THIS IS THE HIJACK LOG PLS PLS PLS PLS PLEASEEEEEEEEEEE HELP....I AM ON THE VERGE OF A NERVOUS BREAKDOWN BECAUSE OF THIS...THIS IS CRAZY.....INTERNET WINDOWS OPEN ON THEIR OWN...AND USUALLY DISPLAY SOME ADVERTS,...ETC
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:56:38 AM, on 8/5/2008 Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
Copy and Paste that log into your next reply, along with fresh hijackthis log.
NB: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: C:\WINDOWS\system32\ogwrjyho.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\pmnoPggE.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\pxkoltqo.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\jkkhhecy.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\lfyplw.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\zxtvkd.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\iblphz.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\vjvqyj.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\hlcmxdyi.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dbffe26a-01d1-45c0-aec2-cdd8d0e5341c} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{dbffe26a-01d1-45c0-aec2-cdd8d0e5341c} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{4ec66e48-b863-4413-bc91-463d9cca093b} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ec66e48-b863-4413-bc91-463d9cca093b} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkhhecy (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{d72c758f-3553-4310-a5de-edf6aee86eb7} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d72c758f-3553-4310-a5de-edf6aee86eb7} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2120cda9-b23e-4b7a-a139-d9882dfed012} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\00078706 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4ec66e48-b863-4413-bc91-463d9cca093b} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\pmnopgge -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\pmnopgge -> Quarantined and deleted successfully.
Folders Infected: (No malicious items detected)
Files Infected: C:\WINDOWS\system32\pmnoPggE.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\EggPonmp.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\EggPonmp.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ogwrjyho.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\ohyjrwgo.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pxkoltqo.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\oqtlokxp.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jkkhhecy.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\lfyplw.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\zxtvkd.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\iblphz.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\vjvqyj.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\hlcmxdyi.dll (Trojan.Vundo) -> Delete on reboot. C:\System Volume Information\_restore{8CA739E2-8807-4002-B219-92BB43678AC6}\RP13\A0002270.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8CA739E2-8807-4002-B219-92BB43678AC6}\RP5\A0000795.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8CA739E2-8807-4002-B219-92BB43678AC6}\RP5\A0000796.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\djqwkdpn.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\puugja.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\elrfdrrh.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wwecemyt.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tuvTjKCs.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vqjxtena.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:30:02 PM, on 8/5/2008 Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal
HELLO HELLO HELLO....U R GOD FOR ME....THINGS SEEM TO BE FINE AS OF NOW...I WISH I CLD COME AND THANK U PERSONALLY....HAD A CRAZY TIME BECOZ OF THIS...THANK U SO MUCH.
Run a scan with HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any): O2 - BHO: (no name) - {4EC66E48-B863-4413-BC91-463D9CCA093B} - (no file) O2 - BHO: (no name) - {57D26D26-760D-4698-9E16-B71BB10ECABF} - (no file) O2 - BHO: (no name) - {675B0EBA-0501-4944-8C87-AE807B8CB922} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {d72c758f-3553-4310-a5de-edf6aee86eb7} - (no file) O2 - BHO: (no name) - {DBFFE26A-01D1-45C0-AEC2-CDD8D0E5341C} - (no file) O2 - BHO: (no name) - {F6E85A01-68D1-415D-AAE8-684D3193F57E} - (no file)
Currently it is Saturday, November 22, 2008 3:51 PM (GMT +1) There are a total of 64.053 posts in 15.836 threads. In the last 3 days there were 25 new threads and 156 reply posts. View Active Threads
Who's Online
This forum has 27198 registered members. Please welcome our newest member, shahed. 48 Guest(s), 0 Registered Member(s) are currently online. Details