Hi Guys, New registrar a buddy of mine recommended me to your site. On Sunday My Mcaffee alerted me to the Vundo Trojan on my system. I ran a full scan of Mcaffe, Ad-Aware and Windows defender to no avail I then downloaded and tried Malwarebytes and it removed everything and I was good to go even after rebooting a few times. On Monday evening It reappeared on my system, once again a full malwarebytes scan removed it or so I thought. I started getting popups again and after another full malwarebytes scan it removed it again. Now after getting home from woprk and running yet another malwarebytes scan it detected 3 mroe infected files. I had played around in msconfig and disabled a few programs from startup that appeared to be gibberish to me such as: lumuhzee, vThmfyz, yitmvu, gihujasu & skytel all of these are in the SOFTWARE\microsoft\windows\currentcersion\run section of msconfig malwarebytes also tends to crash on the reload opton. I am geting kind of frustrated and dont want to trash my entire system by nuking it or deleting the wrong file. I am running Windows xp operating system and here is the Logfile from malwarebytes most recent scan
Malwarebytes' Anti-Malware 1.35
Database version: 1923
Windows 5.1.2600 Service Pack 3
3/31/2009 8:09:19 PM
mbam-log-2009-03-31 (20-09-19).txt
Scan type: Full Scan (C:\|)
Objects scanned: 294967
Time elapsed: 26 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c6b418bb-a941-4292-83ba-78df61f6e2c5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c6b418bb-a941-4292-83ba-78df61f6e2c5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vutefekoja (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
It says they have been deleted succesfully but I have to wonder if it is coming back. any thoughts or input as to where to go now??? Thanks a load!!
Pantel2k9
Yup as expected 5 minutes after my post mcaffee aler the Vundo Trojan and the stupid pop-ups have started again
here is a copy of the very first logfile from malwarebytes whatever you need to help please let me know. . . ..
here is a possible problem whenver I reboot the blue "shutting down" screen freezes up and my computer never fully reboots I have to hit the reset button, could this be contributing? should I reactivate the files I disable in msconfig startup? ( see abhove post)
Malwarebytes' Anti-Malware 1.35
Database version: 1915
Windows 5.1.2600 Service Pack 3
3/29/2009 11:52:46 AM
mbam-log-2009-03-29 (11-52-46).txt
Scan type: Full Scan (C:\|)
Objects scanned: 292010
Time elapsed: 46 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 8
Registry Values Infected: 5
Registry Data Items Infected: 23
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\neweyoko.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zurufalo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\fituzafi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rawomuba.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\gihujasu.dll (Trojan.Vundo.H) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c6b418bb-a941-4292-83ba-78df61f6e2c5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c6b418bb-a941-4292-83ba-78df61f6e2c5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c6b418bb-a941-4292-83ba-78df61f6e2c5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vutefekoja (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\9478356d (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm974b06f1 (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\zurufalo.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\zurufalo.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\zurufalo.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\gihujasu.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\gihujasu.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d748223a-a106-48a1-a5d8-5d969dc83ea4}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{d748223a-a106-48a1-a5d8-5d969dc83ea4}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{d748223a-a106-48a1-a5d8-5d969dc83ea4}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ea71ee63-bfa0-4485-b4b9-160be2631e43}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ef5f26cc-e651-45f9-9268-f828714b6562}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.194,85.255.112.98 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\fituzafi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\neweyoko.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\gihujasu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rawomuba.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zurufalo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\Jason\Local Settings\Temp\e.exe (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bebuviza.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bigivofo.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vewalimu.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\didduid.ini (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winsub.xml (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\svcp.csv (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kernel32.exe (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ossproxy.exe (Spyware.MarketScore) -> Quarantined and deleted successfully.
Good Morning Pantel2k9,
I suggest you go to this
link and follow thoroughly to the end. Please be patient as there are always more logs to analise than Malware specialists to volunteer for the work involved, but it is worth the wait in the end.
kind regards,
Thanks for speedy reply did as requested. followed to the letter and realized that I opened a second thread. I will consider this one now closed. sorry
You did very well. Now there is just a waiting game for the specialist to pick up your log. That should not be to long.
If you have not heard in 5 days, please post a gentle reminder
here
kind regards,