

I've somehow managed to acquire the Trojan.Vundo.DVS virus, and it's giving me fits! Originally, the only inconvenience was that BitDefender would pop up every minute letting me know that it had blocked the virus from infecting my computer, but now, that annoyance has stopped, and instead I get pummelled with pop-ups whenever I'm browsing the internet (FireFox & IE7).

I've run various BitDefender scans multiple times, and I've run VundoFix a couple of times as well, but to no avail. I no longer know what to do other than ask for help!

I’ve seen a number of posts on this issue, and would seem that the best course of action for me to take is to post my SilentRunners and HijackThis logs for review. So, that’s what I’m going to do.

I will paste my results in the next couple of posts.

Any help you can offer would be GREATLY appreciated!



  • "Silent Runners.vbs", revision 56,

    Operating System: Windows XP SP2

    Output limited to non-default values, except where indicated by "{++}"

    Startup items buried in registry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

    "(Default)" = (empty string) [file not found]

    "StartCCC" = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [null data]

    "uTorrent" = ""C:\Program Files\uTorrent\uTorrent.exe"" [null data]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

    "BDMCon" = "C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" ["SOFTWIN S.R.L."]

    "BDAgent" = ""C:\Program Files\Softwin\BitDefender10\bdagent.exe"" ["SOFTWIN S.R.L."]

    "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]

    "NeroFilterCheck" = "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" ["Nero AG"]

    "InCD" = "C:\Program Files\Nero\Nero 7\InCD\InCD.exe" ["Nero AG"]

    "CTHelper" = "CTHELPER.EXE" ["Creative Technology Ltd"]

    "CTxfiHlp" = "CTXFIHLP.EXE" ["Creative Technology Ltd"]

    "QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ["Apple Inc."]

    "Acrobat Assistant 8.0" = ""C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"" ["Adobe Systems Inc."]

    "(Default)" = (empty string) [file not found]

    "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"" ["Sun Microsystems, Inc."]

    "04bf8c0e" = "rundll32.exe "C:\WINDOWS\system32\orrodoup.dll",b" [MS]

    "BM078cbf92" = "Rundll32.exe "C:\WINDOWS\system32\fgwyynnv.dll",s" [MS]

    HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\

    >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"

    \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

    {00C6482D-C502-44C8-8409-FCE54AD9C208}\(Default) = (no title provided)

    -> {HKLM...CLSID} = "SnagIt Toolbar Loader"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SNA335~1.DLL" ["TechSmith Corporation"]

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)

    -> {HKLM...CLSID} = "SSVHelper Class"

    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."]

    {c29e5bbf-37e4-48f9-8e46-e9a231aae9ce}\(Default) = "{ec9eaa13-2a9e-64e8-9f84-4e73fbb5e92c}"

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\WINDOWS\system32\udfilorc.dll" [null data]

    {CA57FAAB-5A1C-4FD4-B660-E2C684E8354E}\(Default) = (no title provided)

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\WINDOWS\system32\iifdaYom.dll" [null data]

    {CE86878F-D099-4FFC-A4DC-E51D192063B1}\(Default) = (no title provided)

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\WINDOWS\system32\cbXQkiji.dll" [null data]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"

    -> {HKLM...CLSID} = "Display Panning CPL Extension"

    \InProcServer32\(Default) = "deskpan.dll" [file not found]

    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"

    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]

    "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"

    -> {HKLM...CLSID} = "Microsoft Office Outlook"

    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]

    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"

    -> {HKLM...CLSID} = "Outlook File Icon Extension"

    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]

    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]

    "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" = "SnagIt"

    -> {HKLM...CLSID} = "SnagIt"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SNAGIT~4.DLL" ["TechSmith Corporation"]

    "{CF74B903-3389-469c-B3B6-0204D204FCBD}" = "SnagIt Shell Extension"

    -> {HKLM...CLSID} = "SnagItShellExt Class"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SN17E1~1.DLL" ["TechSmith Corporation"]

    "{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"

    -> {HKLM...CLSID} = "SimpleShlExt Class"

    \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [empty string]

    "{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}" = "NeroCoverEd Live Icons"

    -> {HKLM...CLSID} = "NeroCoverEdLiveIcons Class"

    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]

    "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"

    -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"

    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]

    "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"

    -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"

    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]

    "{46E22146-59C0-4136-9233-FB7720E777B2}" = "EzCddax extension"

    -> {HKLM...CLSID} = "EzCddax Class"

    \InProcServer32\(Default) = "C:\Program Files\Easy CD-DA Extractor\ezcddax10.dll" [null data]

    "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"

    -> {HKLM...CLSID} = "My Sharing Folders"

    \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]

    "{23170F69-40C1-278A-1000-000100020000}" = "7-Zip Shell Extension"

    -> {HKLM...CLSID} = "7-Zip Shell Extension"

    \InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

    "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}" = "Adobe.Acrobat.ContextMenu"

    -> {HKLM...CLSID} = "Acrobat Elements Context Menu"

    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll" ["Adobe Systems Inc."]


    <<!>> "{CE86878F-D099-4FFC-A4DC-E51D192063B1}" = "*n" (unwritable string)

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\WINDOWS\system32\cbXQkiji.dll" [null data]


    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

    -> {HKLM...CLSID} = "WPDShServiceObj Class"

    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]


    <<!>> "Authentication Packages" = "msv1_0"|"C:\WINDOWS\system32\iifdaYom"

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

    <<!>> cbXQkiji\DLLName = "cbXQkiji.dll" [null data]


    <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"

    -> {HKLM...CLSID} = (no title provided)

    \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]


    {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"

    -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"

    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]

    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"

    -> {HKLM...CLSID} = "PDF Shell Extension"

    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"

    -> {HKLM...CLSID} = "7-Zip Shell Extension"

    \InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

    Adobe.Acrobat.ContextMenu\(Default) = "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"

    -> {HKLM...CLSID} = "Acrobat Elements Context Menu"

    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll" ["Adobe Systems Inc."]

    Cover Designer\(Default) = "{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}"

    -> {HKLM...CLSID} = "NeroCoverEdContextMenu Class"

    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]

    EzCddax\(Default) = "{46E22146-59C0-4136-9233-FB7720E777B2}"

    -> {HKLM...CLSID} = "EzCddax Class"

    \InProcServer32\(Default) = "C:\Program Files\Easy CD-DA Extractor\ezcddax10.dll" [null data]

    SnagItMainShellExt\(Default) = "{CF74B903-3389-469c-B3B6-0204D204FCBD}"

    -> {HKLM...CLSID} = "SnagItShellExt Class"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SN17E1~1.DLL" ["TechSmith Corporation"]


    7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"

    -> {HKLM...CLSID} = "7-Zip Shell Extension"

    \InProcServer32\(Default) = "C:\Program Files\7-Zip\7-zip.dll" ["Igor Pavlov"]

    SnagItMainShellExt\(Default) = "{CF74B903-3389-469c-B3B6-0204D204FCBD}"

    -> {HKLM...CLSID} = "SnagItShellExt Class"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SN17E1~1.DLL" ["TechSmith Corporation"]


    Adobe.Acrobat.ContextMenu\(Default) = "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"

    -> {HKLM...CLSID} = "Acrobat Elements Context Menu"

    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll" ["Adobe Systems Inc."]

    Group Policies {GPedit.msc branch and setting}:


    Note: detected settings may not have any effect.


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001

    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

    Shutdown: Allow system to be shut down without having to log on}

    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001

    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

    Devices: Allow undock without having to log on}

    Active Desktop and Wallpaper:


    Active Desktop may be disabled at this entry:


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

    "Wallpaper" = "%APPDATA%\Mozilla\Firefox\Desktop Background.bmp"

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

    HKCU\Control Panel\Desktop\

    "Wallpaper" = "C:\Documents and Settings\Scott Wyatt\Application Data\Mozilla\Firefox\Desktop Background.bmp"

    Startup items in "Scott Wyatt" & "All Users" startup folders:


    C:\Documents and Settings\Scott Wyatt\Start Menu\Programs\Startup

    "Adobe Gamma" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]

    Enabled Scheduled Tasks:


    "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."]

    Winsock2 Service Provider DLLs:


    Namespace Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

    000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" [null data]

    Transport Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13

    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

    Toolbars, Explorer Bars, Extensions:



    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\

    "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" = (no title provided)

    -> {HKLM...CLSID} = "SnagIt"

    \InProcServer32\(Default) = "C:\PROGRA~1\TECHSM~1\SNAGIT~1\SNAGIT~4.DLL" ["TechSmith Corporation"]

    Explorer Bars

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\

    HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research"

    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]

    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    "MenuText" = "Sun Java Console"

    "CLSIDExtension" = "{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}"

    -> {HKCU...CLSID} = "Java Plug-in 1.6.0_05"

    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."]

    -> {HKLM...CLSID} = "Java Plug-in 1.6.0_05"

    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll" ["Sun Microsystems, Inc."]


    "ButtonText" = "Research"


    "MenuText" = "@xpsp3res.dll,-20001"

    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]


    "ButtonText" = "Messenger"

    "MenuText" = "Messenger"

    "Exec" = "C:\Program Files\Messenger\MSMSGS.EXE" [MS]

    Running Services (Display Name, Service Name, Path {Service DLL}):


    Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]

    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service" ["SOFTWIN S.R.L"]

    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service" ["SOFTWIN S.R.L."]

    BitDefender Scan Server, bdss, ""C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service" [null data]

    BitDefender Virus Shield, VSSERV, ""C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service" ["SOFTWIN S.R.L."]

    FLEXnet Licensing Service, FLEXnet Licensing Service, ""C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"" ["Macrovision Europe Ltd."]

    InCD Helper, InCDsrv, "C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe" ["Nero AG"]

    LightScribeService Direct Disc Labeling Service, LightScribeService, ""C:\Program Files\Common Files\LightScribe\LSSrvc.exe"" ["Hewlett-Packard Company"]

    StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]

    Print Monitors:



    Adobe PDF Port\Driver = "C:\WINDOWS\system32\AdobePDF.dll" ["Adobe Systems Incorporated."]

    Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]

    ---------- (launch time: 2008-05-07 11:44:47)

    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.

    + To see *everywhere* the ****** checks and *everything* it finds,

    launch it from a command prompt or a shortcut with the -all parameter.

    + To search all directories of local fixed drives for DESKTOP.INI

    DLL launch points, use the -supp parameter or answer "No" at the

    first message box and "Yes" at the second message box.

    ---------- (total run time: 57 seconds, including 11 seconds for message boxes)

  • Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:44:18 AM, on 07/05/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16640)

    Boot mode: Normal

    Running processes:










    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe

    C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

    C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe


    C:\Program Files\Softwin\BitDefender10\bdmcon.exe

    C:\Program Files\Softwin\BitDefender10\bdagent.exe

    C:\Program Files\Nero\Nero 7\InCD\InCD.exe


    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe




    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe

    C:\Program Files\Softwin\BitDefender10\vsserv.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\PROGRA~1\TECHSM~1\SNAGIT~1\SNAGIT~4.DLL

    O4 - HKLM\..\Run: [bDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe

    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"

    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [inCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe

    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    O4 - HKLM\..\Run: [04bf8c0e] rundll32.exe "C:\WINDOWS\system32\orrodoup.dll",b

    O4 - HKLM\..\Run: [bM078cbf92] Rundll32.exe "C:\WINDOWS\system32\fgwyynnv.dll",s

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -

    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -

    O17 - HKLM\System\CCS\Services\Tcpip\..\{EF146F02-089A-40F4-AECF-F85ECC367F59}: NameServer =

    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe

    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe

    O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    End of file - 7394 bytes

  • Okay... things have worsened!

    Now when I boot my computer I can view my wallpaper, but the desktop icons and task bar never appear. I can ctrl-alt-del in order to bring up the task manager, but I can’t use keyboard commands to do anything else. Even right-clicking on the desktop has no effect.

    Fortunately, I can still boot properly in safe mode, but to the best of my knowledge I can’t run BitDefender in safe mode.

    Please help! I use my computer to work from home and I can’t afford to have it out of commission!

    Thanks in advance.

  • 1. Please upload these files in a zip folder with the password "infected" here.



    2. Run Hijackthis, check and fix the following:

    O4 - HKLM\..\Run: [04bf8c0e] rundll32.exe "C:\WINDOWS\system32\orrodoup.dll",b
    O4 - HKLM\..\Run: [BM078cbf92] Rundll32.exe "C:\WINDOWS\system32\fgwyynnv.dll",s
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)

    3. Download ComboFix.

    4. Run ComboFix and Hijackthis and post the output of both logs on your next reply.

  • Hello,

    I've somehow managed to acquire the Trojan.Vundo.DVS virus, and it's giving me fits! Originally, the only inconvenience was that BitDefender would pop up every minute letting me know that it had blocked the virus from infecting my computer, but now, that annoyance has stopped, and instead I get pummelled with pop-ups whenever I'm browsing the internet (FireFox & IE7).

    I've run various BitDefender scans multiple times, and I've run VundoFix a couple of times as well, but to no avail. I no longer know what to do other than ask for help!

    I've seen a number of posts on this issue, and would seem that the best course of action for me to take is to post my SilentRunners and HijackThis logs for review. So, that's what I'm going to do.

    I will paste my results in the next couple of posts.

    Any help you can offer would be GREATLY appreciated!


    plzzz help

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 5:05:27 PM, on 5/10/2008

    Platform: Windows Vista (WinNT 6.00.1904)

    MSIE: Internet Explorer v7.00 (7.00.6000.16643)

    Boot mode: Normal

    Running processes:




    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe



    C:\Program Files\PowerISO\PWRISOVM.EXE


    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\CursorXP\CursorXP.exe


    C:\Program Files\Java\jre1.6.0_05\bin\javaw.exe




    C:\Program Files\BitDefender\BitDefender 2008\seccenter.exe







    C:\Program Files\Internet Explorer\ieuser.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O1 - Hosts: ::1 localhost

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll

    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

    O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

    O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m

    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"

    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\efcCuuTL.dll,#1

    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe

    O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\ALEXSI~1\AppData\Local\Temp\mlJCUKeE.dll,#1

    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\ALEXSI~1\AppData\Local\Temp\pmnlkKbC.dll,c

    O4 - HKCU\..\Run: [4ab677f6] rundll32.exe "C:\Users\ALEXSI~1\AppData\Local\Temp\kbfytvts.dll",b

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O4 - Global Startup: MP3 Rocket (Minimized).lnk = C:\Program Files\MP3 Rocket\MP3Rocket.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

    O13 - Gopher Prefix:

    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) -

    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

    O23 - Service: dlba_device - - C:\Windows\system32\dlbacoms.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe

    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe

    O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe

    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

    O23 - Service: SCM_Service - Unknown owner - C:\WINDOWS\System32\WinService.exe

    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    End of file - 11209 bytes

    help and teachme what to do plz

  • 1. Please upload these files in a zip folder with the password "infected" here






    2. Run Hijackthis, check and fix the following:

    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\efcCuuTL.dll,#1
    O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\ALEXSI~1\AppData\Local\Temp\mlJCUKeE.dll,#1
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\ALEXSI~1\AppData\Local\Temp\pmnlkKbC.dll,c
    O4 - HKCU\..\Run: [4ab677f6] rundll32.exe "C:\Users\ALEXSI~1\AppData\Local\Temp\kbfytvts.dll",b
    O23 - Service: dlba_device - - C:\Windows\system32\dlbacoms.exe

    3. Download ComboFix

    4. Run ComboFix and Hijackthis and post the output of both logs on your next reply.

  • O1 - Hosts: ::1 localhost

    Just curious: I didn't look at other entries you asked to fix. why are you fixing this one?

  • farbar
    edited May 2008

    After two days still no reply. So I took a look at other entries to be fixed. Therefore the question is what type of malware is the following entry?

    O23 - Service: dlba_device - - C:\Windows\system32\dlbacoms.exe
  • I apologize for the delay in my response, but as a follow-up...

    My computer was essentially “done” after this infection took hold. I ended-up formatting my hard drive, and I had to reinstall every program I had on my computer prior to the infection.

    Hopefully, BitDefender will work out this issue shortly so that the rest of you don’t have to go through the same gauntlet of crap I had to go through just to get my computer up and running again.