Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Multiple pop ups, freezes my pc sometimes

[Fixed] Hijackthis! Logs - [Fixed] Multiple pop ups, freezes my pc sometimes posted in the Security & Safety forums; my anti-virus program keeps saying that it has blocked Trojan.Vundo,Dowloader,Winfixer,DriveCleaner, it happens like every 6 or 7 minutes. Some how, it keeps insisting...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #7  
Old 07-19-2007
NeryCastillo21's Avatar
Bronze Member
 
Join Date: Jul 2007
Posts: 28
NeryCastillo21 - See this Members User comments on their Profile page
Default

my anti-virus program keeps saying that it has blocked Trojan.Vundo,Dowloader,Winfixer,DriveCleaner, it happens like every 6 or 7 minutes. Some how, it keeps insisting


  #8  
Old 07-19-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,521
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Did you run VundoFix as I directed earlier on? Please post the contents of C:\vundofix.txt.


  #9  
Old 07-20-2007
NeryCastillo21's Avatar
Bronze Member
 
Join Date: Jul 2007
Posts: 28
NeryCastillo21 - See this Members User comments on their Profile page
Default

hi, yes i did here it is

Symantec Trojan.Vundo Removal Tool 1.5.0
The process "iexplore.exe" might be affected by the threat. It has been suspended.
The process "iexplore.exe" might be affected by the threat. It has been terminated.
C:\System Volume Information: (not scanned)
Trojan.Vundo has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 96553
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral processes suspended: 1
The number of viral threads terminated: 0
The number of registry entries fixed: 0


My anti virus program keeps saying that it keeps blocking Trojan.Vundo and Downloader. all i remember is clicking on two .exe files and ever since then the problem begin.


  #10  
Old 07-20-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,521
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

What you ran was Symantec's removal tool.

From experience, that does not completely remove all Vundo variants. Please run VundoFix as I directed here:
http://www.pchelpforum.com/hijackthi...tml#post206022


  #11  
Old 07-21-2007
NeryCastillo21's Avatar
Bronze Member
 
Join Date: Jul 2007
Posts: 28
NeryCastillo21 - See this Members User comments on their Profile page
Default

sorry about that i got mixed up with the names here is the vundofix.txt


VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.7
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Scan started at 10:34:31 PM 7/20/2007
Listing files found while scanning....
C:\WINDOWS\system32\cbeeg.bak1
C:\WINDOWS\system32\cbeeg.bak2
C:\WINDOWS\system32\cbeeg.ini
C:\WINDOWS\system32\cbeeg.ini2
C:\WINDOWS\system32\cbeeg.tmp
C:\windows\system32\cgfgyhwr.dll
C:\windows\system32\epicyxmq.ini
C:\windows\system32\erilaqks.dll
C:\windows\system32\fcwlvmuy.ini
C:\windows\system32\fmefacet.dll
C:\windows\system32\fyepffwd.dll
C:\WINDOWS\system32\geebc.dll
C:\windows\system32\hujxromx.dll
C:\windows\system32\jcmalggm.dll
C:\windows\system32\jstjhjbu.dll
C:\windows\system32\lmfjbjhp.dll
C:\windows\system32\mlttcdlm.dll
C:\windows\system32\mslpvpls.dll
C:\windows\system32\mstifeeo.dll
C:\windows\system32\msukogde.dll
C:\windows\system32\opfnlbkq.dll
C:\windows\system32\oyxhrunh.dll
C:\windows\system32\ppjtjffr.dll
C:\WINDOWS\system32\qmxycipe.dll
C:\windows\system32\qwqaxwvf.dll
C:\windows\system32\rgqbryyw.dll
C:\windows\system32\riganugt.dll
C:\windows\system32\ubjhjtsj.ini
C:\windows\system32\ujpahfhr.dll
C:\windows\system32\unvsrfko.dll
C:\windows\system32\vblkaqsy.dll
C:\WINDOWS\system32\wsoyvaaj.dll
C:\windows\system32\yumvlwcf.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\cbeeg.bak1
C:\WINDOWS\system32\cbeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cbeeg.bak2
C:\WINDOWS\system32\cbeeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cbeeg.ini
C:\WINDOWS\system32\cbeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cbeeg.ini2
C:\WINDOWS\system32\cbeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cbeeg.tmp
C:\WINDOWS\system32\cbeeg.tmp Has been deleted!
Attempting to delete C:\windows\system32\cgfgyhwr.dll
C:\windows\system32\cgfgyhwr.dll Has been deleted!
Attempting to delete C:\windows\system32\epicyxmq.ini
C:\windows\system32\epicyxmq.ini Has been deleted!
Attempting to delete C:\windows\system32\erilaqks.dll
C:\windows\system32\erilaqks.dll Has been deleted!
Attempting to delete C:\windows\system32\fcwlvmuy.ini
C:\windows\system32\fcwlvmuy.ini Has been deleted!
Attempting to delete C:\windows\system32\fmefacet.dll
C:\windows\system32\fmefacet.dll Has been deleted!
Attempting to delete C:\windows\system32\fyepffwd.dll
C:\windows\system32\fyepffwd.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebc.dll
C:\WINDOWS\system32\geebc.dll Has been deleted!
Attempting to delete C:\windows\system32\hujxromx.dll
C:\windows\system32\hujxromx.dll Has been deleted!
Attempting to delete C:\windows\system32\jcmalggm.dll
C:\windows\system32\jcmalggm.dll Has been deleted!
Attempting to delete C:\windows\system32\jstjhjbu.dll
C:\windows\system32\jstjhjbu.dll Has been deleted!
Attempting to delete C:\windows\system32\lmfjbjhp.dll
C:\windows\system32\lmfjbjhp.dll Has been deleted!
Attempting to delete C:\windows\system32\mlttcdlm.dll
C:\windows\system32\mlttcdlm.dll Has been deleted!
Attempting to delete C:\windows\system32\mslpvpls.dll
C:\windows\system32\mslpvpls.dll Has been deleted!
Attempting to delete C:\windows\system32\mstifeeo.dll
C:\windows\system32\mstifeeo.dll Has been deleted!
Attempting to delete C:\windows\system32\msukogde.dll
C:\windows\system32\msukogde.dll Has been deleted!
Attempting to delete C:\windows\system32\opfnlbkq.dll
C:\windows\system32\opfnlbkq.dll Has been deleted!
Attempting to delete C:\windows\system32\oyxhrunh.dll
C:\windows\system32\oyxhrunh.dll Has been deleted!
Attempting to delete C:\windows\system32\ppjtjffr.dll
C:\windows\system32\ppjtjffr.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qmxycipe.dll
C:\WINDOWS\system32\qmxycipe.dll Could not be deleted.
Attempting to delete C:\windows\system32\qwqaxwvf.dll
C:\windows\system32\qwqaxwvf.dll Has been deleted!
Attempting to delete C:\windows\system32\rgqbryyw.dll
C:\windows\system32\rgqbryyw.dll Has been deleted!
Attempting to delete C:\windows\system32\riganugt.dll
C:\windows\system32\riganugt.dll Has been deleted!
Attempting to delete C:\windows\system32\ubjhjtsj.ini
C:\windows\system32\ubjhjtsj.ini Has been deleted!
Attempting to delete C:\windows\system32\ujpahfhr.dll
C:\windows\system32\ujpahfhr.dll Has been deleted!
Attempting to delete C:\windows\system32\unvsrfko.dll
C:\windows\system32\unvsrfko.dll Has been deleted!
Attempting to delete C:\windows\system32\vblkaqsy.dll
C:\windows\system32\vblkaqsy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wsoyvaaj.dll
C:\WINDOWS\system32\wsoyvaaj.dll Has been deleted!
Attempting to delete C:\windows\system32\yumvlwcf.dll
C:\windows\system32\yumvlwcf.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\qmxycipe.dll
C:\WINDOWS\system32\qmxycipe.dll Has been deleted!
Performing Repairs to the registry.
Done!


  #12  
Old 07-21-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,521
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default



Now post a new HijackThis log, let's see if the Vundo infection is all cleared up.



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 02:28 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top