This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Can you check these logs? Tell me if my comp is fine?

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This morning I had noticed a pop-up that wouldn't stop appearing. I researched and found that it was probably a virus. So I downloaded Malewarebyte's Anti Malware and scanned my computer. It found 60 or so infections. I told it to fix this and so it did–said it successfully quarantined and deleted all the malware. Then I ran another scan and it found 5 more infections. So I had it fix these as well. Subsequently I have done two more full scans today and it reports that there are no more infections. However I am not much of a computer guy and I hoped that I could post my logs here and have someone who knows what they're looking at confirm my software's assurances. Please let me know if I need to worry anymore. Thank you! Ramsis P.S. I do currently have a router and am searching for a good firewall. I also plan to scan with Malwarebyte's Anti-Malware very often. Malwarebytes' Anti-Malware 1.31 Database version: 1602 Windows 5.1.2600 Service Pack 2 1/3/2009 9:25:07 AM mbam-log-2009-01-03 (09-25-07).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|H:\|) Objects scanned: 97068 Time elapsed: 29 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 4 Registry Keys Infected: 18 Registry Values Infected: 6 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 29 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\mmtndfef.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tuvTnMeE.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\dfwxej.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\hgGxVlll.dll (Trojan.Vundo) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39d2f962-3a1b-4322-8c24-211a6327c6f3} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{39d2f962-3a1b-4322-8c24-211a6327c6f3} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{fecad352-ab05-4045-9b19-0867a90c6c94} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fecad352-ab05-4045-9b19-0867a90c6c94} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fecad352-ab05-4045-9b19-0867a90c6c94} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hggxvlll (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{39d2f962-3a1b-4322-8c24-211a6327c6f3} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prunnet (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\30eb545f (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tlaboca (Trojan.Agent) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\whudacepe (Trojan.Agent) -> Delete on reboot. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvtnmee -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvtnmee -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\tuvTnMeE.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\EeMnTvut.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\EeMnTvut.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mmtndfef.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\fefdntmm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dfwxej.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\hgGxVlll.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\prunnet.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temp\rasesnet.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temp\senekadf89.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temp\winvsnet.tmp (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Laryne\Local Settings\Temporary Internet Files\Content.IE5\85MZG16N\apstpldr.dll[1].htm (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ljJAQiGY.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekarvkjoloy.dll (Trojan.Seneka) -> Delete on reboot. C:\WINDOWS\system32\luccvqtq.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\s_4610_fHx8fHx8fDEyNDM1Nzc0NjB8_.dbx (Rogue.Installer) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\~rt13.tmp (Rogue.Installer) -> Quarantined and deleted successfully. C:\WINDOWS\Sjikiley.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\egahozazohec.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekanvbrroyi.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\senekaxaecbunu.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekadf.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\seneka.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\senekalog.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\senekanfaeedmf.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msiconf.exe (Trojan.Downloader) -> Quarantined and deleted successfully. Malwarebytes' Anti-Malware 1.31 Database version: 1602 Windows 5.1.2600 Service Pack 2 1/3/2009 10:25:05 AM mbam-log-2009-01-03 (10-25-05).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|H:\|) Objects scanned: 96886 Time elapsed: 29 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{58E0A04C-D0CC-4FB7-B648-FB1030F17BA3}\RP693\A0028263.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{58E0A04C-D0CC-4FB7-B648-FB1030F17BA3}\RP693\A0028267.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{58E0A04C-D0CC-4FB7-B648-FB1030F17BA3}\RP693\A0028268.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{58E0A04C-D0CC-4FB7-B648-FB1030F17BA3}\RP693\A0028271.dll (Trojan.Seneka) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{58E0A04C-D0CC-4FB7-B648-FB1030F17BA3}\RP693\A0028273.dll (Trojan.Vundo) -> Quarantined and deleted successfully. Malwarebytes' Anti-Malware 1.31 Database version: 1602 Windows 5.1.2600 Service Pack 2 1/3/2009 12:37:53 PM mbam-log-2009-01-03 (12-37-53).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|H:\|) Objects scanned: 96999 Time elapsed: 33 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.31 Database version: 1602 Windows 5.1.2600 Service Pack 2 1/3/2009 2:26:49 PM mbam-log-2009-01-03 (14-26-49).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|H:\|) Objects scanned: 90396 Time elapsed: 32 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello ramsis

Welcome to the Whatthetech Malware Removal Forum

Download Trendmicros Hijackthis to your desktop.
  • Double click it to install
  • Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI