Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan.Vundo Help Please!


  • This topic is locked This topic is locked

#1
shoyoroll

shoyoroll

    New Member

  • Member
  • Pip
  • 4 posts
Hey Guys,

I tried removing the Trojan.Vundo virus in the safe mode and had no luck. I downloaded the removing tool and had no luck at all. Symantec still sees the virus located in C:\\WINDOWS\system32\mlljk.dll . I still can't get this virus removed from my pc. Here is my hijackTHIS log:

Logfile of HijackThis v1.99.1
Scan saved at 10:38:57 AM, on 12/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\SYR\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: MSEvents Object - {79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A} - C:\WINDOWS\system32\mlljk.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay10...es/MsnPUpld.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.pho...hxStudent15.CAB
O20 - Winlogon Notify: mlljk - C:\WINDOWS\system32\mlljk.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe


thanks again guys.
  • 0

Advertisements


#2
shoyoroll

shoyoroll

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Once again thanks for all your help forum gurus... you guys are the best!!!!
  • 0

#3
shoyoroll

shoyoroll

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
I also went through most of the steps you guys posted on simular topics..

Here is my ewildo report:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 3:51:22 PM, 12/5/2005
+ Report-Checksum: 2F8CB974

+ Scan result:

HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ehg-dig.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@www.burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\Content.IE5\9AT3M5XY\WinTA[1].cab/WToolsA.exe -> Spyware.Wintools : Error during cleaning
C:\Documents and Settings\Melissa\Cookies\melissa@112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@ehg-dig.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Melissa\Cookies\melissa@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.6:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.7:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.17:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.18:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.19:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.21:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.45:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.46:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.47:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.48:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.54:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.63:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.69:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.70:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.74:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\SYR\Application Data\Mozilla\Firefox\Profiles\7ccixt1e.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\SYR\Cookies\syr@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~409362.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~494178.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~504035.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~577806.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~749393.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~755814.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~760597.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~89362.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~908070.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~936793.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~937222.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temp\~987471.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temporary Internet Files\Content.IE5\SLY7S1QF\uninstall6_90[1].exe -> Adware.NewDotNet : Cleaned with backup
C:\Documents and Settings\SYR\Local Settings\Temporary Internet Files\Content.IE5\SLY7S1QF\ysb_prompt[1].htm -> Downloader.IstBar.j : Cleaned with backup
C:\Program Files\Common Files\WinTools\WToolsB.dll -> Spyware.Wintol : Cleaned with backup
C:\WINDOWS\system32\gebyx.dll -> Downloader.ConHook.l : Cleaned with backup
C:\WINDOWS\Temp\~594884.tmp -> Spyware.Wintools : Error during cleaning
C:\WINDOWS\Temp\~775336.tmp -> Spyware.Wintools : Error during cleaning


::Report End
  • 0

#4
OwNt

OwNt

    Malware Expert

  • Retired Staff
  • 7,457 posts
Hello, shoyoroll.

I need to get you to move HijackThis to a folder of its own so that nothing gets deleted by mistake

1. Right click in an empty space on your desktop.

2. From the Menu, click New, then Folder and a folder will appear on your desktop.

3. Name the folder HJT

4. Cut and Paste your current copy of HJT into the new Folder that was just created.

5. Now, run the program and post a fresh HJT log for review.
  • 0

#5
ScHwErV

ScHwErV

    Member 5k

  • Retired Staff
  • 21,285 posts
  • MVP
Being helped by miekiemoes

http://www.geekstogo...showtopic=83031

ScHwErV :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP