Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Another Kernel 1256/vundo Infection- Help Please

Options

Hi everyone-


My laptop seems to be suffering from the same Vundo/Kernel 1256 infection that has been plaguing other people around here. I ran Vundo Fix, and it was able to remove some (but not all) of the .dll files. I've got symptoms similar to many of the other cases- 2 Windows Update icons on my desktop that won't delete, as well as a bucket load of posxxx files in my c: directory. I've downloaded Hijackthis- here's what my log looks like:


Logfile of Trend Micro HijackThis v2.0.2


Scan saved at 11:40:11 PM, on 2/8/2008


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Boot mode: Normal


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\Program Files\Intel\Wireless\Bin\EvtEng.exe


C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe


C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe


C:\Program Files\Common Files\Symantec Shared\ccProxy.exe


C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe


C:\Program Files\Norton Internet Security\ISSVC.exe


C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe


C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\system32\AvidSDMService.exe


C:\Program Files\Bonjour\mDNSResponder.exe


C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe


C:\Program Files\Digidesign\Drivers\MMERefresh.exe


C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE


C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe


C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe


C:\WINDOWS\system32\svchost.exe


C:\Program Files\Viewpoint\Common\ViewpointService.exe


C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe


C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe


C:\WINDOWS\Explorer.EXE


C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe


C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe


C:\WINDOWS\system32\wuauclt.exe


C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe


C:\WINDOWS\system32\dla\tfswctrl.exe


C:\Program Files\Common Files\Symantec Shared\ccApp.exe


C:\WINDOWS\system32\hkcmd.exe


C:\WINDOWS\system32\igfxpers.exe


C:\WINDOWS\system32\igfxsrvc.exe


C:\WINDOWS\system32\NWTRAY.EXE


C:\Program Files\QuickTime\qttask.exe


C:\Program Files\Common Files\Real\Update_OB\realsched.exe


C:\Program Files\Messenger\msmsgs.exe


C:\WINDOWS\system32\ctfmon.exe


C:\Program Files\Skype\Phone\Skype.exe


C:\Program Files\Digital Line Detect\DLG.exe


C:\Program Files\Mozilla Firefox\firefox.exe


C:\Program Files\Skype\Plugin Manager\skypePM.exe


C:\WINDOWS\system32\rundll32.exe


C:\WINDOWS\system32\rundll32.exe


C:\WINDOWS\system32\rundll32.exe


C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.middlebury.edu/


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local


O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll


O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll


O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe


O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


O4 - HKLM\..\Run: [intelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless


O4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r


O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe


O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"


O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer


O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe


O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe


O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe


O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe


O4 - HKLM\..\Run: [e808fde4] rundll32.exe "C:\WINDOWS\system32\nrfdnxcy.dll",b


O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized


O4 - Global Startup: Digital Line Detect.lnk = ?


O4 - Global Startup: VPN Client.lnk = ?


O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe


O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204


O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx


O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://nav.middlebury.edu/sav/webinst.cab


O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL


O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe


O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe


O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe


O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe


O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe


O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe


O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe


O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe


O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe


O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe


O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe


O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe


O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe


O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Nick\LOCALS~1\Temp\hpdj.exe (file missing)


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe


O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe


O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe


O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe


O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe


O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe


O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe


O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\******~1\SBServ.exe


O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe


O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe


O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


Any thoughts on this? I'm ready to run Vundo Fix again if necessary, and I think I'll probably have to run one or two other pieces of software to fix this issue. Thanks for your help!

Comments

  • It seems that this file could be a Trojan.Vundo one : C:\WINDOWS\system32\nrfdnxcy.dll


    Although given missing this file could be on disk : C:\DOCUME~1\Nick\LOCALS~1\Temp\hpdj.exe


    Take these actions :


    1. Download BitDefender Malware Remover : http://students.info.uaic.ro/~daniel.chipi...BDAspySetup.exe


    2. After install and scan, look into the "On Demand" tab and give the mentioned files as path with the option "remove all traces", if that doesn't work then try it with the option "force remove".


    3. Try to delete this registry key from services : "HKLM\SYSTEM\CurrentControlSet\Services\hpdj"


    Tell me if it did the job. ;)

  • Downloaded BDASpy and performed scan- nothing found. Should I try a deep scan?


    After the scan, entered paths of both the nrfdnxcy.dll and the hpdj.exe for removal- program said that the clean-up was successful. For insurance, I tried a "force delete" of both files. When I re-booted, I got a message saying the force delete failed, but clean-up was successful.


    Deleted the hpdj from registry key services and re-booted...hpdj is gone from the registry, but it appears that I'm still having problems. Got a pair of error messages relating to Kernel 1256 when I re-booted, and also, the quick launch icons on my taskbar seem to have disappeared. Strange.


    Any thoughts on what to do next? Can post another Hijackthis or Vundofix log if necessary.