Recently started getting something pop up about WinAntiVirus. Computer also seems to be slow when it probably shouldn't be.
Logfile of HijackThis v1.99.1
Scan saved at 9:32:59 PM, on 11/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Double-click VundoFix.exe to run it.
Click "Scan for Vundo".
Once it's done scanning, click "Remove Vundo".
You will receive a prompt asking if you want to remove the files, click YES.
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post back with contents of C:\vundofix.txt along with a new HijackThis log.
Attempting to delete C:\WINDOWS\system32\atznrwi.dll
C:\WINDOWS\system32\atznrwi.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtutr.dll
C:\WINDOWS\system32\vtutr.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.ini
C:\WINDOWS\system32\rtutv.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.bak1
C:\WINDOWS\system32\rtutv.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.bak2
C:\WINDOWS\system32\rtutv.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.ini2
C:\WINDOWS\system32\rtutv.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.tmp
C:\WINDOWS\system32\rtutv.tmp Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.2.8
Checking Java version...
Java version is 1.5.0.2
Java version is 1.5.0.6
Java version is 1.5.0.7
Java version is 1.5.0.8
Scan started at 4:01:07 PM 11/9/2006
Listing files found while scanning....
No infected files were found.
----------------------------------------------
HJT
----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 4:05:52 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
There's still more Vundo and the scanner isn't picking it out so you'll need to add the file manually.
Double-click VundoFix.exe to run it.
Right click inside the white Window.
Select Add More Files? from the menu that comes up. This will open a new VundoFix window.
In the Window: copy/paste the following in the first field: C:\WINDOWS\SYSTEM32\nnnkkkh.dll Copy/paste the following in the second field: C:\WINDOWS\system32\hkkknnn.* Click the Add Files button.
Click the Close Window button.
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES.
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Download SmitfraudFix.zip to the desktop from here.
* Extract the files to the desktop.
Note: Note: Print or copy these instructions to Notepad and save them. You will be in safe mode and can't access the internet.
* Restart your computer in safe mode(press F8 upon boot, select "Safe Mode" from menu and press Enter).
* Open the SmitFruadFix folder.
* Double-click smitfraudfix.cmd.
* Select 2 and hit Enter to delete infect files.
* You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
* The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
* A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt.
Exit Smitfraudfix and restart in normal mode.
Please post back with the contents of vundofix.txt, the contents of rapport.txt and a new HijackThis log.
Attempting to delete C:\WINDOWS\system32\atznrwi.dll
C:\WINDOWS\system32\atznrwi.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtutr.dll
C:\WINDOWS\system32\vtutr.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.ini
C:\WINDOWS\system32\rtutv.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.bak1
C:\WINDOWS\system32\rtutv.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.bak2
C:\WINDOWS\system32\rtutv.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.ini2
C:\WINDOWS\system32\rtutv.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\rtutv.tmp
C:\WINDOWS\system32\rtutv.tmp Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.2.8
Checking Java version...
Java version is 1.5.0.2
Java version is 1.5.0.6
Java version is 1.5.0.7
Java version is 1.5.0.8
Scan started at 4:01:07 PM 11/9/2006
Listing files found while scanning....
No infected files were found.
VundoFix V6.2.8
Checking Java version...
Java version is 1.5.0.2
Java version is 1.5.0.6
Java version is 1.5.0.7
Java version is 1.5.0.8
Scan started at 6:36:40 PM 11/9/2006
Listing files found while scanning....
Beginning removal...
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\nnnkkkh.dll
C:\WINDOWS\SYSTEM32\nnnkkkh.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\nnnkkkh.dll
C:\WINDOWS\SYSTEM32\nnnkkkh.dll Has been deleted!
Performing Repairs to the registry.
Done!
------------------------------------------------------
rapport
------------------------------------------------------
SmitFraudFix v2.120
Scan done at 19:30:25.81, Thu 11/09/2006
Run from C:\Documents and Settings\Lee Miller\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted
C:\WINDOWS\system32\drvsif.dll FOUND !
C:\WINDOWS\system32\1024\ FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lee Miller
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lee Miller\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\Security Toolbar\ FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
------------------------------------------------------
HJT
------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 7:37:33 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
The popup still exists because there's still more Vundo. There's no 02 or 020 entires, which means the Vundo is hiding them. We'll work on that after you post the new HjT log.
There's still the new Smitfraud file showing. S!ri must have not updated SmitfraudFix to rid and delete the new Smitfraud yet. No worries though, we can delete it manually.
Go to Add/Remove Programs and uninstall(if listed):
Viewpoint Toolbar
Viewpoint Manager
Security Toolbar
Run a scan only with HijackThis, check these(if there):
Logfile of HijackThis v1.99.1
Scan saved at 9:52:01 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Please disable Windows Defender. It may interfere with the fixes. You may re-enable it after these fixes are complete.
Open Windows Defender.
Click on Tools > General Settings.
Scroll down and uncheck "Turn on real-time protection (recommended)".
After you unchecking click "Save" and close Windows Defender.
Add this file to VundoFix just as you did the other:
First line: C:\WINDOWS\system32\awtsr.dll Second line: C:\WINDOWS\system32\rstwa.*
After the reboot fix these with HijackThis(if there). Be sure to close all other windows before clicking "Fix checked".
Then, run an online scan to make sure there are no other infections.
Go here to run Kaspersky Online Scanner.
After downloading, click "My Computer" to scan.
After scanning, click "Save report as".
Save as a text file on the desktop.
Post the log in your next reply.
Friday, November 10, 2006 1:21:02 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 10/11/2006
Kaspersky Anti-Virus database records: 226065
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 87126
Number of viruses found 0
Number of infected objects 0 / 0
Number of suspicious objects 0
Duration of the scan process 02:24:49
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\WDLog-06012006-191919.log Object is locked skipped
C:\Documents and Settings\Lee Miller\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Application Data\ApplicationHistory\CLI.EXE.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\History\History.IE5\MSHist012006110920061110\index.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Temp\Perflib_Perfdata_95c.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Temp\Perflib_Perfdata_d38.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Temp\Perflib_Perfdata_d40.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\ntuser.dat Object is locked skipped
C:\Documents and Settings\Lee Miller\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BA5DAB6F-C55D-4FB1-868D-03ECB99A2700}\RP832\A0145630.dll Object is locked skipped
C:\System Volume Information\_restore{BA5DAB6F-C55D-4FB1-868D-03ECB99A2700}\RP840\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{9996DBD4-0640-4341-ACBD-86930BB90302}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_7ac.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Clear your System Restore and create a new restore point.
Turn off System Restore.
Right click My Computer > Properties > System Restore tab > check "Turn off System Restore".
Click Apply, then OK.
Restart then turn System Restore back on.