View Full Version : Eeeek Trojan.Vundo.B


Twiglet
28-04-2005, 21:13
Help! Norton has found this virus on my computer and I've got an error message which stays in front which won't go away. I've run a virus scan and supposedly deleted the infected file, but it says at the end that the computer is still infected. I have also tried going in manually but the files don't show up so I can't delete it that way. The website doesn't seem to have any other suggestions. Any ideas?!?!?! :help:

sccsux
28-04-2005, 21:26
Originally posted by Twiglet
Help! Norton has found this virus on my computer and I've got an error message which stays in front which won't go away. I've run a virus scan and supposedly deleted the infected file, but it says at the end that the computer is still infected. I have also tried going in manually but the files don't show up so I can't delete it that way. The website doesn't seem to have any other suggestions. Any ideas?!?!?! :help:



Have you visited Symantecs website? There are removal instructions on here ->http://www.symantec.co.jp/avcenter/venc/data/trojan.vundo.b.html

vidster
28-04-2005, 21:33
WOW sccsux, your on the ball tonight!

Beat me to it :hihi:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.b.html

Katya
29-04-2005, 16:10
I've got exactly the same problem and have followed the instructions but I still cannot stop Norton Anti-Virus popping up and telling me there is a virus in the file "odbcmc.dll" . It alternates between telling me that "access is denied" and "Unable to repair this file".

I can find the file but Windows won't let me delete it as it says some other program is using it. I have tried to delete it in safe mode, but it still won't do it.

Any suggestions as to how to proceed would be most welcome

(edited as I previously said I couldn't find the file..)

Ann*
29-04-2005, 17:12
I found a similar trojan horse on my friend's pc a while ago, and it turned out to be contained in the installation program for Kazaa....I kept getting the message about the file was in use etc., but I kept trying to delete it, and then eventually I restarted the pc, and somehow it had disappeared....have any of you installed anything new over the past couple of days, or opened a spam e-mail by mistake?

Delete your temp internet files, including all the cookies....I know this is a pain because it means you have to login afresh to everything....and also completely empty your windows temp folder; there shouldn't be anything in that folder that is needed to keep your pc working, although I've found that there's usually one Zone Alarm file that won't delete when ZA is running.

sccsux
29-04-2005, 18:00
Originally posted by Katya
I can find the file but Windows won't let me delete it as it says some other program is using it. I have tried to delete it in safe mode, but it still won't do it.

Any suggestions as to how to proceed would be most welcome

(edited as I previously said I couldn't find the file..)


A lot depends on which file is using the DLL;).

If it is not a system file that is using it, simply boot to DOS (unless your using XP - in which case, ignore me;)) and delete it from there?




Originally posted by Ann_x
Alarm file that won't delete when ZA is running.


That'll be the ZoneAlarm Log File;).

Katya
30-04-2005, 08:50
Nothing suggested so far has worked.

It looks as if this is a new strain of the virus - there are loads of reports from people if you google "Trojan Vundo" and one particular article which cautions against using Norton:

http://www.politicalgateway.com/news/read.html?id=3641

I presume at some point Symantec will come up with a fix but in the meantime I'm not sure how fixable it is, especially if you are not computer-savvy.

LL200
30-04-2005, 15:53
this is symantec's removal tool for the virus:

http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.b.removal.tool.html

pinhead
01-05-2005, 09:56
Hi,

I too have this virus. Not sure but we think it happened on a gaming site. Symantec are useless, their helpline is only open 9-5 on weekdays. Idownloaded the fix and it tells me the problem is cured and to reboot. As soon as the computer reboots the warning pops up. Any other suggestions welcome, please. The computer is still usable if you drag the NAV warninng away from the desktop, but it is annoying.

LL200
01-05-2005, 10:43
been reading about this virus, its a pesky one to get rid of by the sounds of it.

one of the solutions i've read about that works (according to 'the internet', that great source which, of course, is -never- wrong) is detailed here:

http://groups.google.co.uk/groups?hl=en&lr=&client=firefox-a&rls=org.mozilla:en-US:official&selm=1114843398.671575.76900%40g14g2000cwa.googleg roups.com&rnum=1

looks like its a long and technical process but well detailed.

another solution which for some people could be easier is to install the hard disk as a slave in another machine and scan it with an up-to-date virus scanner. the virus infects a explorer (not to be confused with IE) and winlogon to name a couple of files, so while they're in use, its hard to clean them. installing the disk as a slave in another machine means that they wont be in use.

note: i'm only passing on what i've found, do at your own risk :)