Trojan.vundo.b - Removal Tool?

Oct 17, 2005

I've been getting this winfixer 2005 pop up window everytime i open my pc. what i normally do is just close it. i've learned that it's something to do with the trojan.vundo.b virus. i searched the net for removal tools and downloaded one from norton but it didnt help.Now, i've been receiving virus alerts from norton.

Spyware Removal - Remove A Tool Bar Called 'security Tool Bar 7.1

Oct 29, 2007

I have been trying to remove a tool bar called 'security tool bar 7.1' I think its a rouge.

Trojan.vundo Won't Go

Jan 22, 2006

I've got the trojan.vundo virus. I have installed and run the vundo removal tool, and it shows me that it is gone-but when I restart my computer, Norton anti-virus finds it again (and again...and again).

Can't Remove Trojan.Vundo

Nov 2, 2007

I get this trojan today and i never get viruses usually but this one reaqlly is annoying!

Ive looked at all the other posts and ive tried using the vundo fix tool etc but it does not pick it up at all. Ive tried doing it in safe mode and ive tried unistalling java to see if it was involved with that but nothing has worked so far.

I have located the file in my system32 folder and its named xxyywtq.dll but theres no way it will let me delete it as it says it is being used by another program or person.

NIS Scan And Found A Vundo Trojan

Dec 10, 2005

We network our computers and I had alot of adware and a trojan virus on mine so I do believe she has the same. I ran a NIS scan and found a vundo trojan on this computer (hers). Had to download the tool to remove it and it appears it was successful. But the computer is still so slow and having some internet explorer errors.

Trojan Vundo Virus - Slow Computer

Apr 15, 2007

I had this Trojan vundo virus about a month ago and you helped me remove it. My computer was running fine until all of the same things started happening again. Im pretty sure i still have the virus b/c my computer is running very slow and just plain bad. I ran VundoFix.exe (it found like 10 things), clicked remove vundo, and rebooted. I ran HijackThis and here is this log file.what i need to delete? ....

High Risk Virus Alert With Trojan.Vundo

Oct 9, 2005

I'm running into a High Risk virus alert with Trojan.Vundo The object name is C:WINDOWSsystem32mljgd.dll --i've tried deleting it in safe mode through regedit but it always comes back up after i refresh.

MS Spy-ware Removal Tool

Jun 23, 2005

I had alot of spy-ware on a computer and ran MS Spy-ware removal tool and now my Explorer.exe will not come up, no desktop no icons on noting. I can press crtl->Alt->delete and bring up task manager, that is it.

Malicious Software Removal Tool

Feb 16, 2006

Where does the monthly release of the microsoft auto update Malicious Software removal tool go and does it need to be run manually

What's This Newfangled Malicious Removal Tool ?

Sep 18, 2005

I'm just getting to play with it but I can't find it in any of the start menus or control panel. The MS KB points me to a web-based tool

Malicious Software Removal Tool Infected

Jul 9, 2009

I reformatted a friend's computer and reinstalled XP from the disk. Rather than mess around with SP2 I went ahead and installed SP3 afterwards. When it was in the process of installing the IE (whatever one comes with it), the MSRT tool cropped up and found over 435 files that were "infected".

How To Start MS Malicious Software Removal Tool Without In

Sep 14, 2005

If i don't have access to internet and to [...] fault.mspx how can i start MS removal tool

Microsoft Malicious Software Removal Tool

Jan 9, 2007

I use the microsoft malicious software removal tool what a mouthful manually when I download the update should I delete the old one first or will the new version install over the top.

Microsoft Malicious Software Removal Tool

Sep 14, 2010

I ran the Microsoft Windows Malicious Software Removal Tool v3.11, "Engine internal result code = 80508015" means and is it serious This is my desktop with WinXPsp3 which I've had for quite a while but hope nothing serious is wrong with it

Microsoft Malicious Software Removal Tool

Oct 12, 2006

I am getting this Security Alter message saying that " Your computer is infected with last version of PSW.x-Vir trojan. I recently downloaded this program called Microsoft Windows Malicious Software Removal Tool. Hopefully this program will help me remove this trojan, but if anyone can let me know about what programs i could use to remove or if anyone could help me remove this trojan that would be greatful. Also i am getting this message on my toolbar with an x and a question mark on top of it saying that your system detected virus activities and when i click on it, it sends me to this weblink

Microsoft Windows Malicious Software Removal Tool

Jul 19, 2005

I received advice that the following Updated Version is now available:-Microsoft Windows Malicious Software Removal Tool <> I tried over the last three days to download it to my Desktop, but every time I get the following Notice: Cannot download this file.Invalid http server reply. Details MZ followed by a square

Malicious Software Removal Tool Does It Report Finds?

Dec 20, 2007

Ive been told that the monthly tool doesn report if it finds OR removes anything is this true

Microsoft Malicious Software Removal Tool On Dell Dimension XPS Gen 4

Jun 17, 2005

I have attempted to run this software, but each time i do so, it cause my entire system to freeze. I have tried running it from the website as well as downloading it and then running it. Both cause my system to freeze, requiring a hard boot. i have a Dell Dimension XPS Gen 4

Malicous Software Removal Tool / NetFrameWork Update Keeps Appearing In Tray

Apr 17, 2008

my dad has been having these problems for months now - updates for net framework and Windows Malicuous Software Removal Tool... keep appearing in the tray as updates and when he installs them they re-appear - I think its summit to do with .NET Framework but i tried re-installing them all manually and it still happens..

Unbale To Remove Backdoor.Trojan / Removal Tools Wont Work?

Jul 27, 2005

My norton Antivirus detected ( after updating the definitions )Backdoor.Trojan having the object name c: WINDOWSSystem32scrsvc.exe I would like to know about its removal tool as Norton couldnot repair it .If deleting this file can get rid of this virus ?

Trojan/Virus - SECURITY TOOL

Apr 21, 2010

Recently had a window pop up that said SECURITY TOOL do you want to scan your computer blah blah blah. He clicked no and the program installed anyway. Now any time you try to open a program, the security tool pops up saying the file is infected etc. I can't even run hijack this. Here are the computer specs: Need help ASAP

View 6 Replies View Related

Free Virus - Trojan Clean Up Tool By Avast

Apr 7, 2005

Avast has a whole page of awards, I use their free Anti-Virus program. Here is their clean-up tool.

Validation Tool Advantage - Bypass This Tool

May 2, 2008

I use to update my Xp SP-2 regularly from MS website. Now a days it is insisting to install "Windows Genuine Advantage Validation Tool (KB892130)" first to proceed for downloading update files.Is it a FORCE or I can bypass this tool. I do not want to install it, as somebody told me this is a tool by MS to takeout personal information on my OS (XP) and MS Office and other MS Software.I know I use genuine legal copy.But why should I allow MS to take more information ? Is not WPA through internet is not sufficient ? Can this tool take information on other products/3rd party software like NERO,MS OFFICE and ArcSOft ?

Trojan In Reg32.exe =trojan.low Zones: Wont Remove Virus?

Feb 11, 2005

I have of lot of trojans and can't seem to get rid of them I have ran Spy Bot,Avast,Ad-Aware,Stop Sign and found a 1 Trojan in reg32.exe =trojan.low zones
2 downloaded program files says: Trojan.downloader1097 3 System 32 sygate = Win32.HLLW.MyBot.based 4 Avenue Media Internet Optimizer Software Package = Possible spyware Application 5 Appropos Media People On Page Application = Possible Spyware

Vundo Virus

Aug 14, 2007

i used a vundo fix and got rid of all of the vundo viruses but two would not go away.

i got error message : Error: 75. Path/File access error

The two files were :


why these two vundos won't go away? They won't clean from my antivirus or quarantine either.They keep popping up in my system notifying me that they are there.

Norton Saying - Vundo Threat

Oct 15, 2005

A message from Norton that says I have a Trogan Vundo on my computer.When I use the Norton removal tool it does not find the virus.When I use the Norton scan it does.

Virtumonde/vundo Damage

May 10, 2007

Infected by the vundo/virtumonde virus

I have ran scans of spysweeper and max registry cleaner, and from what i understand the actual malware is gone. the problems is i have no icons/taskbar. ive tried running explorer.exe through the task manager, which gets the taskbar to flash fora couple seconds, but it disappears shortly after. ive tried running taskbar repair tool plus, but that doesnt help me much.

Here is it

Logfile of HijackThis v1.99.1
Scan saved at 4:10:39 PM, on 5/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:Program FilesMicrosoft Windows OneCare LiveAntivirusMsMpEng.exe
c:program filesmcafee.comagentmcdetect.exe
C:Program FilesUPHCleanuphclean.exe
C:Program FilesWebrootSpy SweeperSpySweeper.exe
C:Program FilesSkyhook WirelessWi-Fi ServiceWPSScannerSvc.exe
C:Program FilesMicrosoft Windows OneCare LiveFirewallmsfwsvc.exe
C:Program FilesMicrosoft Windows OneCare Livewinss.exe
C:Program FilesMicrosoft Windows OneCare Livewinssnotify.exe
C:Program FilesWindows Media Playerwmplayer.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesHijackThisHijackThis.exe

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:progra~1mcafee.comvsomcvsshl.dll
O4 - HKLM..Run: [SunKistEM] "C:Program FileseMachines Bay Readershwiconem.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_03injusched.exe"
O4 - HKLM..Run: [MCAgentExe] c:PROGRA~1mcafee.comagentmcagent.exe
O4 - HKLM..Run: [MCUpdateExe] c:PROGRA~1mcafee.comagentMcUpdate.exe
O4 - HKLM..Run: [IPHSend] "C:Program FilesCommon FilesAOLIPHSendIPHSend.exe"
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [VSOCheckTask] "C:PROGRA~1McAfee.comVSOmcmnhdlr.exe" /checktask
O4 - HKLM..Run: [VirusScan Online] "C:Program FilesMcAfee.comVSOmcvsshld.exe"
O4 - HKLM..Run: [OASClnt] "C:Program FilesMcAfee.comVSOoasclnt.exe"
O4 - HKLM..Run: [OneCareUI] "C:Program FilesMicrosoft Windows OneCare Livewinssnotify.exe"
O4 - HKLM..Run: [RCSystemTray] "C:Program FilesMax Registry CleanerMaxRCSystemTray.exe"
O4 - HKLM..Run: [SNM] "C:Program FilesSpyNoMoreSNM.exe" /startup
O4 - HKLM..Run: [KernelFaultCheck] C:WINDOWSsystem32dumprep 0 -k
O4 - HKLM..Run: [RCAutoLiveUpdate] "C:Program FilesMax Registry CleanerMaxLiveUpdateRC.exe" -AUTO
O4 - HKLM..Run: [SpySweeper] "C:Program FilesWebrootSpy SweeperSpySweeperUI.exe" /startintray
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Reader
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2in
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2in
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:WINDOWSSystem32shdocvw.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:WINDOWSSystem32shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:Program FilesICQICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:Program FilesICQICQ.exe
O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSSystem32Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O15 - Trusted Zone: * (HKLM)
O15 - Trusted Zone: * (HKLM)
O15 - Trusted Zone: * (HKLM)
O15 - Trusted Zone: * (HKLM)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} ( Operating System Class) -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
O17 - HKLMSystemCCSServicesTcpip..{FB2E15D9-1174-4951-A108-219BE5713585}: NameServer =,
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:PROGRA~1COMMON~1AOLACSacsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodiniPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:WINDOWSsystem32driversKodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:program filesmcafee.comagentmcdetect.exe
O23 - Service: McShield (McShield) - McAfee Inc. - c:PROGRA~1mcafee.comvsomcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:PROGRA~1mcafee.comagentmctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:PROGRA~1McAfee.comAgentmcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:PROGRA~1McAfeeSPAMKI~1MSKSrvr.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:WINDOWSwanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:Program FilesWebrootSpy SweeperSpySweeper.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:Program FilesSkyhook WirelessWi-Fi ServiceWPSScannerSvc.exe

Xsoft Picking Vundo

May 18, 2007

I downloaded vundo.exe and ran it . Says Ok
Then I run xsoft and says has vundo . ?

Vundo Infection Recurring

Oct 16, 2008

I have a vundo infection (on it's automatic scans) i ran superantispyware pro and it said clean.
Then i restarted, and it was back.
I ran superantispyware pro again, along with cwshredder, spybot, spyware blaster, and prevx. the infection seemed to be gone, but then the next day trendmicro alerted me that it was in my system restore. so i turned off system restore, restarted, re-enabled system restore and made a restore point.
The infection isn't gone.

Hijack log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:58:03, on 16/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
C:Program FilesGoogleUpdateGoogleUpdate.exe
C:Program FilesCommon FilesLightScribeLSSrvc.exe
C:OfficeScan NT
c:Program FilesCommon FilesProtexisLicense ServicePsiService_2.exe
C:Program FilesoneTick imesync.exe
C:Program FilesCanonCALCALMAIN.exe
C:Program FilesHewlett-PackardSharedhpqwmiex.exe
C:OfficeScan NT mlisten.exe
C:OfficeScan NTCNTAoSMgr.exe
C:Program FileshpqHP Wireless AssistantHP Wireless Assistant.exe
C:Program FilesJavajre1.6.0_07injusched.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesHPQuickPlayQPService.exe
C:Program FilesHpHP Software UpdateHPWuSchd2.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe
C:Program FilesCommon FilesRealUpdate_OB
C:Program FilesBabylonBabylon-ProBabylon.exe
C:Program FilesCreativeCreative ZENEN Media ExplorerCTCheck.exe
C:OfficeScan NTpccntmon.exe
C:Program FilesRainlendar2Rainlendar2.exe
C:Program FilesATnotesATnotes.exe
C:Program FilesoneTickzonetick.exe
C:Documents and SettingscalindraLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesWindows Desktop SearchWindowsSearch.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
c:program filescommon filesinstallshieldupdateserviceisuspm.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceagent.exe
C:Program FilesOperaopera.exe
C:Program FilesPrevx2PXConsole.exe
C:Program FilesPrevx2PXAgent.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
N4 - Mozilla: user_pref("browser.startup.homepage", ""); (C:Documents and SettingsCALINDRAApplication DataMozillaProfilesdefaultzz9effyd.sltprefs.js)
N4 - Mozilla: user_pref("", "engine:// rc"); (C:Documents and SettingsCALINDRAApplication DataMozillaProfilesdefaultzz9effyd.sltprefs.js)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Program FilesRealRealPlayer
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:Documents and SettingsAll UsersApplication DataPrevxpxbho.dll
O2 - BHO: (no name) - {5C38F1A3-C14E-4EBD-A55B-CF9EE24FE46F} - C:WINDOWSsystem32qOIxWPhg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_07inssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier4.1.805.4472swg.dll
O2 - BHO: {edb801e3-ef97-2908-71d4-7b292271204c} - {c4021722-92b7-4d17-8092-79fe3e108bde} - (no file)
O2 - BHO: (no name) - {CE24BFF5-E53D-4D0E-A2A4-DBF6EE6E92C3} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:Program FilesVeoh NetworksVeohPlugins
O3 - Toolbar: (no name) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:PROGRA~1TEXTAL~1TAForIE.dll
O4 - HKLM..Run: [ehTray] C:WINDOWSehomeehtray.exe
O4 - HKLM..Run: [hpWirelessAssistant] C:Program FileshpqHP Wireless AssistantHP Wireless Assistant.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_07injusched.exe"
O4 - HKLM..Run: [igfxtray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [igfxhkcmd] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [igfxpers] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [QPService] "C:Program FilesHPQuickPlayQPService.exe"
O4 - HKLM..Run: [HP Software Update] C:Program FilesHpHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [ISUSPM Startup] "c:Program FilesCommon FilesInstallShieldUpdateServiceisuspm.exe" -startup
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [QlbCtrl] %ProgramFiles%Hewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe /Start
O4 - HKLM..Run: [Cpqset] C:Program FilesHewlett-PackardDefault Settingscpqset.exe
O4 - HKLM..Run: [RecGuard] C:WindowsSMINSTRecGuard.exe
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 9.0ReaderReader_sl.exe"
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OB
ealsched.exe" -osboot
O4 - HKLM..Run: [Easy-PrintToolBox] C:Program FilesCanonEasy-PrintToolBoxBJPSMAIN.EXE /logon
O4 - HKLM..Run: [Babylon Client] C:Program FilesBabylonBabylon-ProBabylon.exe -AutoStart
O4 - HKLM..Run: [CTCheck] C:Program FilesCreativeCreative ZENEN Media ExplorerCTCheck.exe
O4 - HKLM..Run: [ioCentre] C:GeniusioCentregTaskBar.exe
O4 - HKLM..Run: [IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM..Run: [MSPY2002] C:WINDOWSsystem32IMEPINTLGNTImScInst.exe /SYNC
O4 - HKLM..Run: [OfficeScanNT Monitor] "C:OfficeScan NTpccntmon.exe" -HideWindow
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [AppleSyncNotifier] C:Program FilesCommon FilesAppleMobile Device SupportinAppleSyncNotifier.exe
O4 - HKLM..Run: [QuickFinder Scheduler] "c:Program FilesCorelWordPerfect Office X4ProgramsQFSCHD140.EXE"
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [PrevxOne] "C:Program FilesPrevx2PXConsole.exe"
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Rainlendar2] C:Program FilesRainlendar2Rainlendar2.exe
O4 - HKCU..Run: [ATnotes.exe] C:Program FilesATnotesATnotes.exe
O4 - HKCU..Run: [ZoneTick] C:Program FilesoneTickzonetick.exe
O4 - HKCU..Run: [Google Update] "C:Documents and SettingscalindraLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:Program FilesVongoTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:Program FilesVongoTray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:Program FilesVongoTray.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Windows Search.lnk = C:Program FilesWindows Desktop SearchWindowsSearch.exe
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - c:Program FilesCorelWordPerfect Office X4ProgramsWPLauncher.hta
O8 - Extra context menu item: Translate with &Babylon - res://C:Program FilesBabylonBabylon-ProUtilsBabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_07inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_07inssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardHP Quick Launch ButtonsAddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:Program FilesCanonCALCALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.exe
O23 - Service: Google Update Service (gupdate1c920b4c2ad0755) (gupdate1c920b4c2ad0755) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardSharedhpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodiniPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:OfficeScan NT
O23 - Service: PREVXAgent - Prevx - C:Program FilesPrevx2PXAgent.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:Program FilesCommon FilesProtexisLicense ServicePsiService_2.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:OfficeScan NT mlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:OfficeScan NTTmProxy.exe
O23 - Service: ZoneTick Time (ZTime) - WR Consulting - C:Program FilesoneTick imesync.exe

End of file - 14271 bytes

Xp Slow Ans Vundo Error

Feb 28, 2008

I am running XP Pro and it is very slow, I had a message from Mcafee that I had a vundo virus. When I am on the internet it is very slow and I have window screens open in explorer that dont open all the way and I get message.

HiJack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:53:25 PM, on 2/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe
C:Program FilesMcAfeeMPFMPFSrv.exe
C:Program FilesMicrosoft Windows Feedback PanelWFPService.exe
C:Program FilesMicrosoft Windows Feedback PanelWFPUser.exe
C:Program FilesMcAfeeMPSmpsevh.exe
C:Program FilesMicrosoft Windows Feedback Panelwfpasieve.exe
C:Program FilesPalmHOTSYNC.EXE
C:Program FilesWindows DefenderMsMpEng.exe
C:Program FilesMicrosoft ActiveSyncwcescomm.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O4 - HKLM..Run: [70348166] rundll32.exe "C:WINDOWSsystem32ubiojhqe.dll",b
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKUSS-1-5-21-515967899-1547161642-725345543-1004..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe (User 'Elaine')
O4 - Startup: HotSync Manager.lnk = C:Program FilesPalmHOTSYNC.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: Apple Mobile Device - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:Program FilesSymantecpcAnywhereawhost32.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:PROGRA~1COMMON~1McAfeeEmProxyemproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:PROGRA~1COMMON~1mcafeemnamcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:PROGRA~1COMMON~1mcafeemcproxymcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:PROGRA~1COMMON~1mcafee
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:Program FilesMcAfeeMPFMPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:PROGRA~1McAfeeMPSmps.exe
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe

End of file - 7056 bytes

Unable To Remove "" Trojan?

Apr 1, 2006

I have windows xp, i have avg antivirus and have run the tests in pc pitstop and done a regular search thru windows for the but can't locate it on my pc. My IE browser freezes everytime i go to a particular site and yet when i ask if anyone else has trouble with that site only a very few people say yes. The solution they give me is to download Mozilla and use it for that site. That doesn't protect me from the trojan completely infecting me does it? Can anyone tell me how to delete this trojan?

View 14 Replies View Related

