Monthly Archives: October 2005

Vundo Spyware Removal

1) Download the fix from here http://www.atribune.org/downloads/VundoFix.exe

2) Double click the file which will create a folder on your desktop.

3) Reboot into Safe Mode.

4) Run the KillVundo.bat file from the folder.

5) It will prompt you for two items. The first time you enter the full path to the offending file, such as c:\windows\system32\srvdisk.dll. This file may be different.

6) The second time you enter in the path, with the filename reverse. In the above example, you would enter in this: c:\windows\system32\ksidvrs.* .

7) Reboot the computer and then run Cleanup from this location. http://www.stevengould.org/downloads/cleanup/CleanUp40.exe

The CleanUp options to select are:

Empty Recycle Bins
Delete Cookies
Delete Prefetch files
Cleanup! All Users

8) Run HijackThis and remove the Vundo related files you entered in 5) and 6) above.

Celebrate the Vundo removal!

It’s *ahem* Vundo-bar!

Removing guard.tmp and kldsw.dll

More spyware junk removal.

This time I needed to use l2mfix which you can find at either of these locations.

http://www.downloads.subratam.org/l2mfix.exe
http://www.atribune.org/downloads/l2mfix.exe

Download the zip file and unzip it to your desktop. This will create an l2mfix folder.

From within the folder run the l2mfix.bat file.

Select option #1 for Run Find Log.

Select option #2 for Run Fix. It will reboot your computer and then run the fix on reboot. On some systems the scanning passes may take a while so be patient.

After it is done it will open up notepad with a trace log.