Trojan.Vundo-Variant/Packaged-GEN (10)
Adware.Prun-A (2)
Trojan.Fake-Alert/Warning (3)
Unclassified.Unknown Origin (10)
Adware.Tracking Cookie (3)
Adware.Vundo Variant/Rel (2)
Adware.Vundo Variant (2)
it removed/quarantined them, but whenever the scan finised, a windows error message came up saying:
Generic Host Process for Win32 Services has encountered a problem and needs to close. It also said that the following files will be included in this error report: C:\DOCUME~1\Ownder\LOCALS~1\TempWERaf1e.dir00\svchost.exe.mdmp
C:\DOCUME~1\Ownder\LOCALS~1\TempWERaf1e.dir00\appcompat.txt
i did not send the error report
another error message came up saying DCOM Service Process Launcher sevice terminated unexpectedly
but this second error message does not come up now. after the computer restarted, i ran MBAM, and I have its log here:
Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 3
12/31/2008 2:30:42 PM
mbam-log-2008-12-31 (14-30-42).txt
Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 122252
Time elapsed: 30 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\ukrhspcu.dll (Trojan.Vundo.H) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d004cda3 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\ukrhspcu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ucpshrku.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekarsipfqjo.dll (Trojan.Seneka) -> Delete on reboot.
C:\Documents and Settings\Ownder\Local Settings\temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\seneka.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekadf.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senekalog.dat (Trojan.Agent) -> Quarantined and deleted successfully.
Now norton 360 still doesnt work, and there are still popups, but not that many. the norton antivirus 2009 popup/notifications have gone away, and i can navigate the internet now. however, there is still a problem because whenever i run the scans, the windows error message about Win32 Services comes up. Help as soon as possible would be greatly appreciated.
THANKS!!

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top









