It looks like the infection persists, apparently the vundo thing is creating different file names on the fly. here is a link to symantec's vundo removal tool http://www.symantec.com/security_res...112210-3747-99
Get it and save it somewhere easy to remember, restart the computer in safemode; Run Mbam again after rebooting into safemode, to check if it deleted the files listed in the log as "delete on reboot" as per the instructions in the sticky; rebooting into safemode with restore disabled; after re-running Mbam, to check the files, or remove additional infections, rebooting and go back into safemode, run the symantec vundo removal tool, when it finishes, check to see if there is a report on what it did; try to save it or copy and paste it into notepad and save it as symantec.txt; reboot again into safemode and run hijack this, if you see the following entries; "these are from your HJT log above"
O4 - HKLM\..\Run: [Yqebebeva] rundll32.exe "C:\WINDOWS\orohucopojehu.dll",e
O4 - HKUS\S-1-5-19\..\Run: [sijafokayu] Rundll32.exe "C:\WINDOWS\system32\tiseviho.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [sijafokayu] Rundll32.exe "C:\WINDOWS\system32\tiseviho.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Shelby\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
Check the boxes next to them and have hijack this fix them.
Then reboot into normal mode and run MBAm, save a log, Hijackthis again and save another hijackthis log, then repost the symantec.txt, mbam log and hijackthis log.


Reply With Quote