Hi
I started having problems with my Toshiba notebook two days ago when NOD32 detected a virus infecting the operating memory unable to clean and Windows couldn't restart properly after that.
I then managed to get it started in temporary mode and after that I could even start it normally, the virus was still there so I follow your guide to remove malware. It worked for the operating memory virus, I guess, since NOD32 isn't finding anything anymore but MBAM keeps finding two of them and each time I finish the scans and it asks me to reboot it actually gets worse,, so I'm guessing the trojans are still where they were.
Here is the first log I got from MBAM:
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6001 Service Pack 1
14/09/2009 20.09.00
mbam-log-2009-09-14 (20-09-00).txt
Scan type: Quick Scan
Objects scanned: 84618
Time elapsed: 7 minute(s), 42 second(s)
Memory Processes infected: 0
Memory modules infected: 2
Registry Keys infected: 1
Registry values infected: 0
Registry data items infected: 0
Folders infected: 0
Files infected: 4
Memory processes Infected:
(No malicious items detected)
Memory Modules infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys
(Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\savofeti.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\UACxcfxpmrefq.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
Here is the latest:
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6001 Service Pack 1
15/09/2009 11.02.49
mbam-log-2009-09-15 (11-02-49).txt
Scan type: Quick Scan
Objects scanned: 84423
Time elapsed: 8 minute(s), 35 second(s)
Memory Processes infected: 0
Memory modules infected: 2
Registry Keys infected: 0
Registry values infected: 0
Registry data items infected: 0
Folders infected: 0
Files infected: 2
Memory processes Infected:
(No malicious items detected)
Memory Modules infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys
(Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot.
I didn't do a scan after reboot but I'm pretty sure they're still there as my computer performance hasn't improved, if anything... it has worsened.
One thing that happens among other is that IE opens by itself and tries to go to some weird links, I have disabled the internet to prevent it from actually go online.
Please help me out with this!!!
I started having problems with my Toshiba notebook two days ago when NOD32 detected a virus infecting the operating memory unable to clean and Windows couldn't restart properly after that.
I then managed to get it started in temporary mode and after that I could even start it normally, the virus was still there so I follow your guide to remove malware. It worked for the operating memory virus, I guess, since NOD32 isn't finding anything anymore but MBAM keeps finding two of them and each time I finish the scans and it asks me to reboot it actually gets worse,, so I'm guessing the trojans are still where they were.
Here is the first log I got from MBAM:
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6001 Service Pack 1
14/09/2009 20.09.00
mbam-log-2009-09-14 (20-09-00).txt
Scan type: Quick Scan
Objects scanned: 84618
Time elapsed: 7 minute(s), 42 second(s)
Memory Processes infected: 0
Memory modules infected: 2
Registry Keys infected: 1
Registry values infected: 0
Registry data items infected: 0
Folders infected: 0
Files infected: 4
Memory processes Infected:
(No malicious items detected)
Memory Modules infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys
(Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\savofeti.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\UACxcfxpmrefq.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
Here is the latest:
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6001 Service Pack 1
15/09/2009 11.02.49
mbam-log-2009-09-15 (11-02-49).txt
Scan type: Quick Scan
Objects scanned: 84423
Time elapsed: 8 minute(s), 35 second(s)
Memory Processes infected: 0
Memory modules infected: 2
Registry Keys infected: 0
Registry values infected: 0
Registry data items infected: 0
Folders infected: 0
Files infected: 2
Memory processes Infected:
(No malicious items detected)
Memory Modules infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot
Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys
(Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files infected:
C:\Windows\System32\genanoju.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\kebukilo.dll (Trojan.Vundo) -> Delete on reboot.
I didn't do a scan after reboot but I'm pretty sure they're still there as my computer performance hasn't improved, if anything... it has worsened.
One thing that happens among other is that IE opens by itself and tries to go to some weird links, I have disabled the internet to prevent it from actually go online.
Please help me out with this!!!