PDA

View Full Version : win32/vundo.cr



type r
2007-05-31, 03:06
my virus scanner detected the win32/vundo.cr and it couldnt be removed i tried searching on google but i guess everyone's computer is different because i tried following someone elses solution but found out that i didnt know which files to check on the trend micro hijackthis program.im using the virus scanner that was included with my yahoo dsl

here is the hijackthis log:
1 0.2% F2 Shell=explorer.exe
2 5.1% O12 C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
3 6.2% O16 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
4 0.2% O16 {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
5 0.1% O16 {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
6 0.0% O16 {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
7 0.0% O16 {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
8 0.0% O16 {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - https://objects.aol.com/mcafee/molbin/shared/mcgdmgr/en-us/1,0,0,20/McGDMgr.cab
9 0.0% O16 {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - https://objects.aol.com/mcafee/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
10 0.0% O16 NDWCab - http://www.neededware.com/ndw4.cab
11 0.0% O16 {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/xpre.chm::/xpreload.ocx
12 0.0% O16 {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163120314999
13 0.0% O16 {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163643999063
14 3.7% O2 AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
15 0.6% O2 Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
16 0.6% O2 SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
17 0.3% O2 Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
18 0.0% O2 CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
19 0.0% O2 Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
20 0.0% O2 WinStat - {0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF} - C:\WINDOWS\System32\WinStat13.dll
21 0.0% O2 (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - C:\WINDOWS\System32\hggghee.dll (file missing)
22 0.0% O2 0 - {2FB57088-4D18-45F4-6DB4-9C0C4E0AB7E3} - C:\Program Files\MSN\ladu.dll (file missing)
23 0.0% O2 (no name) - {49b70fbe-b42a-4d4d-8afb-6a69d1f92a1f} - C:\WINDOWS\system32\comdro.dll (file missing)
24 0.0% O2 0 - {75E4EFD9-1F26-450B-A188-F70ACB7B1D1E} - C:\Program Files\MSN\ladu.dll (file missing)
25 0.0% O2 (no name) - {C1850CD2-A9C8-4421-BCE1-D1C91539F976} - C:\WINDOWS\System32\pmnlm.dll (file missing)
26 0.0% O2 (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\System32\qkdejkkg.dll
27 0.0% O20 comdro - comdro.dll (file missing)
28 44.6% O22 Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
29 43.1% O22 Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
30 14.7% O23 Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
31 9.5% O23 ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
32 6.1% O23 iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
33 0.3% O23 VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
34 0.3% O23 CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
35 4.2% O3 &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
36 0.7% O3 Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
37 0.0% O3 Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
38 22.4% O4 [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
39 12.8% O4 [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
40 11.4% O4 [SoundMan] SOUNDMAN.EXE
41 11.0% O4 [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
42 6.1% O4 Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
43 4.8% O4 [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
44 1.4% O4 [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
45 1.1% O4 [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
46 0.6% O4 [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
47 0.5% O4 [IpWins] C:\Program Files\Ipwindows\ipwins.exe
48 0.4% O4 [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
49 0.4% O4 [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
50 0.3% O4 [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
51 0.3% O4 [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
52 0.2% O4 [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
53 0.2% O4 [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
54 0.1% O4 AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
55 0.1% O4 [Yahoo! Pager] 1
56 0.0% O4 [Configuration Manager] C:\WINDOWS\cfg32.exe
57 0.0% O4 [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb03.exe
58 0.0% O4 [runner1] C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
59 0.0% O4 [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
60 0.0% O4 [iurrkxw] c:\windows\system32\fzwpaen.exe r
61 0.0% O4 [juddpa] C:\WINDOWS\System32\juddpa.exe
62 0.0% O4 [ctzfndp] C:\WINDOWS\System32\ctzfndp.exe
63 10.0% O8 E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
64 1.0% O8 &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
65 11.0% O9 Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
66 6.2% O9 Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
67 2.5% O9 AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
68 2.2% O9 Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
69 2.2% O9 Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
70 0.5% O9 (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
71 0.5% O9 Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
72 0.2% O9 AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
73 77.6% P01 C:\WINDOWS\Explorer.EXE
74 75.8% P01 C:\WINDOWS\system32\svchost.exe
75 75.7% P01 C:\WINDOWS\system32\lsass.exe
76 75.7% P01 C:\WINDOWS\system32\winlogon.exe
77 75.7% P01 C:\WINDOWS\system32\services.exe
78 75.6% P01 C:\WINDOWS\System32\smss.exe
79 72.8% P01 C:\WINDOWS\system32\spoolsv.exe
80 18.9% P01 C:\WINDOWS\system32\wuauclt.exe
81 18.4% P01 C:\WINDOWS\system32\Ati2evxx.exe
82 11.7% P01 C:\Program Files\iPod\bin\iPodService.exe
83 11.1% P01 C:\Program Files\iTunes\iTunesHelper.exe
84 10.8% P01 C:\WINDOWS\SOUNDMAN.EXE
85 4.9% P01 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
86 1.4% P01 C:\Program Files\Real\RealPlayer\RealPlay.exe
87 0.8% P01 C:\PROGRA~1\Yahoo!\browser\ycommon.exe
88 0.6% P01 C:\Program Files\BroadJump\Client Foundation\CFD.exe
89 0.4% P01 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
90 0.4% P01 C:\PROGRA~1\Yahoo!\YOP\yop.exe
91 0.3% P01 C:\Program Files\Ipwindows\ipwins.exe
92 0.3% P01 C:\Program Files\Yahoo!\Antivirus\ISafe.exe
93 0.3% P01 C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
94 0.3% P01 C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
95 0.3% P01 C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
96 0.2% P01 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
97 0.2% P01 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
98 0.2% P01 C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
99 0.1% P01 C:\Program Files\Yahoo!\browser\ybrowser.exe
100 0.0% P01 C:\WINDOWS\cfg32.exe
101 0.0% P01 C:\WINDOWS\cfg32a.exe
102 0.0% P01 C:\WINDOWS\retadpu1000106.exe
103 0.0% P01 C:\Documents and Settings\Quiet Boy\Desktop\HiJackThis_v2.exe
104 0.1% R0 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
105 0.0% R0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
106 2.1% R1 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
107 0.5% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
108 0.3% R1 HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
109 0.3% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
110 0.3% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
111 0.2% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
112 0.2% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
113 0.1% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
114 0.6% R3 Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll

can someone please help me im not really good with computers. i also downloaded the vundofix and deleted some stuff

type r
2007-05-31, 03:08
i followed pskelley's advices on someone elses thread and i only used the used the vundofix but i dont know how to go further with the process