goolia
Topic Starter
I am getting a pop-up error that says I have a virus, but that it cannot be deleted. I use Firefox as my browser, but one thing I've noticed is that I get the pop-up every time I open Internet Explorer. I'm using Trend Micro PC-cillin Internet Security 14. Here is the error-
"Notification
Real-time Virus Protection
Real-time Virus Protection has detected a virus or other security risk, and performed the action specified.
Action taken: This file shows signs of infection by an unidentified virus.
Incident name: C:\Windows\system32\vmrdihxe.dll
Detection name: Cryp_Tap
User name: timothy
Note: If Search for and clean Trojans is turned on and executed after scanning, click Next to view the final action taken."
I've tried deleting the file manually, but it says it is being used by another program, so it won't let me delete it. I read on another thread that someone was having a similar problem and was told to download ATF Cleaner and Malwarebytes' Anti-Malware. I ran both. It found some infected files, so I deleted them, but I am still getting the same pop-up that there is a virus.
Here is the log I received-
Malwarebytes' Anti-Malware 1.05
Database version: 396
Scan type: Quick Scan
Objects scanned: 31302
Time elapsed: 4 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa16fe06-b462-470e-9653-79c54b1871ff} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{fa16fe06-b462-470e-9653-79c54b1871ff} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
"Notification
Real-time Virus Protection
Real-time Virus Protection has detected a virus or other security risk, and performed the action specified.
Action taken: This file shows signs of infection by an unidentified virus.
Incident name: C:\Windows\system32\vmrdihxe.dll
Detection name: Cryp_Tap
User name: timothy
Note: If Search for and clean Trojans is turned on and executed after scanning, click Next to view the final action taken."
I've tried deleting the file manually, but it says it is being used by another program, so it won't let me delete it. I read on another thread that someone was having a similar problem and was told to download ATF Cleaner and Malwarebytes' Anti-Malware. I ran both. It found some infected files, so I deleted them, but I am still getting the same pop-up that there is a virus.
Here is the log I received-
Malwarebytes' Anti-Malware 1.05
Database version: 396
Scan type: Quick Scan
Objects scanned: 31302
Time elapsed: 4 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa16fe06-b462-470e-9653-79c54b1871ff} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{fa16fe06-b462-470e-9653-79c54b1871ff} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)