Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Vundo - Need Help!


  • This topic is locked This topic is locked
3 replies to this topic

#1 bennettpaul4

bennettpaul4

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:53 AM

Posted 04 August 2008 - 04:04 AM

Hello, i believe that my computer is infected with Vundo. I attach the DSS logs. For some reason after i installed Hijack this DSS would only give me the main.txt log with no extra.txt. I attach the extra.txt from befor i installed hijack this.
Your help would be very much appreciated.

main.txt

Deckard's System Scanner v20071014.68
Run by pb on 2008-08-04 09:54:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Percentage of Memory in Use: 78% (more than 75%).
Total Physical Memory: 447 MiB (512 MiB recommended).


-- HijackThis (run as pb.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:54:29, on 04/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\pb.THOMASCOOMBS\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\pb.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://companyweb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://sbserver:8080/array.dll?Get.Routing.Script
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sbserver:8080
O2 - BHO: (no name) - {46A0CDD0-59DB-4485-B0EF-AC3F031E4769} - C:\WINDOWS\system32\qcchgvpv.dll (file missing)
O2 - BHO: (no name) - {57DF313A-D072-4170-A02D-20A2A1040A0A} - C:\WINDOWS\system32\jkkJayVP.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: {2bdefe8a-2f6c-9628-4534-3c8b9683e90c} - {c09e3869-b8c3-4354-8269-c6f2a8efedb2} - C:\WINDOWS\system32\ncgnfo.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BM23d2939e] Rundll32.exe "C:\WINDOWS\system32\jaqtmbyc.dll",s
O4 - HKLM\..\Run: [20e1a002] rundll32.exe "C:\WINDOWS\system32\jgqkcaqx.dll",b
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Firewall Client Management.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Star Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O15 - Trusted Zone: http://server1.rezlynx.net
O15 - Trusted Zone: http://server2.rezlynx.net
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1149149398194
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ThomasCoombs.local
O17 - HKLM\Software\..\Telephony: DomainName = ThomasCoombs.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ThomasCoombs.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ThomasCoombs.local
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL ncgnfo.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IRIS Email Monitor Service (IrisEmailMonitorService) - IRIS Group Ltd - C:\TT\IrisEmailMonitorService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

--
End of file - 8024 bytes

-- Files created between 2008-07-04 and 2008-08-04 -----------------------------

2008-08-04 09:54:19 0 d-------- C:\Program Files\Trend Micro
2008-08-04 09:21:27 100864 --a------ C:\WINDOWS\system32\ncgnfo.dll
2008-08-04 09:21:26 100864 --a------ C:\WINDOWS\system32\nsesjxjo.dll
2008-08-04 09:21:24 80896 --a------ C:\WINDOWS\system32\jgqkcaqx.dll
2008-08-04 09:18:27 90624 --a------ C:\WINDOWS\system32\jaqtmbyc.dll
2008-08-04 09:04:27 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-08-04 08:37:00 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-08-03 20:17:28 0 d-------- C:\VundoFix Backups
2008-08-03 19:34:31 0 d-------- C:\WINDOWS\pss
2008-08-03 17:56:59 0 d-------- C:\Program Files\Lavasoft(2)
2008-08-03 17:40:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-03 14:54:14 8126464 --a------ C:\Documents and Settings\pb.THOMASCOOMBS\ntuser.dat
2008-08-03 14:53:27 648622 --ahs---- C:\WINDOWS\system32\PVyaJkkj.ini2
2008-08-03 14:53:21 246272 --a------ C:\WINDOWS\system32\jkkJayVP.dll
2008-08-03 14:48:07 32768 --a------ C:\Program Files\bcd_installed.exe
2008-08-01 12:21:07 0 d-------- C:\Documents and Settings\Default User\Application Data\Macromedia
2008-07-24 14:44:08 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\InterVideo
2008-07-24 09:31:43 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\HP
2008-07-24 09:31:16 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-07-24 09:29:13 0 d-------- C:\Program Files\Common Files\HP
2008-07-24 09:27:01 0 d-------- C:\Program Files\Hewlett-Packard
2008-07-24 09:23:30 0 d-------- C:\Program Files\HP
2008-07-24 09:22:45 14916 -----n--- C:\WINDOWS\hphmdl12.dat
2008-07-24 09:22:45 123992 --a------ C:\WINDOWS\HPHins12.dat
2008-07-10 15:05:19 139264 --a------ C:\WINDOWS\system32\SGISAQry.dll <Not Verified; The Sage Group plc; Sage ISAPI Query Engine>
2008-07-10 15:05:18 167936 --a------ C:\WINDOWS\system32\SGXMLQry.dll <Not Verified; The Sage Group plc; Sage Query Engine Component>
2008-07-10 15:05:18 81920 --a------ C:\WINDOWS\system32\SGUserInfo.dll <Not Verified; The Sage Group plc; Sage User Registration Component>
2008-07-10 15:05:18 126976 --a------ C:\WINDOWS\system32\SGInfProgressBar.dll <Not Verified; The Sage Group plc; Sage MIS Progress Bar>
2008-07-10 15:05:18 335872 --a------ C:\WINDOWS\system32\SGINFMR.dll <Not Verified; The Sage Group plc; Sage Informer Manager>
2008-07-10 15:05:11 0 d-------- C:\Program Files\Informer50
2008-07-10 15:03:15 368696 --a------ C:\WINDOWS\system32\S10DBC32.dll <Not Verified; Sage (UK) Limited; Microsoft Open Database Connectivity>
2008-07-10 15:00:37 0 d-------- C:\Program Files\Sagev10


-- Find3M Report ---------------------------------------------------------------

2008-08-04 08:54:54 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\DNA
2008-08-03 18:43:16 0 d-------- C:\Program Files\SopCast
2008-08-03 18:37:47 0 d-------- C:\Program Files\Common Files
2008-08-03 18:37:17 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\uTorrent
2008-08-03 17:42:18 0 d-------- C:\Program Files\Lavasoft
2008-08-03 17:39:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-01 12:21:55 0 d-------- C:\Program Files\Google
2008-07-10 15:06:28 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-07 19:40:45 0 d-------- C:\Program Files\Microsoft Silverlight
2008-06-25 19:51:18 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\Move Networks
2008-06-22 18:49:16 0 d-------- C:\Program Files\Peggle
2008-06-22 18:47:37 0 d-------- C:\Program Files\BFG
2008-06-21 23:41:17 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-21 23:41:11 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\Mozilla
2008-06-19 22:06:11 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\Real
2008-06-19 22:04:30 0 d-------- C:\Program Files\Common Files\xing shared
2008-06-19 22:04:22 0 d-------- C:\Program Files\Common Files\Real
2008-06-19 22:03:54 0 d-------- C:\Program Files\Real
2008-06-05 13:31:03 0 d-------- C:\Documents and Settings\pb.THOMASCOOMBS\Application Data\Adobe


-- Registry Dump ---------------------------------------------------------------



-- End of Deckard's System Scanner: finished at 2008-08-04 09:54:41 ------------

extra.txt

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® M processor 1.50GHz
Percentage of Memory in Use: 76%
Physical Memory (total/avail): 446.17 MiB / 103.68 MiB
Pagefile Memory (total/avail): 672.25 MiB / 427.02 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1910.46 MiB

C: is Fixed (NTFS) - 37.25 GiB total, 11.65 GiB free.
D: is CDROM (CDFS)
F: is Network (NTFS)
Z: is Network (NTFS)

\\.\PHYSICALDRIVE0 - TOSHIBA MK4026GAX - 37.26 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.25 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.
AntivirusOverride is set.

FW: Norton Internet Security v2005 (Symantec Corporation)
AV: Sophos Anti-Virus v ()
AV: Norton Internet Security v2005 (Symantec Corporation) Outdated

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CCH\\InfoLib\\LPLocal.exe"="C:\\Program Files\\CCH\\InfoLib\\LPLocal.exe:*:Enabled:LivePublish Personal Edition HTTP Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"="C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe:*:Enabled:ConfigFree SUMMIT Engine"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Microsoft Outlook\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Outlook\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CCH\\InfoLib\\LPLocal.exe"="C:\\Program Files\\CCH\\InfoLib\\LPLocal.exe:*:Enabled:LivePublish Personal Edition HTTP Server"
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"="C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe:*:Enabled:ConfigFree SUMMIT Engine"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\\Documents and Settings\\pb.THOMASCOOMBS\\Application Data\\SopCast\\adv\\SopAdver.exe"="C:\\Documents and Settings\\pb.THOMASCOOMBS\\Application Data\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\Microsoft Outlook\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Outlook\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Enabled:Football Manager 2008"
"c:\\program files\\bcd_installed.exe"="c:\\program files\\bcd_installed.exe:*:Enabled:Windows Application Service"


-- Environment Variables -------------------------------------------------------



-- User Profiles ---------------------------------------------------------------

da.THOMASCOOMBS (admin)
philipexley
SVK
PB (admin)
administrator.THOMASCOOMBS (admin)
DA (new local, admin)
Administrator (admin)
al
pb.THOMASCOOMBS (admin)


-- Add/Remove Programs ---------------------------------------------------------



-- Application Event Log -------------------------------------------------------

Event Record #/Type875 / Warning
Event Submitted/Written: 08/04/2008 09:18:25 AM
Event ID/Source: 32 / Sophos Anti-Virus
Event Description:
File "C:\Documents and Settings\pb.THOMASCOOMBS\Local Settings\Temporary Internet Files\Content.IE5\1WH26T4S\kb111653[1]" belongs to virus/spyware 'Troj/Virtum-Gen'.

Event Record #/Type874 / Warning
Event Submitted/Written: 08/04/2008 09:18:25 AM
Event ID/Source: 1 / Sophos Anti-Virus
Event Description:
Infected file "C:\Documents and Settings\pb.THOMASCOOMBS\Local Settings\Temporary Internet Files\Content.IE5\1WH26T4S\kb111653[1]" has been deleted.

Event Record #/Type873 / Warning
Event Submitted/Written: 08/04/2008 09:18:25 AM
Event ID/Source: 32 / Sophos Anti-Virus
Event Description:
File "C:\Documents and Settings\pb.THOMASCOOMBS\Local Settings\Temporary Internet Files\Content.IE5\1WH26T4S\kb111653[1]" belongs to virus/spyware 'Troj/Virtum-Gen'.

Event Record #/Type867 / Error
Event Submitted/Written: 08/04/2008 08:16:42 AM / 08/04/2008 08:16:45 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type864 / Error
Event Submitted/Written: 08/04/2008 08:15:57 AM
Event ID/Source: 8006 / Sophos Message Router
Event Description:
The network identity (also known as the Interoperable Object Reference or IOR) of the local computer is invalid.%%3



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type28739 / Error
Event Submitted/Written: 08/04/2008 09:31:41 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Application Layer Gateway Service service failed to start due to the following error:
%%1053

Event Record #/Type28738 / Error
Event Submitted/Written: 08/04/2008 09:31:40 AM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.

Event Record #/Type28731 / Warning
Event Submitted/Written: 08/04/2008 09:30:54 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00C09FED1AB6. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type28722 / Warning
Event Submitted/Written: 08/04/2008 09:08:31 AM
Event ID/Source: 20 / Print
Event Description:
Printer Driver HP LaserJet 4250 PCL 6 for Windows NT x86 Version-3 was added or updated. Files:- UNIDRV.DLL, UNIDRVUI.DLL, HPC42506.GPD, UNIDRV.HLP, hpzui3zw.DLL, hpz6r3zw.DLL, hpcdmc32.DLL, hpbcfgre.DLL, HPNRA.DLL, HPBNRAC2.DLL, HPBMINI.DLL, HPCEAC05.HPI, HPBMIAPI.DLL, HPBOID.DLL, HPBOIDPS.DLL, HPBPRO.DLL, HPBPROPS.DLL, HPPAPTS0.DLL, HPPASNM0.DLL, HPPAPML0.DLL, HPZIPM12.EXE, HPZIPT12.DLL, HPZINW12.EXE, HPZIPR12.DLL, HPZISN12.DLL, HPJCMN2U.DLL, HPJIPX1U.DLL, HPZIDR12.DLL, hpz6m3zw.GPD, hpzsm3zw.GPD, hpc4250c.ini, hpc42506.xml, hpzst3zw.DLL, hpc4x506.gpd, hpzsc3zw.dtd, hpzev3zw.DLL, pclxl.DLL, pjl.GPD, pclxl.GPD, HPZHL3zw.CAB, STDNAMES.GPD, hpzls3zw.DLL, hpzss3zw.DLL, hplj4x50.CFG, UNIRES.DLL.

Event Record #/Type28703 / Warning
Event Submitted/Written: 08/04/2008 09:01:26 AM
Event ID/Source: 20 / Print
Event Description:
Printer Driver EPSON LQ-590 ESC/P2 for Windows NT x86 Version-3 was added or updated. Files:- UNIDRV.DLL, UNIDRVUI.DLL, ESCP5RN.GPD, UNIDRV.HLP, UNIRES.DLL, STDNAMES.GPD, ESCP5W2S.DLL, EPUPDATE.EXE, SETUP32.DLL.



-- End of Deckard's System Scanner: finished at 2008-08-04 09:36:29 ------------

The symptoms include: a userinit.exe error on startup, sometimes requiring explorer.exe to be manually started. No access to add/remove programs, automatic updates being disabled, some popups while browsing the internet and google and some other websites not working at all.

Thank You in advance for your help.

Edited by bennettpaul4, 04 August 2008 - 04:10 AM.


BC AdBot (Login to Remove)

 


m

#2 bennettpaul4

bennettpaul4
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:53 AM

Posted 05 August 2008 - 02:33 AM

Hi there,
After many hours of trying i believe that i have now removed vundo fully from my system. Everything seems to be back to normal. I know you are all very busy so you can close this topic.

Thank You

#3 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:53 AM

Posted 11 August 2008 - 05:36 AM

Hi,

The forums are really busy, that explains why logs get behind. If you still need some help, please start with posting a new hijackthislog in this thread. Don't start with a new thread.
Then I'll take a look. :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:53 AM

Posted 20 August 2008 - 01:56 PM

Since there is no feedback anymore, I assume this issue is resolved ... so, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users