PDA

View Full Version : Hard to remove malware



markusp
2008-12-29, 04:55
I have malware on my computer that has turned off windows automatic updates. It is a vundo trojan that spybot can detect but not get rid of. I ran malwarebytes anti-malware which found a good bit but was unable to fully get rid of it as automatic updates is still disabled. Any help would be greatly appreciated.

markusp
2008-12-29, 05:16
here is a copy of my malwarebytes log:


Malwarebytes' Anti-Malware 1.31
Database version: 1564
Windows 5.1.2600 Service Pack 2

12/28/2008 10:27:16 PM
mbam-log-2008-12-28 (22-26-54).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 141549
Time elapsed: 1 hour(s), 11 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 11
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\urqRIbyV.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\frjjoa.dll (Trojan.Vundo) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b4eb1204-16b2-4c68-b182-3260bcb58599} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{b4eb1204-16b2-4c68-b182-3260bcb58599} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b4eb1204-16b2-4c68-b182-3260bcb58599} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{a0e1054b-01ee-4d57-a059-4d99f339709f} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\urqribyv -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\urqribyv -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: digeste.dll -> No action taken.

Folders Infected:
C:\Program Files\GetModule (Trojan.Agent) -> No action taken.

Files Infected:
C:\WINDOWS\system32\urqRIbyV.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\VybIRqru.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\VybIRqru.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nbhtymgt.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\tgmythbn.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\frjjoa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\digeste.dll (Trojan.Agent) -> No action taken.

Thanks

Shaba
2008-12-29, 16:08
Hello markusp

Please see this (http://forums.spybot.info/showthread.php?t=288) next

Please follow the instructions in the above thread and then start a fresh topic with the logs required.

Regards.