Help - Search - Members - Calendar
Full Version: No video on computer restart after trojan vundo infection
Malwarebytes Forum > Malwarebytes' Anti-Malware Support > General Malwarebytes' Anti-Malware Forum
pak_ratt
Hi this is my first post and I will do my best to describe the problem I am having. My computer got this trogen.vundo infection when I went to a sharware website. The 2009 antivirus program started running I closed it then all hell broke loose. Malware was able to remove and quarentine the infection and the scans are now clean. Now I have a problem when the computer boots up (cold trun on) sometimes there is no video showing on the monitor, no every boot. I can power down the computer hard shut down sad.gif and it will start up correctly. I did not have any known issues with this computer prior to this trogen infection. Is there something else I can do or check for? Any help or suggestions would be most apprieciated

Tim
Maurice Naggar
Hello pak ratt,

Read the very topmost notes at the HijackThis Logs sub-forum because you will need to post your issues there after you manage to get & run a HijackThis log, and create a NEW Topic on that sub-forum.

Please be aware that with the latest malware infections floating around, it takes more than one single tool to remove the several malwares that your system has onboard. Any one tool is not sufficient.

Let me have you get started with some very basics, and suggest you create a thread in HijackThis afterwards.
Be aware that there is more to be done even after this.

If you have Windows XP, then:
    Set Windows to show all files and all folders.
    On your Desktop, double click My Computer, from the menu options, select tools, then Folder Options, and then select VIEW Tab and look at all of settings listed.

    "CHECK" (turn on) Display the contents of system folders.

    Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.
    Next, un-check Hide extensions for known file types.
    Next un-check Hide protected operating system files.


IF this is running Vista, then:
    Show all files:
    • Click the Start button, and then click Computer.
    • On the Organize menu, click Folder and Search Options.
    • Click the View tab.
    • Locate and uncheck Hide file extensions for known file types.
    • Locate and uncheck Hide protected operating system files (Recommended).
    • Locate and click Show hidden files and folders.
    • Click Apply > OK.

=
Download to your Desktop FixPolicies.exe, by Bill Castner, MS-MVP, a self-extracting ZIP archive from here:
http://cid-6aaab341ce47c5c2.skydrive.live....FixPolicies.exe
  • Double-click FixPolicies.exe.
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box will briefly appear and then close.
  • This fix may prove temporary. Active malware may revert these changes at your next startup. You can safely run the utility again.
  • Note: some malware will block the running of this tool. So if you cannot run Fixpolicies, then, RENAME the EXE file to something like Mytool.exe and then run it.


Download this INF repair file by MS-MVP Miekiemoes: http://users.telenet.be/bluepatchy/miekiem...orepolicies.zip
Unzip the download. Open the folder VArestorepolicies and Right-click the file inside, VArestorepolicies.INF and choose Install.

Delete the download, the unzipped folder and all contents.
=

Take out the trash (temporary files & temporary internet files)
Please download ATF Cleaner by Atribune, saving it to your desktop. It is used to cleanout temporary files & temp areas used by internet browsers.
Start ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser, do this also:
Click Opera at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
ATF-Cleaner should be run per the above in every user-login account {User Profile}
=

Download DDS and save it to your desktop from http://www.techsupportforum.com/sectools/sUBs/dds here or
http://download.bleepingcomputer.com/sUBs/dds.scr or

http://www.forospyware.com/sUBs/dds

Disable any script blocker if your antivirus/antimalware has it.
Then double click dds.scr to run the tool.
When done, DDS.txt will open.
Click Yes at the next prompt for Optional Scan.

  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop.

  • Please include the following logs in your next reply:
    DDS.txt
    Attach.txt


    Then and only then, at the HijackThis sub-forum
    http://www.malwarebytes.org/forums/index.php?showforum=7
    create a new post for your issues by clicking on blue button labeled NEWTOPIC

    In that post, describe your issues in detail, including your Windows version,
    and if you downloaded videos or so-called codecs from the internet,
    and copy and paste into it (inside the body of reply) copies of the DDS.txt and the Attach.txt
    After posting, await a reply. There will be much more to do to actually remove the residual malwares.
    This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
    Invision Power Board © 2001-2010 Invision Power Services, Inc.