LukehWaffles
2008-08-04, 18:47
My computerhas so many viruses and trojans and I have only had internet for about 2 weeks. Virtumonde has come up in S&D on every scan, as well as ad malware such as Casalemedia and Ad.Doubleserve, etc. I ran Malwarebytes Anti-Malware and it found 80 infections. Here is a list:
Malwarebytes' Anti-Malware 1.24
Database version: 1015
Windows 5.1.2600 Service Pack 2
11:34:34 AM 8/4/2008
mbam-log-8-4-2008 (11-34-34).txt
Scan type: Quick Scan
Objects scanned: 66678
Time elapsed: 1 hour(s), 0 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 15
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 34
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\opnnnmlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rbvfofpq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\yudivz.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03d3fe17-c902-4eac-a0fa-e102e7fa6e52} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{03d3fe17-c902-4eac-a0fa-e102e7fa6e52} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9652372-a633-4d4a-9b3f-2900ec53734e} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{d9652372-a633-4d4a-9b3f-2900ec53734e} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Explorer.exe (Security.Hijack) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\48057849 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnnnmlj -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnnnmlj -> Delete on reboot.
Folders Infected:
C:\Program Files\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\yudivz.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\opnnnmlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\jlmnnnpo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jlmnnnpo.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rbvfofpq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\qpfofvbr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulxiwedo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odewixlu.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nycvbjjx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\GTI7G5YR\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\YLO7Q5WD\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\rhcaetj0ea15.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\rhcaetj0ea15.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk (Rogue.AntivirusXP) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\BM4b364bd5.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM4b364bd5.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphceetj0ea15.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phceetj0ea15.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\iexplorer.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
I am unsure of where to go from here. How many viruses are on my computer? How can I get rid of them? What do I do next (posting, running scans, etc.) Spybot cannot get rid of the results it finds, rather, it appears they are gona and then they resurface. My computer background is gone and the tab to change it has dissapeared. This is SO ANNOYING!
If anyone could help me I would greatly appreciate it.
Malwarebytes' Anti-Malware 1.24
Database version: 1015
Windows 5.1.2600 Service Pack 2
11:34:34 AM 8/4/2008
mbam-log-8-4-2008 (11-34-34).txt
Scan type: Quick Scan
Objects scanned: 66678
Time elapsed: 1 hour(s), 0 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 15
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 34
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\opnnnmlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rbvfofpq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\yudivz.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03d3fe17-c902-4eac-a0fa-e102e7fa6e52} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{03d3fe17-c902-4eac-a0fa-e102e7fa6e52} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9652372-a633-4d4a-9b3f-2900ec53734e} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{d9652372-a633-4d4a-9b3f-2900ec53734e} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Explorer.exe (Security.Hijack) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\48057849 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnnnmlj -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnnnmlj -> Delete on reboot.
Folders Infected:
C:\Program Files\rhcaetj0ea15 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\yudivz.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\opnnnmlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\jlmnnnpo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jlmnnnpo.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rbvfofpq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\qpfofvbr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulxiwedo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odewixlu.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nycvbjjx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\GTI7G5YR\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\Local Settings\Temporary Internet Files\Content.IE5\YLO7Q5WD\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\rhcaetj0ea15.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\rhcaetj0ea15.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\rhcaetj0ea15\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk (Rogue.AntivirusXP) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\BM4b364bd5.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM4b364bd5.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphceetj0ea15.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phceetj0ea15.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Luke\iexplorer.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
I am unsure of where to go from here. How many viruses are on my computer? How can I get rid of them? What do I do next (posting, running scans, etc.) Spybot cannot get rid of the results it finds, rather, it appears they are gona and then they resurface. My computer background is gone and the tab to change it has dissapeared. This is SO ANNOYING!
If anyone could help me I would greatly appreciate it.