Hello, and thanks in advance for any help.
My PC got infected with what appeared to be two viruses simultaneously. Norton identified the first as some Vundo. I ran VundoFix, and it seems to have taken care of that one.
Then Norton discovered what it calls Trojan.MetaJuan. This virus keeps adding dll files in the system32 folder. One of them was sttss.dll, but I managed to remove that one, and new ones with random names keep being created. Norton, of course, can't deal with it. The virus slows down the system, and opens browser windows with advertisements for rogue antivirus software. I also found that my eMule incoming folder contained 300 files which I suspect were fake key generators infected with the virus. I think that this was done by the first virus, though, as that folder has remained empty for a few days now.
Vundofix doesn't find any of the DLL files of the second virus. Combofix does find them, and deletes the dlls, as well as a few other files. After I run Combofix, the machine appears to be clean for a while, but the virus always returns eventually.
This is a typical Combofix activity log:
Other Deletions
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\apeeygkf.dll
C:\WINDOWS\system32\awvtq.dll
C:\WINDOWS\system32\cfdjgsbn.dll
C:\WINDOWS\system32\ddccyvw.dll
C:\WINDOWS\system32\dmyupmgb.ini
C:\WINDOWS\system32\hggddcy.dll
C:\WINDOWS\system32\igpgnhlp.dll
C:\WINDOWS\system32\mtiournp.ini
C:\WINDOWS\system32\pnruoitm.dll
C:\WINDOWS\system32\qtvwa.ini
C:\WINDOWS\system32\qtvwa.ini2
----- BITS: Possible infected sites -----
hxxp://au.download.windowsupdate.com
By the way, if I run HijackThis the virus hides and no dll's appear in the log, but this was easily defeated by changing the executable to HJT.exe.
I will post this morning's HighJack log in a following message
Thanks in advance to any help. I have cleaned viruses on my own before, but this one is too tough for me.
Ron