• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

nasty trojan:win32/vundo.gen!bd

Joined
Sep 5, 2004
Messages
1,956 (0.27/day)
Location
The Kingdom of Norway
Processor Ryzen 5900X
Motherboard Gigabyte B550I AORUS PRO AX 1.1
Cooling Noctua NB-U12A
Memory 2x 32GB Fury DDR4 3200mhz
Video Card(s) PowerColor Radeon 5700 XT Red Dragon
Storage Kingston FURY Renegade 2TB PCIe 4.0
Display(s) 2x Dell U2412M
Case Phanteks P400A
Audio Device(s) Hifimediy Sabre 9018 USB DAC
Power Supply Corsair AX850 (from 2012)
Software Windows 10?

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
antivirus reccomendations always boil down to three.

kaspersky, nod32, malwarebytes.

Thats pretty much their order of popularity, and the order of preference i have. kaspersky is dirt cheap on ebay (2009 keys work on the latest 2010 version, so you can buy the older ones even cheaper)
 
Joined
Sep 5, 2004
Messages
1,956 (0.27/day)
Location
The Kingdom of Norway
Processor Ryzen 5900X
Motherboard Gigabyte B550I AORUS PRO AX 1.1
Cooling Noctua NB-U12A
Memory 2x 32GB Fury DDR4 3200mhz
Video Card(s) PowerColor Radeon 5700 XT Red Dragon
Storage Kingston FURY Renegade 2TB PCIe 4.0
Display(s) 2x Dell U2412M
Case Phanteks P400A
Audio Device(s) Hifimediy Sabre 9018 USB DAC
Power Supply Corsair AX850 (from 2012)
Software Windows 10?
anti-virus = NOD32
anti-crapware = MalwareBytes Anti-Malware
for me ;)
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
I just installed malwarebytes, and decided that i still dont like it. it may be great at detecting things, but it uses scare-monger tactics on harmless things.

On a fresh windows 7 install i've been warned i have an "infected" "bad" item - and you know what it was? a registry key mis-detected. Something about a policy for "noactivedesktopchanges" which is default in windows 7.

False positives and making small issues appear to be large ones, is the best way to get me to blacklist a program and refuse to use it. Malwarebytes is still on my shitlist.
 
Joined
Jan 11, 2005
Messages
1,491 (0.21/day)
Location
66 feet from the ground
System Name 2nd AMD puppy
Processor FX-8350 vishera
Motherboard Gigabyte GA-970A-UD3
Cooling Cooler Master Hyper TX2
Memory 16 Gb DDR3:8GB Kingston HyperX Beast + 8Gb G.Skill Sniper(by courtesy of tabascosauz &TPU)
Video Card(s) Sapphire RX 580 Nitro+;1450/2000 Mhz
Storage SSD :840 pro 128 Gb;Iridium pro 240Gb ; HDD 2xWD-1Tb
Display(s) Benq XL2730Z 144 Hz freesync
Case NZXT 820 PHANTOM
Audio Device(s) Audigy SE with Logitech Z-5500
Power Supply Riotoro Enigma G2 850W
Mouse Razer copperhead / Gamdias zeus (by courtesy of sneekypeet & TPU)
Keyboard MS Sidewinder x4
Software win10 64bit ltsc
Benchmark Scores irrelevant for me
i once had vundo and no matter what tools used the system remain affected even if you don't have the virus anymore;only a fresh install help or a restore from back-up if available

good luck!
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
i once had vundo and no matter what tools used the system remain affected even if you don't have the virus anymore;only a fresh install help or a restore from back-up if available

good luck!

vundo is nasty. i've had to clean it off other peoples machines several times, the vundo fix tool i listed is the only one that ever did the trick. Its because vundo opens the door to many other viruses, and thats the only tool designed to get not just vundo, but the crap it downloads too (which often is the cause for re-downloading vundo, and the source of reinfection)
 
Joined
Jan 11, 2005
Messages
1,491 (0.21/day)
Location
66 feet from the ground
System Name 2nd AMD puppy
Processor FX-8350 vishera
Motherboard Gigabyte GA-970A-UD3
Cooling Cooler Master Hyper TX2
Memory 16 Gb DDR3:8GB Kingston HyperX Beast + 8Gb G.Skill Sniper(by courtesy of tabascosauz &TPU)
Video Card(s) Sapphire RX 580 Nitro+;1450/2000 Mhz
Storage SSD :840 pro 128 Gb;Iridium pro 240Gb ; HDD 2xWD-1Tb
Display(s) Benq XL2730Z 144 Hz freesync
Case NZXT 820 PHANTOM
Audio Device(s) Audigy SE with Logitech Z-5500
Power Supply Riotoro Enigma G2 850W
Mouse Razer copperhead / Gamdias zeus (by courtesy of sneekypeet & TPU)
Keyboard MS Sidewinder x4
Software win10 64bit ltsc
Benchmark Scores irrelevant for me
vundo is nasty. i've had to clean it off other peoples machines several times, the vundo fix tool i listed is the only one that ever did the trick. Its because vundo opens the door to many other viruses, and thats the only tool designed to get not just vundo, but the crap it downloads too (which often is the cause for re-downloading vundo, and the source of reinfection)


i used the same tool also but this virus is so well made.. it makes subtle changes to os and the general functionality will be degraded after removal (slower boot, programs open time even game fps decrease) that's why i preferred fresh install; of course this depend on the user decision after removal :)
 

InnocentCriminal

Resident Grammar Amender
Joined
Feb 21, 2005
Messages
6,477 (0.92/day)
System Name BeeR 6
Processor Intel Core i7 3770K*
Motherboard ASUS Maximus V Gene (1155/Z77)
Cooling Corsair H100i
Memory 16GB Samsung Green 1600MHz DDR3**
Video Card(s) 4GB MSI Gaming X RX480
Storage 256GB Samsung 840 Pro SSD
Display(s) 27" Samsung C27F591FDU
Case Fractal Design Arc Mini
Power Supply Corsair HX750W
Software 64bit Microsoft Windows 10 Pro
Benchmark Scores *@ 4.6GHz **@ 2133MHz
Malwarebytes really kicks the lama's ass.

Or something.
 
Joined
Jan 11, 2005
Messages
1,491 (0.21/day)
Location
66 feet from the ground
System Name 2nd AMD puppy
Processor FX-8350 vishera
Motherboard Gigabyte GA-970A-UD3
Cooling Cooler Master Hyper TX2
Memory 16 Gb DDR3:8GB Kingston HyperX Beast + 8Gb G.Skill Sniper(by courtesy of tabascosauz &TPU)
Video Card(s) Sapphire RX 580 Nitro+;1450/2000 Mhz
Storage SSD :840 pro 128 Gb;Iridium pro 240Gb ; HDD 2xWD-1Tb
Display(s) Benq XL2730Z 144 Hz freesync
Case NZXT 820 PHANTOM
Audio Device(s) Audigy SE with Logitech Z-5500
Power Supply Riotoro Enigma G2 850W
Mouse Razer copperhead / Gamdias zeus (by courtesy of sneekypeet & TPU)
Keyboard MS Sidewinder x4
Software win10 64bit ltsc
Benchmark Scores irrelevant for me
Malwarebytes really kicks the lama's ass.

Or something.

i agree with you but in the hand of a novice user it may make more damage than good

it has the tendency to delete-clean more than necessary from system and program files

i used it a few times and the results wasn't the expected ones so i'm a novice also i admit;only with online assistance from the site can be used acceptably.
 

InnocentCriminal

Resident Grammar Amender
Joined
Feb 21, 2005
Messages
6,477 (0.92/day)
System Name BeeR 6
Processor Intel Core i7 3770K*
Motherboard ASUS Maximus V Gene (1155/Z77)
Cooling Corsair H100i
Memory 16GB Samsung Green 1600MHz DDR3**
Video Card(s) 4GB MSI Gaming X RX480
Storage 256GB Samsung 840 Pro SSD
Display(s) 27" Samsung C27F591FDU
Case Fractal Design Arc Mini
Power Supply Corsair HX750W
Software 64bit Microsoft Windows 10 Pro
Benchmark Scores *@ 4.6GHz **@ 2133MHz
That is completely weird, I've never seen Malwarebytes give a false positive. I whole heartedly disagree it uses scare tactics. We like so much at work we use it when some tardo messes their machine up by visiting dirty sites.

I don't know how I managed without Malwarebytes tbh, I love NOD32 but Malwarebytes is definitely an essential item for me now. I don't use any AV just a hardware firewall and MB.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
That is completely weird, I've never seen Malwarebytes give a false positive. I whole heartedly disagree it uses scare tactics. We like so much at work we use it when some tardo messes their machine up by visiting dirty sites.

I don't know how I managed without Malwarebytes tbh, I love NOD32 but Malwarebytes is definitely an essential item for me now. I don't use any AV just a hardware firewall and MB.

well it tells me it has found "infected" files, when its talking about the registry. to me, Infected means something has attached itself to an existing file, adding malicious code and such.




After i click show results, it tells me about this "bad" file.



well actually, no it doesnt tell me squat.




My infected, bad file is... what? from what that says, a registry key is infected and wants to hijack my display properties.
 

InnocentCriminal

Resident Grammar Amender
Joined
Feb 21, 2005
Messages
6,477 (0.92/day)
System Name BeeR 6
Processor Intel Core i7 3770K*
Motherboard ASUS Maximus V Gene (1155/Z77)
Cooling Corsair H100i
Memory 16GB Samsung Green 1600MHz DDR3**
Video Card(s) 4GB MSI Gaming X RX480
Storage 256GB Samsung 840 Pro SSD
Display(s) 27" Samsung C27F591FDU
Case Fractal Design Arc Mini
Power Supply Corsair HX750W
Software 64bit Microsoft Windows 10 Pro
Benchmark Scores *@ 4.6GHz **@ 2133MHz
I still wouldn't say that's scare tactics, it's obviously stating that the original registry key has been hi-jacked/modified. If it concerns you so much, why not email Malwarebytes and ask for an explanation or even tell them how they could change this.
 
Joined
Jan 11, 2005
Messages
1,491 (0.21/day)
Location
66 feet from the ground
System Name 2nd AMD puppy
Processor FX-8350 vishera
Motherboard Gigabyte GA-970A-UD3
Cooling Cooler Master Hyper TX2
Memory 16 Gb DDR3:8GB Kingston HyperX Beast + 8Gb G.Skill Sniper(by courtesy of tabascosauz &TPU)
Video Card(s) Sapphire RX 580 Nitro+;1450/2000 Mhz
Storage SSD :840 pro 128 Gb;Iridium pro 240Gb ; HDD 2xWD-1Tb
Display(s) Benq XL2730Z 144 Hz freesync
Case NZXT 820 PHANTOM
Audio Device(s) Audigy SE with Logitech Z-5500
Power Supply Riotoro Enigma G2 850W
Mouse Razer copperhead / Gamdias zeus (by courtesy of sneekypeet & TPU)
Keyboard MS Sidewinder x4
Software win10 64bit ltsc
Benchmark Scores irrelevant for me
thanks Mussels but if you make a deep scan with different settings i'm sure will find more
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
I still wouldn't say that's scare tactics, it's obviously stating that the original registry key has been hi-jacked/modified. If it concerns you so much, why not email Malwarebytes and ask for an explanation or even tell them how they could change this.

thats obviously whats happened, but its NOT what the program says. the program is saying i have an 'infection'

Infection vs. registry key not on default.... cmon. the program is just comparing reg keys to a database from a stock windows install, and crying INFECTION if it sees something thats changed. thats hardly going to work on a system if you change settings yourself.


thanks Mussels but if you make a deep scan with different settings i'm sure will find more

Why yes it did. it found a file i renamed to keygen.exe for laughs, and claimed it was infected too.



Kaspersky disagrees.


I ran the test again, making a copy of the file with a different name - what do you know, it wasnt detected. Bravo malwarebytes... you can tell its a virus by looking at the name.

I've uploaded the file (with both names) to http://www.filterbit.com i'm waiting on its results. i bet you $5 its clean.
Filterbit currently uses Metascan® antivirus engines from CA (Computer Associates), Norman Data Defense Systems, ClamAV, ESET, Microworld and VirusBuster.

edit: well the test just keeps looping on that site, but i'm willing to upload it to any others you suggest.

I'm sorry guys, at this point theres nothing you can do to convince me of anything, other than the fact this program is a piece of crap.
 
Last edited:

InnocentCriminal

Resident Grammar Amender
Joined
Feb 21, 2005
Messages
6,477 (0.92/day)
System Name BeeR 6
Processor Intel Core i7 3770K*
Motherboard ASUS Maximus V Gene (1155/Z77)
Cooling Corsair H100i
Memory 16GB Samsung Green 1600MHz DDR3**
Video Card(s) 4GB MSI Gaming X RX480
Storage 256GB Samsung 840 Pro SSD
Display(s) 27" Samsung C27F591FDU
Case Fractal Design Arc Mini
Power Supply Corsair HX750W
Software 64bit Microsoft Windows 10 Pro
Benchmark Scores *@ 4.6GHz **@ 2133MHz
^^

Fair enough, nice work Mussels.
 

Iarwain

New Member
Joined
Jun 30, 2009
Messages
28 (0.01/day)
Processor AMD 720x3 BE at 3.7Ghz
Motherboard DFI Lanparty DK M2RS
Cooling Scythe Mugen 2
Memory 4GB A-Data DDR2
Video Card(s) Sapphire HD 4890 at 990/1000 with Scythe Mushashi
Storage 150GB Raptor
Display(s) Samsung
Case Raidmax Katana
Audio Device(s) XtremeGamer
Power Supply Corsair 650w
Software Windows 7
Malwarebytes plus the vundo removal tool got that crap off my system. I'm sold on it.
 
Joined
Apr 4, 2009
Messages
541 (0.10/day)
Processor i3-4160
Motherboard msi z97 pcmate
Cooling generic
Memory 8gb ballistix
Video Card(s) evga 750 ti ftw
Storage samsung ssd 120gb + 1tb samsung
Case 210 elite
Power Supply evga 500w
Software Win 7 ultimate 64bit
hey i got another problem. anytime i use internet for like 5min or so, i got a bsod.
The error code is something IRQL_....... i'm not sure about the rest of the code cuz it flashs too fast. Is there an option in bios to set it not to reboot immediately after bsod ?

Anyway, anyone have clue on that IRQL_....
 
Joined
Jan 11, 2005
Messages
1,491 (0.21/day)
Location
66 feet from the ground
System Name 2nd AMD puppy
Processor FX-8350 vishera
Motherboard Gigabyte GA-970A-UD3
Cooling Cooler Master Hyper TX2
Memory 16 Gb DDR3:8GB Kingston HyperX Beast + 8Gb G.Skill Sniper(by courtesy of tabascosauz &TPU)
Video Card(s) Sapphire RX 580 Nitro+;1450/2000 Mhz
Storage SSD :840 pro 128 Gb;Iridium pro 240Gb ; HDD 2xWD-1Tb
Display(s) Benq XL2730Z 144 Hz freesync
Case NZXT 820 PHANTOM
Audio Device(s) Audigy SE with Logitech Z-5500
Power Supply Riotoro Enigma G2 850W
Mouse Razer copperhead / Gamdias zeus (by courtesy of sneekypeet & TPU)
Keyboard MS Sidewinder x4
Software win10 64bit ltsc
Benchmark Scores irrelevant for me
you can't fix all the vundo damage...
 

{JNT}Raptor

New Member
Joined
Jul 12, 2005
Messages
732 (0.11/day)
Location
NY
System Name Ummmm...Mine
Processor I7 920 @ 4.2ghz @ 1.29v's load
Motherboard ASUS P6T Deluxe V2
Cooling Custom 1/2 inch H20
Memory 3x2gb Patriot Sector 7 @2008Mhz 27-9-11-9 1T
Video Card(s) EVGA GTX 580 SC 900/1800/1090
Storage 1-Mushkin 60gb SSD 1-500GB WD Black and 2-1TB 32mb WD Black
Display(s) 25 inch Hanns-G 2ms
Case Custom
Audio Device(s) Turtle Beach Catalina
Power Supply Corsair AX850 Pro Series-Modular
Software All Kinds...and then some.
Benchmark Scores 3dMark 11 P7066 Compare Link- http://3dmark.com/3dm11/251153
SUPERAntiSpyware cleaned VUNDO off of a rig I was working on....no issues with that rig since(6 months).....liked it so much......I bought it. :D

Hope it helps. :)
 
Joined
Jan 12, 2009
Messages
1,241 (0.22/day)
Location
Connecticut
System Name Corsair 900D
Processor FX8350
Motherboard Asus Crosshair V
Cooling Corsair H110I
Memory 16GB Corsair Vengeance
Video Card(s) Asus GTX1080
Storage 2x 500GB 1x 1TB WD Green
Display(s) Acer 24" 1080p / HP 27" 1080p LED
Case Corsair 900D
Audio Device(s) Sound Blaster X-Fi (Built in/Mobo) - Xonar Sound Card
Power Supply Enermax 1020Watt
Mouse Logitech Something Whatever
Keyboard Logtich G910
Software Windows 10
Vundo is a pain to remove but you can repair most of the damage that it has caused via the Recovery Console and SFC after the virus has been removed.

I've always had good luck with Combofix, the Vundo Removal Tool, (Malwarebytes is and up and down for me...sometimes it doesn't detect shit other times it gives a lot of False Positives), Avira work's well for a free AV.

SuperANTIspyware is a good final cleaning tool.

www.bleepingcomputer.com also has a ton of walkthrough's on how to kill pesky annoying virus's.
 
Joined
Feb 19, 2006
Messages
6,270 (0.94/day)
Location
New York
Processor INTEL CORE I9-9900K @ 5Ghz all core 4.7Ghz Cache @1.305 volts
Motherboard ASUS PRIME Z390-P ATX
Cooling CORSAIR HYDRO H150I PRO RGB 360MM 6x120mm fans push pull
Memory CRUCIAL BALLISTIX 3000Mhz 4x8 32gb @ 4000Mhz
Video Card(s) EVGA GEFORECE RTX 2080 SUPER XC HYBRID GAMING
Storage ADATA XPG SX8200 Pro 1TB 3D NAND NVMe,Intel 660p 1TB m.2 ,1TB WD Blue 3D NAND,500GB WD Blue 3D NAND,
Display(s) 50" Sharp Roku TV 8ms responce time and Philips 75Hz 328E9QJAB 32" curved
Case BLACK LIAN LI O11 DYNAMIC XL FULL-TOWER GAMING CASE,
Power Supply 1600 Watt
Software Windows 10
Download malewarebytes http://filehippo.com/download_malwarebytes_anti_malware/download/0183b13df8587a49060b35c937c73372/
install it get the updates reboot into safe mode and run full scan and remove findings reboot into safe mode again and do the same till there are no findings..If your PC will not allow malwarebytes to install you will need to remove the harddrive and scan it with a different PC then install drive back in your rig and install malwarebytes and do the first set of instructions above.GL
 
Joined
Feb 19, 2006
Messages
6,270 (0.94/day)
Location
New York
Processor INTEL CORE I9-9900K @ 5Ghz all core 4.7Ghz Cache @1.305 volts
Motherboard ASUS PRIME Z390-P ATX
Cooling CORSAIR HYDRO H150I PRO RGB 360MM 6x120mm fans push pull
Memory CRUCIAL BALLISTIX 3000Mhz 4x8 32gb @ 4000Mhz
Video Card(s) EVGA GEFORECE RTX 2080 SUPER XC HYBRID GAMING
Storage ADATA XPG SX8200 Pro 1TB 3D NAND NVMe,Intel 660p 1TB m.2 ,1TB WD Blue 3D NAND,500GB WD Blue 3D NAND,
Display(s) 50" Sharp Roku TV 8ms responce time and Philips 75Hz 328E9QJAB 32" curved
Case BLACK LIAN LI O11 DYNAMIC XL FULL-TOWER GAMING CASE,
Power Supply 1600 Watt
Software Windows 10
well it tells me it has found "infected" files, when its talking about the registry. to me, Infected means something has attached itself to an existing file, adding malicious code and such.

http://img.techpowerup.org/090710/Capture009439.jpg


After i click show results, it tells me about this "bad" file.

http://img.techpowerup.org/090710/Capture010705.jpg

well actually, no it doesnt tell me squat.


http://img.techpowerup.org/090710/Capture011496.jpg

My infected, bad file is... what? from what that says, a registry key is infected and wants to hijack my display properties.

I want my scans to report all keygens too some people don't but they use to be an issue with keygens being infected ,not so much now days though...also I believe the display reading is because of some setting that that is keeping your display options from a hijack and that is the same as a highjack...yes a true false positive for sure but if it wasn't a policy you wanted on your PC I would think you would like to be notified that it was there and then you are able to decide if it real or not.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
I want my scans to report all keygens too some people don't but they use to be an issue with keygens being infected ,not so much now days though...also I believe the display reading is because of some setting that that is keeping your display options from a hijack and that is the same as a highjack...yes a true false positive for sure but if it wasn't a policy you wanted on your PC I would think you would like to be notified that it was there and then you are able to decide if it real or not.

both reports are false positives. why would i want to be notified about something thats a default setting in windows, and told its an INFECTION. Same again with the keygen.exe... no matter what you say, this program is assuming its a virus by name alone - renaming it makes it no longer an "infection" so does that mean viruses can slip by this program by changing their names too?
 
Top