BlazeTheKing
2008-12-01, 04:42
Hello,
I have not been able to find any topics on a multitude of sites relating to my current problem. Spybot never worked to remove the virus in the first place so I had to find an alternative. Malbytes' Malware worked perfectly, except there are 3 registry keys that keep regenerating everytime I log into windows normally. I'm thinking it has to do with some kind of file that is running because they do not get recreated when going into safe mode.
I'm actually an IT person but since I usually keep myself from getting on sites with trojans etc I'm having trouble getting rid of this persistent virus. Oddly enough it was on some news site but anyways here's the 3 that keep regenerating:
O4 - HKLM\..\Run: [CPM9f24eeaf] Rundll32.exe "c:\windows\system32\vahuyayu.dll",a
O4 - HKLM\..\Run: [fidufajamo] Rundll32.exe "C:\WINDOWS\system32\nakuteye.dll",s
O4 - HKLM\..\Run: [9c17dd33] rundll32.exe "C:\WINDOWS\system32\zizakohe.dll",b
I've scanned my whole system with F-Secure from Charter, Malbyte's, HJT, the secure libary scan from Microsoft, Spybot S n D, and VundoFix as well as VundoBegone. Malbytes got rid of all the infected files but no matter how many times i delete these regkeys they come back.
Thanks
I have not been able to find any topics on a multitude of sites relating to my current problem. Spybot never worked to remove the virus in the first place so I had to find an alternative. Malbytes' Malware worked perfectly, except there are 3 registry keys that keep regenerating everytime I log into windows normally. I'm thinking it has to do with some kind of file that is running because they do not get recreated when going into safe mode.
I'm actually an IT person but since I usually keep myself from getting on sites with trojans etc I'm having trouble getting rid of this persistent virus. Oddly enough it was on some news site but anyways here's the 3 that keep regenerating:
O4 - HKLM\..\Run: [CPM9f24eeaf] Rundll32.exe "c:\windows\system32\vahuyayu.dll",a
O4 - HKLM\..\Run: [fidufajamo] Rundll32.exe "C:\WINDOWS\system32\nakuteye.dll",s
O4 - HKLM\..\Run: [9c17dd33] rundll32.exe "C:\WINDOWS\system32\zizakohe.dll",b
I've scanned my whole system with F-Secure from Charter, Malbyte's, HJT, the secure libary scan from Microsoft, Spybot S n D, and VundoFix as well as VundoBegone. Malbytes got rid of all the infected files but no matter how many times i delete these regkeys they come back.
Thanks