I shut the computer off manually and when I started up again, some icons were missing from the bottom right of the task bar. I opened Norton Corporate and my computer claimed to be "installing" and "searching" for Norton, however the Norton program opened up just fine in the background. A completed scan revealed "Trojan Vundo", which I attempted to learn more about by clicking on, however the virus has disabled some websites, Symantec included (I learned that the task manager and website problem is common with this virus when I went to wikipedia). I used another computer and printed out instructions on removal at the Symantec website. I went through all the steps, including manual, and it didn't work. I then looked for other tools online and came across this site. I went through all the steps utilizing the rkill, MBAM, vundofix, & VirtumundoBegone programs. Afterwards, I stopped getting messages that random .dll programs could not be found at start up (ex. "giweweno"), however I cannot navigate to some websites (Google searches are useless) and I have no access to MBAM, Superantispyware, and I continue to receive messages that Norton Corporate is missing some pieces (even though it opens in the background). I was able to manually fix the task manager problem, but that's it. I then tried Combofix. As you will see, I had to rename it (aaah111.exe) to get it on my computer, because I couldn't get through the installation process until I changed the name. I ran that and have a log saved if you need it. I have followed the tutorial for posting and I am including the other logs here as instructed:
DDS (Ver_09-10-26.01) - NTFSx86
Run by Joe at 13:06:10.39 on Fri 11/20/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.1956 [GMT -5:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Joe\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Kxuyuqim] "c:\documents and settings\joe\application data\?dobe\n?tepad.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\corece~1.lnk - c:\program files\msi\core center\CoreCenter.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: principal.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.clarkcolor.com/ClarkActivia.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38184.9602662037
DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E7C44C86-0CD3-11D2-9311-00A0247A4E65} - hxxp://65.246.89.22/JWALKC10/JWalkXS/ais40.cab
TCP: {A119825C-0782-4C8E-A037-BAADCDC4292D} = 77.74.48.113
TCP: {CF51FC7F-C0A7-4DEA-98AE-425C977D5921} = 77.74.48.113
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [2006-5-9 16384]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-22 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-22 55024]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2006-5-9 105472]
R3 EraserUtilDrvI9;EraserUtilDrvI9;c:\program files\common files\symantec shared\eengine\EraserUtilDrvI9.sys [2009-11-19 102448]
R3 MBX2DFU;MBX2DFU;c:\windows\system32\drivers\mbx2dfu.sys [2006-5-9 15488]
R3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [2006-5-9 15232]
S3 EraserUtilDrv10920;EraserUtilDrv10920;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10920.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10920.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-22 7408]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]
=============== Created Last 30 ================
2009-11-19 20:06:53 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-11-19 20:06:53 50176 ----a-w- c:\windows\system32\proquota.exe
2009-11-19 19:55:02 0 d-sha-r- C:\cmdcons
2009-11-19 19:53:36 77312 ----a-w- c:\windows\MBR.exe
2009-11-19 19:53:35 98816 ----a-w- c:\windows\sed.exe
2009-11-19 19:53:35 260608 ----a-w- c:\windows\PEV.exe
2009-11-19 19:53:35 161792 ----a-w- c:\windows\SWREG.exe
2009-11-19 19:53:23 0 d-----w- C:\aaah111
2009-11-19 19:38:41 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-19 18:54:39 0 d-----w- C:\VundoFix Backups
2009-11-19 01:40:57 0 d-----w- c:\docume~1\joe\applic~1\Malwarebytes
2009-11-19 01:40:50 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-11-19 00:22:58 1162 --sha-r- c:\documents and settings\joe\ntuser.pol
2009-11-19 00:20:55 0 d--h--w- c:\windows\system32\GroupPolicy
2009-11-17 04:55:33 41632 ----a-w- C:\vuou.exe
2009-11-17 04:55:31 32256 ----a-w- C:\aruxss.exe
2009-11-17 04:55:30 6656 ----a-w- C:\excbx.exe
2009-11-17 04:55:30 37888 ----a-w- C:\kewwr.exe
2009-11-17 04:55:29 67388 ----a-w- c:\windows\system32\winupdate86.exe.delme1932
==================== Find3M ====================
2009-10-09 19:36:12 4056 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-08 17:38:43 18983 ----a-w- c:\docume~1\joe\applic~1\ucica.bin
2009-10-08 17:38:43 18045 ----a-w- c:\program files\common files\xipafo.pif
2009-10-08 17:38:43 17832 ----a-w- c:\program files\common files\nalekuf.pif
2009-10-08 17:38:43 13890 ----a-w- c:\docume~1\alluse~1\applic~1\bobopovix.com
2009-10-08 17:38:43 11745 ----a-w- c:\program files\common files\gude.lib
2009-10-08 17:38:43 11034 ----a-w- c:\docume~1\alluse~1\applic~1\ituvuzeso.sys
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 04:56:09 1208891 --sha-w- c:\windows\system32\kudebeze.exe
============= FINISH: 13:06:26.90 ===============
Attached File(s)
-
Attach.txt (11.3K)
Number of downloads: 17 -
ark.txt (3.54K)
Number of downloads: 10

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top













