Could someone please help me to clean up my machine after MBAM removed Trojan.Agent and Trojan.Vundo.H? MBAM looks like it worked but suspiciously there's a file that was deleted that returned by itself.
1. Removed Trojan.Agent using MBAM.
Database version: 1915
Windows 5.1.2600 Service Pack 3
18/04/2009 11:27:45 PM
Scan type: Full Scan (C:\|)
Objects scanned: 142863
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wcayulecugofu (Trojan.Agent) -> Delete on reboot.
Files Infected:
C:\WINDOWS\unilobakamodeta.dll (Trojan.Agent) -> Delete on reboot.
2. Updated MBAM
Malwarebytes' Anti-Malware 1.36
Database version: 2000
Windows 5.1.2600 Service Pack 3
18/04/2009 11:56:36 PM
Scan type: Quick Scan
Objects scanned: 71077
Time elapsed: 2 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: dkblmn.dll -> Not selected for removal.
Files Infected:
C:\WINDOWS\dkblmn.dll (Trojan.Vundo.H) -> Delete on reboot.
.. must have forgotten to tick remove ...
19/04/2009 12:00:58 AM
Scan type: Quick Scan
Objects scanned: 71163
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: dkblmn.dll -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\dkblmn.dll (Trojan.Vundo.H) -> Delete on reboot.
3. Looked in C:\WINDOWS and both deleted file were gone. dkblmn.dll was in c:\avenger directory (MBAM must have done that) so I deleted it.
4. After a while, C:\WINDOWS\dkblmn.dll reappeared and I checked my registry and found that the infected registry data item (LSA\Notification Packages) was there. I can't manually delete dkblmn.dll using a normal delete.
5. MBAM shows as clean
Malwarebytes' Anti-Malware 1.36
Database version: 2057
Windows 5.1.2600 Service Pack 3
29/04/2009 7:19:31 PM
mbam-log-2009-04-29 (19-19-31).txt
Scan type: Full Scan (C:\|)
Objects scanned: 153086
Time elapsed: 50 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)

Help
This topic is locked

Back to top










