Home > Vundo > Vundo & Func.js Virus - Please Help

Vundo & Func.js Virus - Please Help

Logfile of HijackThis v1.99.1 Scan saved at 11:34:23 PM, on 6/30/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Companion2007-08-11 15:58

Write down the exact name. Explore all its options, but skip the prefetch folder cleaning option. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [dlcdmon.exe] "C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe"O4 - C:\Documents and Settings\Owner.UPPERPLAYGROUND\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Adbrite : No action taken. :mozilla.106:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\mii861a3.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.17:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\mii861a3.default\cookies.txt -> TrackingCookie.Advertising : No action taken.

Attempting to delete C:\windows\system32\vturo.dll C:\windows\system32\vturo.dll Has been deleted! Post the contents of C:\vundofix.txt plus a new HijackThis log. 0 OPDiscussion Starter nerdwithnikeson 9 Years Ago everything worked and things are running a little bit better -------------------------------------------------- heres the contents Simply click on the I Accept button.After the license agreement goes away, you will be at the HijackThis Main Menu.Exit HijackThis for now.Finally,Please download VundoFix.exe to your desktop.Double-click VundoFix.exe to run Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLLO3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dllO3

Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.Copy and paste ALL the following blue text in the Quote box below into Notepad.Click on File(in the menu at http://www.geekstogo.com/forum/topic/168801-trojans-conhookd-and-virtmonde0-please-help-resolved/ Click OK. · Make sure everything in the white box has a check next to it, then click Next. · It will quarantine what it found and if it asks if Attempting to delete C:\windows\system32\tfutqygk.dll C:\windows\system32\tfutqygk.dll Has been deleted!

only problems were that thinksnet.exe was nowhere to be found so i could not delete it and when i tried to stop and delete windows overlay components it said that it Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htmO8 - Extra context menu item: Yahoo! &SMS Windows 10 Freezes Last Post 1 Week Ago Trigger Warning: Old specs are old. navigate here C:\windows\system32\atspglof.exe C:\WINDOWS\system32\awvvs.dll C:\windows\system32\bwprvnwq.dll C:\windows\system32\cewnvbjq.dll C:\windows\system32\cnxuejgw.ini C:\WINDOWS\system32\cqpksnhw.dll C:\windows\system32\docbveaj.ini C:\windows\system32\irytquxx.dll C:\windows\system32\j1271333.dll C:\windows\system32\jaevbcod.dll C:\windows\system32\jlhxisdu.dll C:\WINDOWS\system32\ktkcheay.dll C:\windows\system32\kxllnrnr.dll C:\WINDOWS\system32\kyhbsdro.dll C:\WINDOWS\system32\ljjjkhh.dll C:\windows\system32\ljyqfpwa.exe C:\windows\system32\nkqttmex.exe C:\windows\system32\nnnkiig.dll C:\windows\system32\orutv.ini C:\windows\system32\padfhwqt.dll C:\WINDOWS\system32\pgrcisci.dll C:\windows\system32\piyobysg.exe C:\windows\system32\pjrwljfi.exe C:\windows\system32\qvamqsvd.exe C:\windows\system32\qwnvrpwb.ini C:\windows\system32\qxdxucnq.exe C:\windows\system32\rakiubkv.exe C:\windows\system32\rdgvcnnx.exe C:\windows\system32\rpleetje.exe C:\windows\system32\rqqccqii.exe C:\windows\system32\ryqfjaoi.exe

About MDN Terms Privacy Cookies Contribute to the code Other languages: English (US) (en-US) Deutsch (de) Español (es) Français (fr) Italiano (it) 日本語 (ja) 한국어 (ko) Português (do Brasil) (pt-BR) Русский (ru) Back to top #5 Daisy01 Daisy01 Topic Starter Members 5 posts OFFLINE Local time:03:57 PM Posted 14 August 2007 - 06:22 PM *******************************************COMBOFIX LOG*******************************************ComboFix 07-08-14 - "amber" 2007-08-14 18:58:52.2 - IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} http://controlpanelsource.com/vundo/vundo.html Go file, export, and follow through.

Several functions may not work. Attempting to delete C:\windows\system32\cnxuejgw.ini C:\windows\system32\cnxuejgw.ini Has been deleted! Attempting to delete C:\windows\system32\wpbyvcco.dll C:\windows\system32\wpbyvcco.dll Has been deleted! C:\Documents and Settings\Owner.UPPERPLAYGROUND\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Trafficmp : No action taken.

Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 22:49]"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-31 23:42]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-09 09:45]"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-06-18 15:58]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]"Sen"="C:\Program Files\Outerinfo\OuterinfoUpdate.exe" []C:\Documents and Settings\amber\Start Menu\Programs\Startup\LimeWire On Startup.lnk C:\Documents and Settings\Owner.UPPERPLAYGROUND\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken. This has been changed as of Firefox 24. Just because it is easy, please delete c:\vundofix.txt and run it again....

Attempting to delete C:\WINDOWS\system32\cqpksnhw.dll C:\WINDOWS\system32\cqpksnhw.dll Has been deleted! a : b; // Easy array filtering, mapping, ... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:04:46 PM, on 7/20/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe Done that?