Re: Can't remove Vundo/MS Juan trojan

I can delete MS Juan but it keeps coming back.

"nass" <nass@discussions.microsoft.com> wrote in message
news:BA3FFB13-04D0-455C-920F-296494D3786D@microsoft.com...
>
>
> "Michael" wrote:
>
>> I tried 5 different apps but I can't keep this removed. It keeps
>> reappearing
>> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is
>> there a
>> fix to remove this permanently?

>
> Read these info:
> http://www.castlecops.com/t224702-He...o_MS_Juan.html
>
> http://www.bleepingcomputer.com/forums/topic135123.html
>
> http://forums.techguy.org/malware-re...-sorry-ms.html
> http://forum.avast.com/index.php?topic=36067.15
>
> Right click on the subfolder on that Key and select permissions and assign
> yourself a full control on that key then try the deletion, does it help?
>
> Start in safe mode and try the deletion.
> Try this tool:
> http://www.ccleaner.com
> HTH.
> nass
> ---
> http://www.nasstec.co.uk
>



Reply With Quote
  #4 (permalink)  
Old 07-07-2008, 11:37 AM
TaurArian
 
Posts: n/a
Re: Can't remove Vundo/MS Juan trojan

FYI - http://www.microsoft.com/security/po...=Win32%2fVundo
Vundo (McAfee)
Trojan:Win32/Vundo.K (Microsoft)
Vundo.gen18 (Norman)
Summary
Win32/Vundo is a multiple-component family of programs that deliver 'out of context'
pop-up advertisements. They may also download and execute arbitrary files.
Vundo is often distributed as a DLL file and installed on an affected machine as a Browser
Helper Object (BHO) without a user's consent. This family uses advanced defensive and
stealth techniques to escape detection and to hinder removal.

For assistance -

Try the Security - Viruses Newsgroup

OE client -
news://msnews.microsoft.com/microsof...security.virus
or
Web client -
http://www.microsoft.com/communities...&lang=en&cr=us


--

TaurArian [MVP] 2005-2009 - Update Services
http://taurarian.mvps.org
======================================
How to ask a question: http://support.microsoft.com/kb/555375
Computer Maintenance: Acronis / Diskeeper / Paragon / Raxco


"Michael" <reply@spam.com> wrote in message news:e9djNg73IHA.1192@TK2MSFTNGP05.phx.gbl...
|I can delete MS Juan but it keeps coming back.
|
| "nass" <nass@discussions.microsoft.com> wrote in message
| news:BA3FFB13-04D0-455C-920F-296494D3786D@microsoft.com...
| >
| >
| > "Michael" wrote:
| >
| >> I tried 5 different apps but I can't keep this removed. It keeps
| >> reappearing
| >> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is
| >> there a
| >> fix to remove this permanently?
| >
| > Read these info:
| > http://www.castlecops.com/t224702-He...o_MS_Juan.html
| >
| > http://www.bleepingcomputer.com/forums/topic135123.html
| >
| >
http://forums.techguy.org/malware-re...-sorry-ms.html
| > http://forum.avast.com/index.php?topic=36067.15
| >
| > Right click on the subfolder on that Key and select permissions and assign
| > yourself a full control on that key then try the deletion, does it help?
| >
| > Start in safe mode and try the deletion.
| > Try this tool:
| > http://www.ccleaner.com
| > HTH.
| > nass
| > ---
| > http://www.nasstec.co.uk
| >
|
|


Reply With Quote
  #5 (permalink)  
Old 07-07-2008, 01:10 PM
Elmo
 
Posts: n/a
Re: Can't remove Vundo/MS Juan trojan

Michael wrote:
> I can delete MS Juan but it keeps coming back.
>
> "nass" <nass@discussions.microsoft.com> wrote in message
> news:BA3FFB13-04D0-455C-920F-296494D3786D@microsoft.com...
>>
>> "Michael" wrote:
>>
>>> I tried 5 different apps but I can't keep this removed. It keeps
>>> reappearing
>>> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is
>>> there a
>>> fix to remove this permanently?

>> Read these info:
>> http://www.castlecops.com/t224702-He...o_MS_Juan.html
>>
>> http://www.bleepingcomputer.com/forums/topic135123.html
>>
>> http://forums.techguy.org/malware-re...-sorry-ms.html
>> http://forum.avast.com/index.php?topic=36067.15
>>
>> Right click on the subfolder on that Key and select permissions and assign
>> yourself a full control on that key then try the deletion, does it help?
>>
>> Start in safe mode and try the deletion.
>> Try this tool:
>> http://www.ccleaner.com
>> HTH.
>> nass
>> ---
>> http://www.nasstec.co.uk


But you need to boot to Safe Mode, and run at least, a good a/v program
and a good spyware program to remove whatever keeps reapplying that
registry entry.

"Safe Mode with Networking" should allow you to update your compromised
a/v software before the full scan.

And as a last resort, or just as further protection against the next
infection, Spybot S&D includes "Tea Timer" which alerts you to registry
changes. Once you set it to not allow that change, and to remember the
reply, you shouldn't see it added again. Tea Timer can also alert you
to other changes, but it is a nuisance at times.. You can turn off the
alerts at each remembered block or allow operation though.

--
Joe =o)
Reply With Quote
  #6 (permalink)  
Old 07-07-2008, 02:18 PM
jimbo571@operamail.com
 
Posts: n/a
Re: Can't remove Vundo/MS Juan trojan

On Sun, 6 Jul 2008 15:31:01 -0700, "Michael" <reply@spam.com> wrote:

>I can delete MS Juan but it keeps coming back.
>
>"nass" <nass@discussions.microsoft.com> wrote in message
>news:BA3FFB13-04D0-455C-920F-296494D3786D@microsoft.com...
>>
>>
>> "Michael" wrote:
>>
>>> I tried 5 different apps but I can't keep this removed. It keeps
>>> reappearing
>>> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is
>>> there a
>>> fix to remove this permanently?

>>
>> Read these info:
>> http://www.castlecops.com/t224702-He...o_MS_Juan.html
>>
>> http://www.bleepingcomputer.com/forums/topic135123.html
>>
>> http://forums.techguy.org/malware-re...-sorry-ms.html
>> http://forum.avast.com/index.php?topic=36067.15
>>
>> Right click on the subfolder on that Key and select permissions and assign
>> yourself a full control on that key then try the deletion, does it help?
>>
>> Start in safe mode and try the deletion.
>> Try this tool:
>> http://www.ccleaner.com
>> HTH.
>> nass
>> ---
>> http://www.nasstec.co.uk
>>

>


Are you using any registry security programs ?- they can stop you
editing the registry .
Reply With Quote
  #7 (permalink)  
Old 07-07-2008, 03:11 PM
=?Utf-8?B?bmFzcw==?=
 
Posts: n/a
Re: Can't remove Vundo/MS Juan trojan



"Elmo" wrote:

> Michael wrote:
> > I can delete MS Juan but it keeps coming back.
> >
> > "nass" <nass@discussions.microsoft.com> wrote in message
> > news:BA3FFB13-04D0-455C-920F-296494D3786D@microsoft.com...
> >>
> >> "Michael" wrote:
> >>
> >>> I tried 5 different apps but I can't keep this removed. It keeps
> >>> reappearing
> >>> in the registry as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan. Is
> >>> there a
> >>> fix to remove this permanently?
> >> Read these info:
> >> http://www.castlecops.com/t224702-He...o_MS_Juan.html
> >>
> >> http://www.bleepingcomputer.com/forums/topic135123.html
> >>
> >> http://forums.techguy.org/malware-re...-sorry-ms.html
> >> http://forum.avast.com/index.php?topic=36067.15
> >>
> >> Right click on the subfolder on that Key and select permissions and assign
> >> yourself a full control on that key then try the deletion, does it help?
> >>
> >> Start in safe mode and try the deletion.
> >> Try this tool:
> >> http://www.ccleaner.com
> >> HTH.
> >> nass
> >> ---
> >> http://www.nasstec.co.uk

>
> But you need to boot to Safe Mode, and run at least, a good a/v program
> and a good spyware program to remove whatever keeps reapplying that
> registry entry.
>
> "Safe Mode with Networking" should allow you to update your compromised
> a/v software before the full scan.
>
> And as a last resort, or just as further protection against the next
> infection, Spybot S&D includes "Tea Timer" which alerts you to registry
> changes. Once you set it to not allow that change, and to remember the
> reply, you shouldn't see it added again. Tea Timer can also alert you
> to other changes, but it is a nuisance at times.. You can turn off the
> alerts at each remembered block or allow operation though.
>
> --
> Joe =o)



I think Michael need to run a thorough scan again and then Delete all
restore points then recreate a new one by doing this:
Right click on "My Computer" select properties then click on System Restore
Tab and checking this check box:
[ ] Turn OFF System Restore on all drivers

Click [Apply] then [OK].
Repeat the steps again and this time Uncheck the check Box:
[ ] Turn OFF System Restore on all drivers

Click [Apply] then [OK].
Reboot your machine, do you still see the Entry for the Trojan?

Also jimbo571 Opera (lol) given a good option that if you are running a
security software in real time can block the chamges and on Restart all comes
back to original settings.
HTH

Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows XP > More Help & Support


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:35 AM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Learn Spanish | MPAA | Agencia de viagens | Buy Anything On eBay | Loan



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114