<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-15754461.post7549690460431282826..comments</id><updated>2009-10-30T11:16:40.549-07:00</updated><category term='mobile'/><category term='forust'/><category term='cooking'/><category term='sheeptravel'/><category term='poem'/><category term='finance'/><category term='converted-doc'/><category term='stuff'/><category term='converted-htm'/><category term='build computer'/><category term='photos'/><category term='curl'/><category term='lyrics'/><category term='diary'/><category term='travel'/><category term='js'/><category term='journal'/><category term='spam'/><category term='ltoc'/><category term='blogclub'/><category term='wf:404'/><category term='video'/><category term='windows'/><category term='tmnt'/><category term='wf:out'/><category term='webfront'/><category term='rant'/><category term='cinebar'/><category term='linux'/><category term='apache'/><category term='story'/><category term='baseball'/><category term='wf:url'/><category term='xml'/><category term='turk'/><category term='batman'/><category term='tech'/><category term='business'/><category term='walk'/><category term='basic'/><category term='php'/><category term='howto'/><category term='enom'/><category term='music'/><category term='dream'/><category term='cats'/><category term='philosophy'/><category term='game'/><category term='book'/><category term='bellybye'/><category term='linkfest'/><category term='blogger'/><category term='miguel'/><category term='bio'/><category term='stocks'/><category term='muse'/><category term='converted-jor'/><category term='quotes'/><category term='coffee'/><category term='thief'/><category term='converted-txt'/><title type='text'>Comments on Gibdon Moon: Getting Rid of Vundo and Pop-Ups</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.gibdon.com/feeds/7549690460431282826/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html'/><author><name>Neil C. Obremski</name><uri>http://www.blogger.com/profile/06141393537077736482</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_vGt1OWtFHBI/SSxuHkSDoxI/AAAAAAAANDI/L8XBMm8xXiY/S220/10+PastyMickBastard.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-15754461.post-1841739659198963316</id><published>2009-10-30T11:16:40.549-07:00</published><updated>2009-10-30T11:16:40.549-07:00</updated><title type='text'>One of my co-workers had this on her computer and ...</title><content type='html'>One of my co-workers had this on her computer and none of the programs listed on bleepingcomputer could fix it.  The computer blue screened when try to get into SafeMode, I couldn&amp;#39;t get into regedit and I couldn&amp;#39;t delete any of the entries in HiJack This.  I followed your suggestions and loaded Windows Recovery Console and deleted the bad dll files that way - all fixed now :)  I think I owe you a beer!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/1841739659198963316'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/1841739659198963316'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1256926600549#c1841739659198963316' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-722737728'/></entry><entry><id>tag:blogger.com,1999:blog-15754461.post-410323079563353185</id><published>2008-12-13T14:24:00.000-08:00</published><updated>2008-12-13T14:24:00.000-08:00</updated><title type='text'>Neil, your suggestion worked Great!!! Thank you so...</title><content type='html'>Neil, your suggestion worked Great!!! Thank you so much!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/410323079563353185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/410323079563353185'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1229207040000#c410323079563353185' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2079689788'/></entry><entry><id>tag:blogger.com,1999:blog-15754461.post-1845735900125863307</id><published>2008-11-24T20:17:00.000-08:00</published><updated>2008-11-24T20:17:00.000-08:00</updated><title type='text'>Dang I just spent nearly an hour &lt;i&gt;actually&lt;/i&gt; g...</title><content type='html'>Dang I just spent nearly an hour &lt;I&gt;actually&lt;/I&gt; getting rid of frickin' Vundo.  It's insanely simple once you know what to do, but the problem is a lot of sources give you bad information.  Here's the low-down:&lt;BR/&gt;&lt;BR/&gt;1.) View C:\WINDOWS\System32 in Explorer sorted by "Created Date" to find the Vundo DLL's which should be very recent assuming you caught this early enough.  Its DLL names are always an 8 character assortment of upper and lower-case letters.&lt;BR/&gt;&lt;BR/&gt;2.) Write down the names of said files.&lt;BR/&gt;&lt;BR/&gt;3.) Boot off your Windows XP CD.  To do this put it in your drive, restart, and pay attention ... your computer should say something like "Press any key to boot from CD-ROM".&lt;BR/&gt;&lt;BR/&gt;4.) After waiting 4-EVA for the CD to "start Windows", select the "Recovery Console" option.  You'll need to type in your Administrator password so I hope you have it handy.&lt;BR/&gt;&lt;BR/&gt;5.) Type "CD \WINDOWS\System32" (without the quotes) and then for each file you wrote down type "DEL blahblah.dll" (where blahblah is the file name).&lt;BR/&gt;&lt;BR/&gt;6.) Type "EXIT" to restart your computer and this time don't boot from the CD.&lt;BR/&gt;&lt;BR/&gt;7.) Once back in Windows, you should be able to clean out the registry entries left behind without them constantly re-appearing.  Basically just run "REGEDIT" and do a search for those file names in the registry, deleting any place they show up.  If you have some sort of utility to check for "Windows Errors" then it will do this for you.&lt;BR/&gt;&lt;BR/&gt;--&lt;BR/&gt;&lt;BR/&gt;The problem I was having is that since Vundo hooks into WinLogon, NONE of the solutions I found worked 100%.  Sure they'd stop the BHO or pop-ups, but that main "kernel" of Vundo was still running.  The delete-on-reboot utilities ran AFTER WinLogon and therefore would not delete it and I couldn't rename the files even in Safe Mode.  Then I realized I was looking at it the wrong way, fighting the criminal from WITHIN their little cave rather than bombing it from outside.  Good thing I kept those boot CD's around!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/1845735900125863307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/1845735900125863307'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1227586620000#c1845735900125863307' title=''/><author><name>Neil C. Obremski</name><uri>http://www.blogger.com/profile/06141393537077736482</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://www.neilstuff.com/avatar'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1732840326'/></entry><entry><id>tag:blogger.com,1999:blog-15754461.post-462693970132345895</id><published>2008-11-23T10:32:00.000-08:00</published><updated>2008-11-23T10:32:00.000-08:00</updated><title type='text'>Wouldn't you know it, but nearly a year later and ...</title><content type='html'>Wouldn't you know it, but nearly a year later and I got Vundo on my desktop.  I launched Internet Explorer simply to test a website and I believe some malicious AD code installed it on my system.  Using my own blog entry (this one) I removed it with HijackThis and in doing so I found that the URL to that in my post is no longer valid (fixing now).&lt;BR/&gt;&lt;BR/&gt;The culprit this time?&lt;BR/&gt;&lt;BR/&gt;&lt;B&gt;O4 - HKLM\..\Run: [acfa1503] rundll32.exe "C:\WINDOWS\system32\wroovkbn.dll",b&lt;/B&gt;&lt;BR/&gt;&lt;BR/&gt;In case it helps, it was launching THIS website:&lt;BR/&gt;&lt;BR/&gt;&lt;B&gt;http://www.premiercardoffers.com/?Mkt=674&amp;amp;SubMkt=1341&amp;amp;PID=1&amp;amp;BID=0&amp;amp;SourceID=YOUR_SOURCEID&amp;amp;jump=ap1&lt;/B&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/462693970132345895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/462693970132345895'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1227465120000#c462693970132345895' title=''/><author><name>Neil C. Obremski</name><uri>http://www.blogger.com/profile/06141393537077736482</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://www.neilstuff.com/avatar'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1732840326'/></entry><entry><id>tag:blogger.com,1999:blog-15754461.post-8190929551943550748</id><published>2008-02-04T16:55:00.000-08:00</published><updated>2008-02-04T16:55:00.000-08:00</updated><title type='text'>Yes I too have the same problem as your sister.It ...</title><content type='html'>Yes I too have the same problem as your sister.It started happening after I had downloaded some MP3 files from Limewire. &lt;BR/&gt;The pop-up that appears at the bottom  right hand corner is Malware. Just Google Advanced Cleaner and you'll see what I mean. Also known as Drive Cleaner as well.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/8190929551943550748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/8190929551943550748'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1202172900000#c8190929551943550748' title=''/><author><name>austral alien</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1944354270'/></entry><entry><id>tag:blogger.com,1999:blog-15754461.post-2462065110614031639</id><published>2008-01-01T15:39:00.000-08:00</published><updated>2008-01-01T15:39:00.000-08:00</updated><title type='text'>Hi, this virus is running rampant this month and i...</title><content type='html'>Hi, this virus is running rampant this month and it is a new strain of vundo that is very potent and corrupts many files. The only program that is currently able to completely remove it is called combofix You can download it through a site called bleepingcomputer.&lt;BR/&gt;&lt;BR/&gt;After running combofix, if any important system files are quarantined you can reinstall them by taking the log file after combofix is done, renaming it log.txt, and dropping it into the rev icon on your desktop. This whole issue and these fixes are discussed on the avast antivirus forums.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/2462065110614031639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15754461/7549690460431282826/comments/default/2462065110614031639'/><link rel='alternate' type='text/html' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html?showComment=1199230740000#c2462065110614031639' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.gibdon.com/2007/12/getting-rid-of-vundo-and-pop-ups.html' ref='tag:blogger.com,1999:blog-15754461.post-7549690460431282826' source='http://www.blogger.com/feeds/15754461/posts/default/7549690460431282826' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-993705656'/></entry></feed>
