Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - Trojan.Vundo -- Tried everything!!! posted in the Security & Safety forums; VundoFix.exe DOESNT EVEN FIND THE FILE!! The norton window pops back up whenever I press OK!!! Help!!...


Reply
Scan your PC for Errors
Old 07-18-2007   #29
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

VundoFix.exe DOESNT EVEN FIND THE FILE!! The norton window pops back up whenever I press OK!!! Help!!
Slow2die is offline   Reply With Quote
Advertisement - Register to Remove

Old 07-18-2007   #30
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

Slow2die is offline   Reply With Quote
Old 07-18-2007   #31
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

I just ran a Spyware Doctor and AVG Anti-Spyware Scan. Both Full scans.

Spyware Doctor sadly found nothing, and AVG only found one threat, which I deleted once the scan was finished.

Here is the AVG Report.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:10:09 18/07/2007
+ Scan result:

C:\System Volume Information\_restore{D85D6C89-42D5-4EE0-822F-27698E2A53D6}\RP330\A0249975.exe -> Dropper.Small : Cleaned.

::Report end
Slow2die is offline   Reply With Quote
Old 07-18-2007   #32
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default

Please be patient, as we are after all in different timezones.

Download Avenger from here:
Swandog46’s Public Tools Page

Open the program. Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens, paste this:
Files to delete:
C:\WINDOWS\system32\closeapp.exe
C:\WINDOWS\SYSTEM32\opnmlli.dll
and click 'Done'.

Click the Traffic Light icon to start the program, and OK the prompts to reboot your PC.
Post the Avenger output.txt, which you can find at C:\Avenger\.txt. Let me know if Norton is still prompting you.
chiaz is offline   Reply With Quote
Old 07-18-2007   #33
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

Apologies for becoming impatient. It's just this virus is doing my head in, and restricting me from being able to complete my work, which really isn't helping.

Report:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Service s\shqovqop
*******************
Script file located at: \??\C:\Program Files\pyxihkep.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\closeapp.exe deleted successfully.

File C:\WINDOWS\SYSTEM32\opnmlli.dll not found!
Deletion of file C:\WINDOWS\SYSTEM32\opnmlli.dll failed!
Could not process line:
C:\WINDOWS\SYSTEM32\opnmlli.dll
Status: 0xc0000034

Completed script processing.

It seems it was not found? I noticed no more popups after this reboot. Perhaps the file moved to another location that hasn't been detected yet?
Slow2die is offline   Reply With Quote
Old 07-18-2007   #34
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

And by popups, I meant the Norton alerts. The Pop-ups in Internet Explorer have stopped, but there is still much lagg when I open new windows/tabs etc which I never had before this virus came along.
Slow2die is offline   Reply With Quote
Old 07-18-2007   #35
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

Popups are back in internet explorer. Downloaders are coming. Everything is getting worse. IE laggs, and I keep getting "Page cannot be displayed" now too....

Looks like I will have to reinstall windows, as I can't work with this. Its a shame I couldnt be helped this time round.
Slow2die is offline   Reply With Quote

Reply

Bookmarks

Tags
trojanvundo

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 01:36 PM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2