How to remove recurring virus (farakive.dll)
Posted on 2009-04-28
Hello - I'm trying to help a client remove a virus (possibly Trojan Vundo?)... they're currently using the free version of AVG for virus protection, and it's finding an infected file named "farakive.dll". They're letting AVG remove the infected file, but after several minutes, it comes back, so obviously not the root of the problem.
When trying to restart the computer, Windows XP (media center edition) says it can't end the process rundll32.exe and they must end task.
Whatever it is, it's breaking Explorer (very slow, lots of random popups) and Outlook (launches with an error). I've tried disabling all the startup items using msconfig, but after restart, at least a couple are automagically re-enabled: kumabobu and sedutodo
Was hoping to avoid a fresh install of Windows XP, but if that's the best thing to recommend, please let me know. As far as utilities to run, they've already run ccleaner, malwarebyes and AVG. They always seem to find the same files, but they come back again later after removal.
Thanks in advance for any help/advice.