I certainly did reboot after running MBAM, but I didn't do another scan. So I ran another scan now and it still found some nasties (log included below), which required a reboot, which I did. Then I realised that I hadn't downloaded the latest update, so I did that and ran another scan (log also included), which required a reboot, which I did and then ran a third scan, which still found a nasty (yet another log included). At this point I decided to continue with your other instructions. The log for SUPERAntiSpyware is included, too. While SUPERAntiSpyware was running I realised that the account that I used to run the MBAM scans had been switched to limited access, so I logged off and logged on under an administrator account and re-ran MBAM. It found and removed the last remaining file, without requiring a reboot (and if you're not yet sick of them, the log file for this one is included, too). But I rebooted anyway and did another scan, which found nothing at all!
Thanks again. Here are the logs:
MBAM 1:
Malwarebytes' Anti-Malware 1.17
Database version: 854
11:21:23 AM 18/06/2008
mbam-log-6-18-2008 (11-21-23).txt
Scan type: Quick Scan
Objects scanned: 36989
Time elapsed: 3 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\iiffFuVn.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\nVuFffii.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
MBAM 2:
Malwarebytes' Anti-Malware 1.17
Database version: 865
11:29:59 AM 18/06/2008
mbam-log-6-18-2008 (11-29-59).txt
Scan type: Quick Scan
Objects scanned: 37391
Time elapsed: 2 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\iiffFuVn.dll (Trojan.Vundo) -> Delete on reboot.
MBAM 3:
Malwarebytes' Anti-Malware 1.17
Database version: 865
11:35:50 AM 18/06/2008
mbam-log-6-18-2008 (11-35-50).txt
Scan type: Quick Scan
Objects scanned: 37302
Time elapsed: 3 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\iiffFuVn.dll (Trojan.Vundo) -> Delete on reboot.
SUPERAntiSpyware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 06/18/2008 at 01:01 PM
Application Version : 4.15.1000
Core Rules Database Version : 3484
Trace Rules Database Version: 1475
Scan type : Complete Scan
Total Scan Time : 01:08:38
Memory items scanned : 159
Memory threats detected : 0
Registry items scanned : 5413
Registry threats detected : 0
File items scanned : 71393
File threats detected : 0
Adware.Tracking Cookie
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.bs.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.msnportal.112.2o7.net [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\x54gkyh8.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.msnportal.112.2o7.net [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.statse.webtrendslive.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\Vicky.VICKYSPC\Application Data\Mozilla\Firefox\Profiles\ib6mnjp8.default\cookies.txt ]
MBAM 4:
Malwarebytes' Anti-Malware 1.17
Database version: 867
2:05:54 PM 18/06/2008
mbam-log-6-18-2008 (14-05-54).txt
Scan type: Quick Scan
Objects scanned: 34916
Time elapsed: 2 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)