Page 1 of 2 1 2 LastLast
Results 1 to 15 of 16

Thread: Infestation by wudepuve.

  1. #1
    Senior Member docusk's Avatar
    Join Date
    May 2003
    Location
    Reading England
    Posts
    880

    Infestation by wudepuve.

    I found this last night. Must have come from a DVD from a friend who lent me Front Page to try. Not an official M$ CD but I don't really want to buy any more s./ware just now. (some of you will know why).
    Idiot that I am!
    Up comes this pop up telling me that everything I go to use is a 'Bad Image', Close it and another pop down arrives, sometimes as many as 8 times but eventually the application starts and runs perfectly.
    I have looked in the registry and there are about 5 entries labelled as "notification packages"
    I'm comfortable with editing the registry but is this all I need to do to get rid of this whatever-it-is-beastie? I can't help thinking there's more to it.
    Vipre and Sunbelt Personal Firewall are running all the time. I've since done a deep scan to no avail. Anyone have experience of the virus/malware?
    docusk

  2. #2
    Stark Raving MOD Midknyte's Avatar
    Join Date
    May 2002
    Location
    Arkham Asylum
    Posts
    22,270
    If it's not an official MS disc, we can't help you with the application. Forum rules.

    wudepuve is a variant of the Vundo trojan. Vipre should have caught it. What do the logs say?

    You can try running the Avira Boot CD. Check AV/Antispy for the download link.

  3. #3
    Senior Member docusk's Avatar
    Join Date
    May 2003
    Location
    Reading England
    Posts
    880
    OK MK, got that.
    I still have the Avira AV boot disk from the last time we corresponded. Also F secure and Virtumonde plus both versions of UBCD - win and plain.
    The Avira is from early in Jan so should I get a fresh copy? It's on a CD-RW disk which I can erase presumably?

    I don't normally use things other people have, probably P 2 P sites but this time, I let my guard down. There's no fool like an old fool!
    You didn't say if it would do any harm to remove the lines from the registry?

    docusk

  4. #4
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    I would run a full scan with Avira and Malwarebytes before you start messing with the registry. Do you have any registry cleaner/defraggers available such as JV16 or Registry Booster? I like them both (depending on the OS version running).

  5. #5
    Stark Raving MOD Midknyte's Avatar
    Join Date
    May 2002
    Location
    Arkham Asylum
    Posts
    22,270
    Avira should be able to update if you have an internet connection. No harm in downloading a newer copy, since they just released version 9. Not sure if the boot disc was updated, though.

    You can erase the CD-RW, but CD-R media is so cheap I don't even bother.

  6. #6
    Extreme Member! BipolarBill's Avatar
    Join Date
    Oct 2000
    Location
    Norton Noo Joisey
    Posts
    41,528
    The Avira Rescue CD is updated multiple times each day. It's always new.

    Malwarebytes should kill that easily.

    www.malwarebytes.org
    MS MCP, MCSE

  7. #7
    Senior Member docusk's Avatar
    Join Date
    May 2003
    Location
    Reading England
    Posts
    880
    OK chaps, all gone now!!!
    Just for interest, I tried MBAM with no results, Found Norman_malware_cleaner.exe via Major geeks and ran that overnight, it took almost 9 hours to complete. I followed that with a restart with Avira boot disk and that took about another 5 hours but I went out whilst it was running and at restart all seemed well. One thing, I can't start the Windows Security Centre and the nag screen comes up whenever I reboot.
    That would be a bonus if you could solve that one for me. It's probably connected.
    So. Once more - for the umpteenth time - very many thanks to all of you for helping me and more.... being so patient.
    My watchword to all under 70, "Don't get old."
    docusk

  8. #8
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    You may want to try a free scan using Trend Micro Housecall.

    http://housecall.trendmicro.com/

  9. #9
    Stark Raving MOD Midknyte's Avatar
    Join Date
    May 2002
    Location
    Arkham Asylum
    Posts
    22,270
    What does the event viewer say about security center? Did you try manually starting the service from services.msc?

  10. #10
    Extreme Member! BipolarBill's Avatar
    Join Date
    Oct 2000
    Location
    Norton Noo Joisey
    Posts
    41,528
    Yes - in Control Panel > Administrative Tools > Services, you should be able to set Security Center to "Automatic" and start it manually.
    MS MCP, MCSE

  11. #11
    Senior Member docusk's Avatar
    Join Date
    May 2003
    Location
    Reading England
    Posts
    880
    OK Thanks. I've just done that and it seems as if it's running OK. All elements of the scurity seem OK, Firewall, Defender, Updates all shown as ON.
    I'll shut down now and see what happens tomorrow but so far everything seems normal. I'm gradually learning Vista but it's a slow process. Perhaps it's just me?
    docusk

  12. #12
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    Quote Originally Posted by docusk View Post
    I'm gradually learning Vista but it's a slow process. Perhaps it's just me?
    docusk
    No it is not just you. I dropped Vista from my system and went back to XP.

  13. #13
    Senior Member docusk's Avatar
    Join Date
    May 2003
    Location
    Reading England
    Posts
    880
    Is it really that bad? I have a second PC next door to this one running XP pro as I can't use my nice Colour Laserjet or my Scanner in Vista. That seems to be common knowledge (to everyone but me!)
    If I decide to follow your lead, can I just overload with XP or must I remove everything in Vista?
    I have so many applications for my special interests they have already taken me an age to get set up up on this PC.
    I do have a spare 250 Gb SATA H/disk I can put in here and maybe that will make it easier to transfer stuff. I understand there is a special routine from M$ to do that. No?
    docusk

  14. #14
    Lifetime Friend of Staff
    Join Date
    May 2007
    Location
    Sheboygan, WI
    Posts
    3,921
    You will need to wipe Vista completely before installing XP

  15. #15
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    You lose EVERYTHING!!!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •