CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Back on the air!

 
Post new topic   Reply to topic       All -> FavForums -> General Site [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
abbeyhurst

Cadet
Cadet


Joined: Nov 18, 2007
Posts: 1
Location: USA

PostPosted: Wed Nov 21, 2007 7:52 pm    Post subject: Back on the air!
Reply with quote

At the risk of cluttering up this great BBS with 'post repair' info, kudos to the team here at CastleCops for getting me out of a quagmire! Had what turned out to be a Vundo infection which may have been spawned by Huntbar, but in any event it's now repaired. This site was recommended by http://www.windowsbbs.com/ - another excellent site which has been an incredible help over the years. My symptoms were the innumerable and never-ending popups designed to have a 'windows' look and feel, all purporting to have 'found' an infection and suggesting 'click here' for removal software. Additionally, two desktop icons were continually propogated, looking like shields and having the following names/properties targets: Online Security Guide/http://htepo.com/cehpkoin/?mp=h5lid=1_1gai=..... ; and Live Safety Center/http://htepo.com/cehpkoin/?mp=h5lid=2_1gai=..... . Continual attempts to invoke internet connectivity were made by the culprit and a pseudo-IE window appeared while still offline. By following the Malware Removal and Prevention overview here at CastleCops I finally got relief by Vundofix's discovery/removal of the following C:\windows\system32\ files:aacdd.bak1, aacdd.bak2, aacdd.ini, cdjuktmq.dllbox,ddcaa.dll,ljjijhe.dll and ]b]ygnmpvyy.dll.[/b] Thanks to all who administer and contribute to this site... it's very much appreciated! Very Happy

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Nov 21, 2007 8:01 pm    Post subject:
Reply with quote

Thank you for your nice comments, but this is really the wrong forum for them. I have moved this topic to our General Site Forum


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Site All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer