This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Winfixer and Trojan.Vundo

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having major problems with the WinFixer adware and have now gotten a Trojan.vundo alert showing up on Norton Antivirus. I have tried the trojan removal tool and it is useless. The file that was identified by Norton was bakvb.dll. I tried deleting it to no avail.


My Hijackthis log is appended below. I would greatly appreciate your help.

Logfile of HijackThis v1.99.1
Scan saved at 9:03:10 PM, on 10/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\ehome\ehtray.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\ehome\ehSched.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\ehome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - (no file)
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINNT\Cursors\bakvb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINNT\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://support.gateway.com/eSupport/static…h/weblaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O20 - Winlogon Notify: bakvb - C:\WINNT\Cursors\bakvb.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Copy the text in the following quote box into Notepad:

dir C:\WINNT\Cursors\ /ah > files.txt
dir C:\WINNT\Cursors\ >> files.txt
notepad files.txt

Save it to your desktop as ff.bat.

Close Notepad

Now, the ff.bat file on the desktop.

Wait for a Notepad window to open up.

Please paste it's contents into your next post.

Run Hijack This!

Click the "Open the Misc Tools section" button.

Click the "Open process manager" button.

Check the "Show DLLs" box (upper right).

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using C:\WINNT\Cursors\bakvb.dll

Post back letting me know all processes using that DLL.
Thank you for doing this!!! Here is the information you requested.

Logfile of HijackThis v1.99.1
Scan saved at 12:11:39 AM, on 10/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\ehome\ehtray.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\ehome\ehSched.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\ehome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - (no file)
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINNT\Cursors\bakvb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINNT\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://support.gateway.com/eSupport/static…h/weblaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O20 - Winlogon Notify: bakvb - C:\WINNT\Cursors\bakvb.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


The file that shows up on the show dll is:
c:\winnt\system32\ntdll.dll


The results of the FF.BAT are:
Volume in drive C has no label.
Volume Serial Number is 0C23-97B1

Directory of C:\WINNT\Cursors

10/12/2005 06:19 AM 359,816 bvkab.bak1
10/13/2005 08:33 PM 344,430 bvkab.bak2
09/19/2005 09:56 PM 423,591 bvkab.ini
10/14/2005 12:07 AM 345,740 bvkab.ini2
09/19/2005 09:56 PM 422,744 bvkab.tmp
5 File(s) 1,896,321 bytes
0 Dir(s) 56,607,768,576 bytes free
Volume in drive C has no label.
Volume Serial Number is 0C23-97B1

Directory of C:\WINNT\Cursors

10/14/2005 12:07 AM .
10/14/2005 12:07 AM ..
03/31/2003 08:00 AM 766 3dgarro.cur
03/31/2003 08:00 AM 766 3dgmove.cur
03/31/2003 08:00 AM 766 3dgnesw.cur
03/31/2003 08:00 AM 766 3dgno.cur
03/31/2003 08:00 AM 766 3dgns.cur
03/31/2003 08:00 AM 766 3dgnwse.cur
03/31/2003 08:00 AM 766 3dgwe.cur
03/31/2003 08:00 AM 766 3dsmove.cur
03/31/2003 08:00 AM 766 3dsns.cur
03/31/2003 08:00 AM 766 3dsnwse.cur
03/31/2003 08:00 AM 766 3dwarro.cur
03/31/2003 08:00 AM 766 3dwmove.cur
03/31/2003 08:00 AM 766 3dwnesw.cur
03/31/2003 08:00 AM 766 3dwno.cur
03/31/2003 08:00 AM 766 3dwns.cur
03/31/2003 08:00 AM 766 3dwnwse.cur
03/31/2003 08:00 AM 766 3dwwe.cur
03/31/2003 08:00 AM 7,962 appstar2.ani
03/31/2003 08:00 AM 7,856 appstar3.ani
03/31/2003 08:00 AM 7,954 appstart.ani
03/31/2003 08:00 AM 326 arrow_i.cur
03/31/2003 08:00 AM 766 arrow_il.cur
03/31/2003 08:00 AM 766 arrow_im.cur
03/31/2003 08:00 AM 766 arrow_l.cur
03/31/2003 08:00 AM 766 arrow_m.cur
03/31/2003 08:00 AM 326 arrow_r.cur
03/31/2003 08:00 AM 766 arrow_rl.cur
03/31/2003 08:00 AM 766 arrow_rm.cur
08/29/2005 07:02 PM 516,116 bakvb.dll
03/31/2003 08:00 AM 11,904 banana.ani
03/31/2003 08:00 AM 8,660 barber.ani
03/31/2003 08:00 AM 326 beam_i.cur
03/31/2003 08:00 AM 766 beam_il.cur
03/31/2003 08:00 AM 766 beam_im.cur
03/31/2003 08:00 AM 766 beam_l.cur
03/31/2003 08:00 AM 766 beam_m.cur
03/31/2003 08:00 AM 326 beam_r.cur
03/31/2003 08:00 AM 766 beam_rl.cur
03/31/2003 08:00 AM 766 beam_rm.cur
03/31/2003 08:00 AM 326 busy_i.cur
03/31/2003 08:00 AM 766 busy_il.cur
03/31/2003 08:00 AM 766 busy_im.cur
03/31/2003 08:00 AM 766 busy_l.cur
03/31/2003 08:00 AM 766 busy_m.cur
03/31/2003 08:00 AM 326 busy_r.cur
03/31/2003 08:00 AM 766 busy_rl.cur
03/31/2003 08:00 AM 766 busy_rm.cur
03/31/2003 08:00 AM 7,114 coin.ani
03/31/2003 08:00 AM 6,832 counter.ani
03/31/2003 08:00 AM 766 cross.cur
03/31/2003 08:00 AM 326 cross_i.cur
03/31/2003 08:00 AM 766 cross_il.cur
03/31/2003 08:00 AM 766 cross_im.cur
03/31/2003 08:00 AM 766 cross_l.cur
03/31/2003 08:00 AM 766 cross_m.cur
03/31/2003 08:00 AM 326 cross_r.cur
03/31/2003 08:00 AM 766 cross_rl.cur
03/31/2003 08:00 AM 766 cross_rm.cur
03/31/2003 08:00 AM 4,804 dinosau2.ani
03/31/2003 08:00 AM 4,804 dinosaur.ani
03/31/2003 08:00 AM 3,240 drum.ani
03/31/2003 08:00 AM 14,936 fillitup.ani
03/31/2003 08:00 AM 3,292 hand.ani
03/31/2003 08:00 AM 6,356 handapst.ani
03/31/2003 08:00 AM 1,700 handnesw.ani
03/31/2003 08:00 AM 4,066 handno.ani
03/31/2003 08:00 AM 1,698 handns.ani
03/31/2003 08:00 AM 1,700 handnwse.ani
03/31/2003 08:00 AM 7,530 handwait.ani
03/31/2003 08:00 AM 1,698 handwe.ani
03/31/2003 08:00 AM 766 harrow.cur
03/31/2003 08:00 AM 766 hcross.cur
03/31/2003 08:00 AM 326 help_i.cur
03/31/2003 08:00 AM 766 help_il.cur
03/31/2003 08:00 AM 766 help_im.cur
03/31/2003 08:00 AM 766 help_l.cur
03/31/2003 08:00 AM 766 help_m.cur
03/31/2003 08:00 AM 326 help_r.cur
03/31/2003 08:00 AM 766 help_rl.cur
03/31/2003 08:00 AM 766 help_rm.cur
03/31/2003 08:00 AM 766 hibeam.cur
03/31/2003 08:00 AM 766 hmove.cur
03/31/2003 08:00 AM 766 hnesw.cur
03/31/2003 08:00 AM 766 hnodrop.cur
03/31/2003 08:00 AM 766 hns.cur
03/31/2003 08:00 AM 766 hnwse.cur
03/31/2003 08:00 AM 18,722 horse.ani
03/31/2003 08:00 AM 11,832 hourgla2.ani
03/31/2003 08:00 AM 11,830 hourgla3.ani
03/31/2003 08:00 AM 11,824 hourglas.ani
03/31/2003 08:00 AM 766 hwe.cur
03/31/2003 08:00 AM 766 lappstrt.cur
03/31/2003 08:00 AM 766 larrow.cur
03/31/2003 08:00 AM 766 lcross.cur
03/31/2003 08:00 AM 766 libeam.cur
03/31/2003 08:00 AM 766 lmove.cur
03/31/2003 08:00 AM 766 lnesw.cur
03/31/2003 08:00 AM 766 lnodrop.cur
03/31/2003 08:00 AM 766 lns.cur
03/31/2003 08:00 AM 766 lnwse.cur
03/31/2003 08:00 AM 766 lwait.cur
03/31/2003 08:00 AM 766 lwe.cur
10/11/2005 06:18 AM 200 mcrh.tmp
03/31/2003 08:00 AM 5,674 metronom.ani
03/31/2003 08:00 AM 326 move_i.cur
03/31/2003 08:00 AM 766 move_il.cur
03/31/2003 08:00 AM 766 move_im.cur
03/31/2003 08:00 AM 766 move_l.cur
03/31/2003 08:00 AM 766 move_m.cur
03/31/2003 08:00 AM 326 move_r.cur
03/31/2003 08:00 AM 766 move_rl.cur
03/31/2003 08:00 AM 766 move_rm.cur
03/31/2003 08:00 AM 326 no_i.cur
03/31/2003 08:00 AM 766 no_il.cur
03/31/2003 08:00 AM 766 no_im.cur
03/31/2003 08:00 AM 766 no_l.cur
03/31/2003 08:00 AM 766 no_m.cur
03/31/2003 08:00 AM 326 no_r.cur
03/31/2003 08:00 AM 766 no_rl.cur
03/31/2003 08:00 AM 766 no_rm.cur
03/31/2003 08:00 AM 326 pen_i.cur
03/31/2003 08:00 AM 766 pen_il.cur
03/31/2003 08:00 AM 766 pen_im.cur
03/31/2003 08:00 AM 766 pen_l.cur
03/31/2003 08:00 AM 766 pen_m.cur
03/31/2003 08:00 AM 326 pen_r.cur
03/31/2003 08:00 AM 766 pen_rl.cur
03/31/2003 08:00 AM 766 pen_rm.cur
03/31/2003 08:00 AM 4,100 piano.ani
03/31/2003 08:00 AM 9,824 rainbow.ani
03/31/2003 08:00 AM 4,826 raindrop.ani
03/31/2003 08:00 AM 326 size1_i.cur
03/31/2003 08:00 AM 766 size1_il.cur
03/31/2003 08:00 AM 766 size1_im.cur
03/31/2003 08:00 AM 766 size1_l.cur
03/31/2003 08:00 AM 766 size1_m.cur
03/31/2003 08:00 AM 326 size1_r.cur
03/31/2003 08:00 AM 766 size1_rl.cur
03/31/2003 08:00 AM 766 size1_rm.cur
03/31/2003 08:00 AM 326 size2_i.cur
03/31/2003 08:00 AM 766 size2_il.cur
03/31/2003 08:00 AM 766 size2_im.cur
03/31/2003 08:00 AM 766 size2_l.cur
03/31/2003 08:00 AM 766 size2_m.cur
03/31/2003 08:00 AM 326 size2_r.cur
03/31/2003 08:00 AM 766 size2_rl.cur
03/31/2003 08:00 AM 766 size2_rm.cur
03/31/2003 08:00 AM 326 size3_i.cur
03/31/2003 08:00 AM 766 size3_il.cur
03/31/2003 08:00 AM 766 size3_im.cur
03/31/2003 08:00 AM 766 size3_l.cur
03/31/2003 08:00 AM 766 size3_m.cur
03/31/2003 08:00 AM 326 size3_r.cur
03/31/2003 08:00 AM 766 size3_rl.cur
03/31/2003 08:00 AM 766 size3_rm.cur
03/31/2003 08:00 AM 326 size4_i.cur
03/31/2003 08:00 AM 766 size4_il.cur
03/31/2003 08:00 AM 766 size4_im.cur
03/31/2003 08:00 AM 766 size4_l.cur
03/31/2003 08:00 AM 766 size4_m.cur
03/31/2003 08:00 AM 326 size4_r.cur
03/31/2003 08:00 AM 766 size4_rl.cur
03/31/2003 08:00 AM 766 size4_rm.cur
03/31/2003 08:00 AM 818 sizenesw.ani
03/31/2003 08:00 AM 818 sizens.ani
03/31/2003 08:00 AM 818 sizenwse.ani
03/31/2003 08:00 AM 818 sizewe.ani
03/31/2003 08:00 AM 6,712 stopwtch.ani
03/31/2003 08:00 AM 326 up_i.cur
03/31/2003 08:00 AM 326 up_il.cur
03/31/2003 08:00 AM 326 up_im.cur
03/31/2003 08:00 AM 766 up_l.cur
03/31/2003 08:00 AM 766 up_m.cur
03/31/2003 08:00 AM 326 up_r.cur
03/31/2003 08:00 AM 326 up_rl.cur
03/31/2003 08:00 AM 326 up_rm.cur
03/31/2003 08:00 AM 1,894 vanisher.ani
03/31/2003 08:00 AM 2,548 wagtail.ani
03/31/2003 08:00 AM 326 wait_i.cur
03/31/2003 08:00 AM 766 wait_il.cur
03/31/2003 08:00 AM 766 wait_im.cur
03/31/2003 08:00 AM 766 wait_l.cur
03/31/2003 08:00 AM 766 wait_m.cur
03/31/2003 08:00 AM 326 wait_r.cur
03/31/2003 08:00 AM 766 wait_rl.cur
03/31/2003 08:00 AM 766 wait_rm.cur
186 File(s) 824,300 bytes
2 Dir(s) 56,607,752,192 bytes free
Please print these instructions out for use in Safe Mode.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to extract the files
  • This will create a VundoFix folder on your desktop.
  • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
  • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
  • You will first be presented with a warning and a list of forums to seek help at.
    it should look like this

    VundoFix V2.1 by Atri
    By pressing enter you agree that you are using this at your own risk
    Please seek assistance at one of the following forums:
    http://www.atribune.org/forums
    http://www.247fixes.com/forums
    http://www.geekstogo.com/forum
    http://forums.net-integration.net


  • At this point press enter one time.

  • Next you will see:

    Type in the filepath as instructed by the forum staff
    Then Press Enter, Then F6, Then Enter Again to continue with the fix.

  • At this point please type the following file path (make sure to enter it exactly as below!):
    • C:\WINNT\Cursors\bakvb.dll
  • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
  • Next you will see:

    Please type in the second filepath as instructed by the forum staff
    Then Press Enter, Then F6, Then Enter Again to continue with the fix.

  • At this point please type the following file path (make sure to enter it exactly as below!):C:\WINNT\Cursors\bvkab.*
  • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
  • The fix will run then HijackThis will open.
  • In HijackThis, please place a check next to the following items and click FIX CHECKED:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

    O2 - BHO: (no name) - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - (no file)

    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINNT\Cursors\bakvb.dll

    O20 - Winlogon Notify: bakvb - C:\WINNT\Cursors\bakvb.dll
  • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
  • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
  • Once your machine reboots please continue with the instructions below.
Copy a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.
Hi Micah

I did as you instructed but the script came up - bakvb.dll file not found. I went ahead and fixed the entries using Hijackthis. The log is below:

Logfile of HijackThis v1.99.1
Scan saved at 5:46:48 PM, on 10/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\ehome\ehtray.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\ehome\ehSched.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\ehome\ehmsas.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - (no file)
O2 - BHO: (no name) - {827DC836-DD9F-4A68-A602-5812EB50A834} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINNT\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn.com/Components/Ocx/SurVid/MSSurVid.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://support.gateway.com/eSupport/static…h/weblaunch.cab
O16 - DPF: {9F6D8A59-DD92-499D-944A-38FDB2CE46FF} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

There was no text file from Vundo fix.
I re ran the ff.bat and here is the result
Volume in drive C has no label.
Volume Serial Number is 0C23-97B1

Directory of C:\WINNT\Cursors

10/12/2005 06:19 AM 359,816 bvkab.bak1
10/13/2005 08:33 PM 344,430 bvkab.bak2
09/19/2005 09:56 PM 423,591 bvkab.ini
10/14/2005 09:16 AM 347,775 bvkab.ini2
09/19/2005 09:56 PM 422,744 bvkab.tmp
5 File(s) 1,898,356 bytes
0 Dir(s) 56,636,186,624 bytes free
Volume in drive C has no label.
Volume Serial Number is 0C23-97B1

Directory of C:\WINNT\Cursors

10/14/2005 05:26 PM .
10/14/2005 05:26 PM ..
03/31/2003 08:00 AM 766 3dgarro.cur
03/31/2003 08:00 AM 766 3dgmove.cur
03/31/2003 08:00 AM 766 3dgnesw.cur
03/31/2003 08:00 AM 766 3dgno.cur
03/31/2003 08:00 AM 766 3dgns.cur
03/31/2003 08:00 AM 766 3dgnwse.cur
03/31/2003 08:00 AM 766 3dgwe.cur
03/31/2003 08:00 AM 766 3dsmove.cur
03/31/2003 08:00 AM 766 3dsns.cur
03/31/2003 08:00 AM 766 3dsnwse.cur
03/31/2003 08:00 AM 766 3dwarro.cur
03/31/2003 08:00 AM 766 3dwmove.cur
03/31/2003 08:00 AM 766 3dwnesw.cur
03/31/2003 08:00 AM 766 3dwno.cur
03/31/2003 08:00 AM 766 3dwns.cur
03/31/2003 08:00 AM 766 3dwnwse.cur
03/31/2003 08:00 AM 766 3dwwe.cur
03/31/2003 08:00 AM 7,962 appstar2.ani
03/31/2003 08:00 AM 7,856 appstar3.ani
03/31/2003 08:00 AM 7,954 appstart.ani
03/31/2003 08:00 AM 326 arrow_i.cur
03/31/2003 08:00 AM 766 arrow_il.cur
03/31/2003 08:00 AM 766 arrow_im.cur
03/31/2003 08:00 AM 766 arrow_l.cur
03/31/2003 08:00 AM 766 arrow_m.cur
03/31/2003 08:00 AM 326 arrow_r.cur
03/31/2003 08:00 AM 766 arrow_rl.cur
03/31/2003 08:00 AM 766 arrow_rm.cur
03/31/2003 08:00 AM 11,904 banana.ani
03/31/2003 08:00 AM 8,660 barber.ani
03/31/2003 08:00 AM 326 beam_i.cur
03/31/2003 08:00 AM 766 beam_il.cur
03/31/2003 08:00 AM 766 beam_im.cur
03/31/2003 08:00 AM 766 beam_l.cur
03/31/2003 08:00 AM 766 beam_m.cur
03/31/2003 08:00 AM 326 beam_r.cur
03/31/2003 08:00 AM 766 beam_rl.cur
03/31/2003 08:00 AM 766 beam_rm.cur
03/31/2003 08:00 AM 326 busy_i.cur
03/31/2003 08:00 AM 766 busy_il.cur
03/31/2003 08:00 AM 766 busy_im.cur
03/31/2003 08:00 AM 766 busy_l.cur
03/31/2003 08:00 AM 766 busy_m.cur
03/31/2003 08:00 AM 326 busy_r.cur
03/31/2003 08:00 AM 766 busy_rl.cur
03/31/2003 08:00 AM 766 busy_rm.cur
03/31/2003 08:00 AM 7,114 coin.ani
03/31/2003 08:00 AM 6,832 counter.ani
03/31/2003 08:00 AM 766 cross.cur
03/31/2003 08:00 AM 326 cross_i.cur
03/31/2003 08:00 AM 766 cross_il.cur
03/31/2003 08:00 AM 766 cross_im.cur
03/31/2003 08:00 AM 766 cross_l.cur
03/31/2003 08:00 AM 766 cross_m.cur
03/31/2003 08:00 AM 326 cross_r.cur
03/31/2003 08:00 AM 766 cross_rl.cur
03/31/2003 08:00 AM 766 cross_rm.cur
03/31/2003 08:00 AM 4,804 dinosau2.ani
03/31/2003 08:00 AM 4,804 dinosaur.ani
03/31/2003 08:00 AM 3,240 drum.ani
03/31/2003 08:00 AM 14,936 fillitup.ani
03/31/2003 08:00 AM 3,292 hand.ani
03/31/2003 08:00 AM 6,356 handapst.ani
03/31/2003 08:00 AM 1,700 handnesw.ani
03/31/2003 08:00 AM 4,066 handno.ani
03/31/2003 08:00 AM 1,698 handns.ani
03/31/2003 08:00 AM 1,700 handnwse.ani
03/31/2003 08:00 AM 7,530 handwait.ani
03/31/2003 08:00 AM 1,698 handwe.ani
03/31/2003 08:00 AM 766 harrow.cur
03/31/2003 08:00 AM 766 hcross.cur
03/31/2003 08:00 AM 326 help_i.cur
03/31/2003 08:00 AM 766 help_il.cur
03/31/2003 08:00 AM 766 help_im.cur
03/31/2003 08:00 AM 766 help_l.cur
03/31/2003 08:00 AM 766 help_m.cur
03/31/2003 08:00 AM 326 help_r.cur
03/31/2003 08:00 AM 766 help_rl.cur
03/31/2003 08:00 AM 766 help_rm.cur
03/31/2003 08:00 AM 766 hibeam.cur
03/31/2003 08:00 AM 766 hmove.cur
03/31/2003 08:00 AM 766 hnesw.cur
03/31/2003 08:00 AM 766 hnodrop.cur
03/31/2003 08:00 AM 766 hns.cur
03/31/2003 08:00 AM 766 hnwse.cur
03/31/2003 08:00 AM 18,722 horse.ani
03/31/2003 08:00 AM 11,832 hourgla2.ani
03/31/2003 08:00 AM 11,830 hourgla3.ani
03/31/2003 08:00 AM 11,824 hourglas.ani
03/31/2003 08:00 AM 766 hwe.cur
03/31/2003 08:00 AM 766 lappstrt.cur
03/31/2003 08:00 AM 766 larrow.cur
03/31/2003 08:00 AM 766 lcross.cur
03/31/2003 08:00 AM 766 libeam.cur
03/31/2003 08:00 AM 766 lmove.cur
03/31/2003 08:00 AM 766 lnesw.cur
03/31/2003 08:00 AM 766 lnodrop.cur
03/31/2003 08:00 AM 766 lns.cur
03/31/2003 08:00 AM 766 lnwse.cur
03/31/2003 08:00 AM 766 lwait.cur
03/31/2003 08:00 AM 766 lwe.cur
10/11/2005 06:18 AM 200 mcrh.tmp
03/31/2003 08:00 AM 5,674 metronom.ani
03/31/2003 08:00 AM 326 move_i.cur
03/31/2003 08:00 AM 766 move_il.cur
03/31/2003 08:00 AM 766 move_im.cur
03/31/2003 08:00 AM 766 move_l.cur
03/31/2003 08:00 AM 766 move_m.cur
03/31/2003 08:00 AM 326 move_r.cur
03/31/2003 08:00 AM 766 move_rl.cur
03/31/2003 08:00 AM 766 move_rm.cur
03/31/2003 08:00 AM 326 no_i.cur
03/31/2003 08:00 AM 766 no_il.cur
03/31/2003 08:00 AM 766 no_im.cur
03/31/2003 08:00 AM 766 no_l.cur
03/31/2003 08:00 AM 766 no_m.cur
03/31/2003 08:00 AM 326 no_r.cur
03/31/2003 08:00 AM 766 no_rl.cur
03/31/2003 08:00 AM 766 no_rm.cur
03/31/2003 08:00 AM 326 pen_i.cur
03/31/2003 08:00 AM 766 pen_il.cur
03/31/2003 08:00 AM 766 pen_im.cur
03/31/2003 08:00 AM 766 pen_l.cur
03/31/2003 08:00 AM 766 pen_m.cur
03/31/2003 08:00 AM 326 pen_r.cur
03/31/2003 08:00 AM 766 pen_rl.cur
03/31/2003 08:00 AM 766 pen_rm.cur
03/31/2003 08:00 AM 4,100 piano.ani
03/31/2003 08:00 AM 9,824 rainbow.ani
03/31/2003 08:00 AM 4,826 raindrop.ani
03/31/2003 08:00 AM 326 size1_i.cur
03/31/2003 08:00 AM 766 size1_il.cur
03/31/2003 08:00 AM 766 size1_im.cur
03/31/2003 08:00 AM 766 size1_l.cur
03/31/2003 08:00 AM 766 size1_m.cur
03/31/2003 08:00 AM 326 size1_r.cur
03/31/2003 08:00 AM 766 size1_rl.cur
03/31/2003 08:00 AM 766 size1_rm.cur
03/31/2003 08:00 AM 326 size2_i.cur
03/31/2003 08:00 AM 766 size2_il.cur
03/31/2003 08:00 AM 766 size2_im.cur
03/31/2003 08:00 AM 766 size2_l.cur
03/31/2003 08:00 AM 766 size2_m.cur
03/31/2003 08:00 AM 326 size2_r.cur
03/31/2003 08:00 AM 766 size2_rl.cur
03/31/2003 08:00 AM 766 size2_rm.cur
03/31/2003 08:00 AM 326 size3_i.cur
03/31/2003 08:00 AM 766 size3_il.cur
03/31/2003 08:00 AM 766 size3_im.cur
03/31/2003 08:00 AM 766 size3_l.cur
03/31/2003 08:00 AM 766 size3_m.cur
03/31/2003 08:00 AM 326 size3_r.cur
03/31/2003 08:00 AM 766 size3_rl.cur
03/31/2003 08:00 AM 766 size3_rm.cur
03/31/2003 08:00 AM 326 size4_i.cur
03/31/2003 08:00 AM 766 size4_il.cur
03/31/2003 08:00 AM 766 size4_im.cur
03/31/2003 08:00 AM 766 size4_l.cur
03/31/2003 08:00 AM 766 size4_m.cur
03/31/2003 08:00 AM 326 size4_r.cur
03/31/2003 08:00 AM 766 size4_rl.cur
03/31/2003 08:00 AM 766 size4_rm.cur
03/31/2003 08:00 AM 818 sizenesw.ani
03/31/2003 08:00 AM 818 sizens.ani
03/31/2003 08:00 AM 818 sizenwse.ani
03/31/2003 08:00 AM 818 sizewe.ani
03/31/2003 08:00 AM 6,712 stopwtch.ani
03/31/2003 08:00 AM 326 up_i.cur
03/31/2003 08:00 AM 326 up_il.cur
03/31/2003 08:00 AM 326 up_im.cur
03/31/2003 08:00 AM 766 up_l.cur
03/31/2003 08:00 AM 766 up_m.cur
03/31/2003 08:00 AM 326 up_r.cur
03/31/2003 08:00 AM 326 up_rl.cur
03/31/2003 08:00 AM 326 up_rm.cur
03/31/2003 08:00 AM 1,894 vanisher.ani
03/31/2003 08:00 AM 2,548 wagtail.ani
03/31/2003 08:00 AM 326 wait_i.cur
03/31/2003 08:00 AM 766 wait_il.cur
03/31/2003 08:00 AM 766 wait_im.cur
03/31/2003 08:00 AM 766 wait_l.cur
03/31/2003 08:00 AM 766 wait_m.cur
03/31/2003 08:00 AM 326 wait_r.cur
03/31/2003 08:00 AM 766 wait_rl.cur
03/31/2003 08:00 AM 766 wait_rm.cur
185 File(s) 308,184 bytes
2 Dir(s) 56,636,174,336 bytes free

Norton Antivirus does not give me a window stating that the trojan.vundo file exists. I have not yet gotten a "winfixer pop up". Could this have been eradicated?
Delete all of these files:

C:\WINNT\Cursors\bvkab.bak1
C:\WINNT\Cursors\bvkab.bak2
C:\WINNT\Cursors\bvkab.ini
C:\WINNT\Cursors\bvkab.ini2
C:\WINNT\Cursors\bvkab.tmp

Some malware files may be "hidden".
Be sure to show hidden files when looking for these files.

Please disable Teatimer, it can interfere with the cleaning process:

How to Disable Teatimer

Reboot after disabling Teatimer.

After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O2 - BHO: (no name) - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - (no file)

O2 - BHO: (no name) - {827DC836-DD9F-4A68-A602-5812EB50A834} - (no file)

Then click "Fix checked" and close Hijack This!.

Reboot, and you're "good to go"

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI