Since this morning pop ups were appearing constantly when my younger sister was browsing basic kids sites (using internet explorer 7), and then when i went on my account i found windows explorer kept randomly closing when generally just on msn and browsing the net (firefox 3).
I run a virus scan using the latest norton anti virus with updates (in safe mode) and it came back with 2 items for attention both of which were the trojan.vundo which it says was high risk it tried to repair but says it was only partially repaired.
Restarted pc, went to the symantec website to find out more about the virus but it had it down as low risk and said it only affected up to XP :/
I tried their removal tool anyway (worth a shot right) and it didnt find anything but the effects were still happening.
I tried atribunes VundoFix and it came back with 4 files
C:/Windows/System32/NCTAVfile.dll
C:/Windows/System32/NCTQuicktimefile.dll
C:/Windows/System32/NCTRMfile.dll
C:/Windows/System32/NCTVideocodeM.dll
I clicked remove but it said it couldnt and restarted.
Once restarted i went to the System32
I run spybot search and destroy and that came back with nothing.
I tried to do a system restore back to last wednesday but it errored.
I run a virus scan again and it comes back clean, i run the atribute vundofix again and it comes back with the same 4 files, i click remove again but it just errored and said the pc would automatically restart which it did.
Not sure what else to try!
I've seen in previous support topics people ask for hijack this logs to help work out problems so just incase i've included it below
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {500DBD6E-6D95-4106-B9A2-DDDCCB2B30D1} - C:\Windows\system32\fcccYrqp.dll
O23 - Service: Google Update Service (gupdate1c8d18dd3de1914) (gupdate1c8d18dd3de1914) - Google Inc. - C:\Program Files\Google\Update\1.1.25.0\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Just now I downloaded MCT and created an ISO
C:\Windows\System32>dism /Get-WimInfo /WimFile:D:\sources\install.esd /index:6
Deployment Image Servicing and Management tool
Version: 10.0.26100.8521
Details for image : D:\sources\install.esd
Index : 6
Name : Windows 11 Pro
Description : Windows 11 Pro
Size : 25,471,900,045 bytes
WIM Bootable : No
Architecture : x64
Hal :
Version : 10.0.26200
ServicePack Build : 8653
ServicePack Level : 0
Edition : Professional
Installation : Client
ProductType : WinNT
ProductSuite : Terminal Server
System Root : WINDOWS
Directories : 33220
Files : 147525
Created : 2026-06-05 - 11:28:55 PM
Modified : 2026-06-12 - 5:56:11 PM
Languages :
en-US (Default)
The operation completed successfully.
It's my daily driver actually. One of the reasons I switched from Chrome was the constant updates offering nothing useful and constantly needing to search for ways to revert things.
Seems that Firefox has a more relaxed schedule of once per month, along with keeping uBlock Origin so time to switch back to the OG
The irony is Microsoft doesn’t care what any of you say of what should be happening minus higher clock speed because you can’t turn off this profile. It was shoved down your throat. Now it’s up to you to “shut up” and move on or uninstall Windows and install Linux.
Clock seems to have an Alarm regression: the only thing that happens now is a notification on the tray. That's not what it was at all (an actual UI popped up, and an alarm sound, too).
Question
Karl
Hey,
First off im running windows vista!
Since this morning pop ups were appearing constantly when my younger sister was browsing basic kids sites (using internet explorer 7), and then when i went on my account i found windows explorer kept randomly closing when generally just on msn and browsing the net (firefox 3).
I run a virus scan using the latest norton anti virus with updates (in safe mode) and it came back with 2 items for attention both of which were the trojan.vundo which it says was high risk it tried to repair but says it was only partially repaired.
Restarted pc, went to the symantec website to find out more about the virus but it had it down as low risk and said it only affected up to XP :/
I tried their removal tool anyway (worth a shot right) and it didnt find anything but the effects were still happening.
I tried atribunes VundoFix and it came back with 4 files
C:/Windows/System32/NCTAVfile.dll
C:/Windows/System32/NCTQuicktimefile.dll
C:/Windows/System32/NCTRMfile.dll
C:/Windows/System32/NCTVideocodeM.dll
I clicked remove but it said it couldnt and restarted.
Once restarted i went to the System32
I run spybot search and destroy and that came back with nothing.
I tried to do a system restore back to last wednesday but it errored.
I run a virus scan again and it comes back clean, i run the atribute vundofix again and it comes back with the same 4 files, i click remove again but it just errored and said the pc would automatically restart which it did.
Not sure what else to try!
I've seen in previous support topics people ask for hijack this logs to help work out problems so just incase i've included it below
Thanks for any help!
Karl
Link to comment
https://www.neowin.net/forum/topic/646214-trojanvundo-virus-infection/Share on other sites
7 answers to this question
Recommended Posts