PDA

View Full Version : Trojan.Vundo.H



okrobie
2009-03-27, 02:10
Hello, Spybot S&D is not finding this, but MBAM is. Problem is that MBAM says its deleted, but it shows up again if I Do an MBAM scan immediately after the first session. Here are the log entries. I also manually deleted them with HJT but they still came back. Can you include this in Spybot S&D? Thanks, Jim

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88096be5-c087-412e-ba7a-9a6880c146e5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{88096be5-c087-412e-ba7a-9a6880c146e5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\makovejoha (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmd7c0aac9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d4f39955 (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Matt
2009-03-27, 14:38
Hi okrobie,

if you don't get rid of Vundo, please feel free to open your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22). Therefore, read the thread "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) from tashi and prepare a HijackThis log file.