
UNSOLVED
Trojan Vundo?
I followed the instructions in the other thread (http://www.dellcommunity.com/supportforums/board/message?message.uid=17487725#U17487725) but per the instructions do not see 02-BHO lines that are necessary to proceed with cleaning the trojan.
Have run AdAware and Symantec with current patches multiple times today only to have symantec pop up again telling me trojan.vundo has been deleted (or cleaned, or quaranteened - I've run this 6 times today) and to reboot.
Any suggestions on how to proceed from here would be greatly appreciated.
___________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:15 PM, on 6/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\zutzjj\Application Data\U3\3514600A3500C749\LaunchPad.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\zutzjj\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.alcoa.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.alcoa.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NA Policy 02-14-08
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=na-proxy.alcoa.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.alcoa.com;*.*.alcoa.com;*.mrplastics.com;*.huck.com;*.fairchilddirect.com;*.howmet.com;*.rmc.com;147.154.*.*;192.168.*.*;192.55.195.*;155.248.*.*;10.*.*.*;137.27.*.*;142.79.*.*;*.alcoadirect.com;*.hewitt.com;*.*.rservices.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: {e4aab70c-a788-9e88-66b4-b54383428159} - {95182438-345b-4b66-88e9-887ac07baa4e} - C:\WINNT\system32\ocyqcofi.dll (file missing)
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINNT\system32\jkkKabyx.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-18 Startup: Client Customization.lnk = C:\WINNT\system32\CC-Stub.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Client Customization.lnk = C:\WINNT\system32\CC-Stub.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Client Customization.lnk = C:\WINNT\system32\CC-Stub.EXE (User 'Default user')
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_13\bin\npjpi142_13.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_13\bin\npjpi142_13.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://intranet.alcoa.com/
O15 - Trusted Zone: http://noaadc-web08.noa.alcoa.com
O15 - Trusted Zone: http://project-adc.intranet.alcoa.com
O15 - Trusted Zone: http://project-cre.intranet.alcoa.com
O15 - Trusted Zone: http://project-default.intranet.alcoa.com
O15 - Trusted Zone: http://project-tax.intranet.alcoa.com
O15 - Trusted Zone: http://Alcoaprism.ciberpgh.com
O15 - Trusted Zone: http://www2.gepower.com
O15 - Trusted Zone: http://supplier.pg.siemens.com
O15 - Trusted Zone: http://noaadc-web08.noa.alcoa.com (HKLM)
O15 - Trusted Zone: http://project-adc.intranet.alcoa.com (HKLM)
O15 - Trusted Zone: http://project-cre.intranet.alcoa.com (HKLM)
O15 - Trusted Zone: http://project-default.intranet.alcoa.com (HKLM)
O15 - Trusted Zone: http://project-tax.intranet.alcoa.com (HKLM)
O15 - Trusted Zone: http://Alcoaprism.ciberpgh.com (HKLM)
O15 - Trusted Zone: http://www2.gepower.com (HKLM)
O15 - Trusted Zone: http://supplier.pg.siemens.com (HKLM)
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = NOA.Alcoa.com
O17 - HKLM\Software\..\Telephony: DomainName = NOA.Alcoa.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = NOA.Alcoa.com
O20 - Winlogon Notify: jkkKabyx - jkkKabyx.dll (file missing)
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 7706 bytes
Responses (2)
Solutions (0)
First, my apologies for the delay given your graceous prompt response - Comcast availability issues. I must also beg your forgiveness as I saw the thread below before your reply. I did install the Malwarebytes per that thread and so far it appears to have resolved the Vundo virus issue (and several other icky things it found). I will create a new thread if my issue isn't resolved.
So thank you again for your willingness to help and time. Sorry for my poor follow through, but the good news is it appears through this forum I was able to get this fixed.
Reply

bamajim
10376 Posts
118
0
Posted June 6th, 2008 11:00
1. Go HERE and download File Lister.
Rt Click ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Open the File Lister Folder.
Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
As the program runs, it will appear that nothing is happening.
When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.
"The world is what you make of it"