It's a vundo rootkit.
Still some vundo files there that need to be removed.
Open notepad and copy/paste the text inside the lines below into it.
--------------------------
File::
C:\WINDOWS\system32\ocljqj
C:\WINDOWS\system32\awtqr.
C:\WINDOWS\system32\dofxjo
C:\WINDOWS\system32\xpvekw
C:\WINDOWS\system32\tuvsqn
C:\WINDOWS\system32\wnfltb
RenV::
C:\Program Files\Messenger\msmsgs .exe
DirLook::
C:\WINDOWS\c3VzYW4
Registry::
[-HKEY_LOCAL_MACHINE\~\Bro
[-HKEY_LOCAL_MACHINE\~\Bro
[-HKEY_LOCAL_MACHINE\~\Bro
[hkey_local_machine\softwa
"{CA4F0D8D-5F2B-4F16-838A-
[-HKEY_LOCAL_MACHINE\softw
--------------------------
Save this as CFScript in the same location as ComboFix.exe
drag CFScript.txt into ComboFix.exe
This will start ComboFix again. Follow the prompts. After reboot, (in case it asks to reboot), attach the contents of Combofix.txt in your next reply together.
Main Topics
Browse All Topics





by: slamondPosted on 2008-04-11 at 11:32:06ID: 21336882
The system is still pathetically slow as I try to update the Norton AV list and reinstall Windows Defender. I'm still getting the continuously popping-up message that NAV found Trojan.Vundo at tuvsqno.dll and is unable to delete it.