-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 29, 2008 2:49:08 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/05/2008
Kaspersky Anti-Virus database records: 811007
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 78111
Number of viruses found: 2
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 01:15:58
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\HiTRUSTDrive\eDS_PSD_drive.vmdf Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\CurEPGEpisode Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\EPGSignal Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\iEPGChInfo Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\RecEpisode Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\Schedule Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\Series Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\1f47_File_Monitoring_eventcritlog.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\1f47_File_Monitoring_eventlog.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\1f49_Web_Monitoring_eventlog.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\detected.idx Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\detected.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\eventlog.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\AVP7\Report\report.rpt Object is locked skipped
C:\ProgramData\Kaspersky Lab\~PRCustomProps#141.dat Object is locked skipped
C:\ProgramData\Kaspersky Lab\~PRObjects#141.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.124.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.124.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy104.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf9201.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf9222.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050025.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QCYU24OJ\kb456456[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\Users\Guest\AppData\Local\Temp\hdrhcigi.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\Users\My Computer\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat{69c6f25d-cd3e-11dc-93ff-001c25237f1e}.TM.blf Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat{69c6f25d-cd3e-11dc-93ff-001c25237f1e}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows\UsrClass.dat{69c6f25d-cd3e-11dc-93ff-001c25237f1e}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\My Computer\AppData\Local\Microsoft\Windows Defender\FileTracker\{9BA22319-7B94-496C-85C4-AEE640E6E54D} Object is locked skipped
C:\Users\My Computer\AppData\Local\Mozilla\Firefox\Profiles\txy4pq08.default\Cache\C2711A93d01 Object is locked skipped
C:\Users\My Computer\AppData\Local\Mozilla\Firefox\Profiles\txy4pq08.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\My Computer\AppData\Local\Mozilla\Firefox\Profiles\txy4pq08.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\My Computer\AppData\Local\Mozilla\Firefox\Profiles\txy4pq08.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\My Computer\AppData\Local\Mozilla\Firefox\Profiles\txy4pq08.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\My Computer\AppData\Local\Temp\fla1A35.tmp Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\cert8.db Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\history.dat Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\key3.db Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\parent.lock Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\search.sqlite Object is locked skipped
C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\txy4pq08.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\My Computer\NTUSER.DAT Object is locked skipped
C:\Users\My Computer\ntuser.dat.LOG1 Object is locked skipped
C:\Users\My Computer\ntuser.dat.LOG2 Object is locked skipped
C:\Users\My Computer\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Users\My Computer\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\My Computer\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\drivers\fidbox.dat Object is locked skipped
C:\Windows\System32\drivers\fidbox.idx Object is locked skipped
C:\Windows\System32\jfnkrdrp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\Windows\System32\kqycdneb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WMI\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\swcwqvys.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\cch~a16d479a9f.htp Object is locked skipped
C:\Windows\Temp\cch~a16d47c6b3.htp Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Malware 1st attempt
Malwarebytes' Anti-Malware 1.12
Database version: 797
Scan type: Quick Scan
Objects scanned: 39063
Time elapsed: 6 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 9
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 21
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\anensgmr.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\Windows\System32\fCrSlKDt.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\Windows\System32\kqycdneb.dll (Trojan.Vundo) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0405c7d3-82a3-4828-833b-7da0691c6ece} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{0405c7d3-82a3-4828-833b-7da0691c6ece} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bad9a9b6-16ee-4fcf-b4f9-36aa8f7cc848} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1012fae9 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM1321c975 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcrslkdt -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcrslkdt -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\anensgmr.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\rmgsnena.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\fCrSlKDt.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\tDKlSrCf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\tDKlSrCf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\jfnkrdrp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\prdrknfj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\kqycdneb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\bendcyqk.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\swcwqvys.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\syvqwcws.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\aqipfjal.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\csincjso.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\eeurhjts.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\ionwbwfy.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\jwmfnhja.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\xafquahs.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\yabfmgjk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\My Computer\Local Settings\Temporary Internet Files\Content.IE5\VZQ4EF7V\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\My Computer\Local Settings\Temporary Internet Files\Content.IE5\VZQ4EF7V\kb713501[1] (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\wkshioep.dll (Trojan.Agent) -> Delete on reboot.
Malware 2nd attempt
Malwarebytes' Anti-Malware 1.12
Database version: 797
Scan type: Quick Scan
Objects scanned: 39063
Time elapsed: 6 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 9
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 21
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\anensgmr.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\Windows\System32\fCrSlKDt.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\Windows\System32\kqycdneb.dll (Trojan.Vundo) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0405c7d3-82a3-4828-833b-7da0691c6ece} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{0405c7d3-82a3-4828-833b-7da0691c6ece} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bad9a9b6-16ee-4fcf-b4f9-36aa8f7cc848} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1012fae9 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM1321c975 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcrslkdt -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\fcrslkdt -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\anensgmr.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\rmgsnena.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\fCrSlKDt.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\tDKlSrCf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\tDKlSrCf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\jfnkrdrp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\prdrknfj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\kqycdneb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\bendcyqk.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\swcwqvys.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\syvqwcws.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\aqipfjal.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\csincjso.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\eeurhjts.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\ionwbwfy.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\jwmfnhja.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\xafquahs.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\yabfmgjk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\My Computer\Local Settings\Temporary Internet Files\Content.IE5\VZQ4EF7V\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\My Computer\Local Settings\Temporary Internet Files\Content.IE5\VZQ4EF7V\kb713501[1] (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Windows\System32\wkshioep.dll (Trojan.Agent) -> Delete on reboot.
*Heres where Im at*
-Haven't tried Combo fix yet, i read further and it requires Windows CD boot up to recover w\c i dont have
will this be a problem? i already finished the malware removal w/c requires to reboot the PC, when the PC booted the .dll errors was gone!
but something wierd popped up after the scan
what do i do next?