Infected with Viruses and Internet disconnected Need help to remove them
#1
Posted 31 July 2009 - 09:05 PM
These are the two subborn viruses I can't seem to remove
Trojan.Downloader-CREW
C:\windows\system32\ujoyvzji.dll
Adware.Vundo/Variant-MSFake
C:\windows\system32\dwrmmuq.dll
Thanks
#2
Posted 01 August 2009 - 10:49 AM
Please subscribe to your topic so that you will be notified as soon as I post a reply, instead of you having to check the topic all of the time. This will allow you to get an email notification when I reply.
To subscribe, go to your topic, and at the top right hand corner by your first post, click the Options button and then click Track this topic. The bullet the immediate notification bubble. Then press submit.
Could you please update Malwarebytes by going to the Update Tab, and then run a Full Scan?
#3
Posted 07 August 2009 - 07:03 PM
#4
Posted 07 August 2009 - 07:30 PM
Please download and install the database from here.
Then run a Full Scan and post back the log
#5
Posted 21 August 2009 - 05:02 AM
I did a full scan on the infected computer on the 8th of this month even though the program wasn't updated.
None of the following infections were deleted even though it said that it was. The computer still has the viruses in log and the other two I posted up earlier.
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 2
8/8/2009 12:14:33 AM
mbam-log-2009-08-08 (00-14-33).txt
Scan type: Full Scan (C:\|D:\|G:\|H:\|I:\|)
Objects scanned: 280514
Time elapsed: 2 hour(s), 25 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
This post has been edited by yoori: 21 August 2009 - 05:04 AM
#6
Posted 21 August 2009 - 05:05 AM
http://www.malwarebytes.org/mbam/database/mbam-rules.exe
No. Try not. Do... or do not. There is no try.
#7
Posted 21 August 2009 - 06:06 PM
I'll post the log when I get a chance to comeback online again
#9
Posted 08 November 2009 - 06:09 AM
Here's the log I was suppose to have posted up
Malwarebytes' Anti-Malware 1.40
Database version: 2667
Windows 5.1.2600 Service Pack 2
8/24/2009 2:12:08 AM
mbam-log-2009-08-24 (02-12-08).txt
Scan type: Full Scan (C:\|D:\|G:\|H:\|I:\|)
Objects scanned: 283201
Time elapsed: 2 hour(s), 29 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\dyae.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\N41FST9V\wcypzaer[1].txt (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\VH0IXNON\loaderadv563[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
#10
Posted 08 November 2009 - 02:55 PM
Malwarebytes
Install that, and then go to the "Update" tab and update the program.
Finally after it is updated, run a Quick Scan and post back the log.
#11
Posted 08 November 2009 - 06:15 PM
#12
Posted 08 November 2009 - 06:19 PM
Please use that link to manually update the def's. Then please run the Quick Scan and post back the log.
#13
Posted 08 November 2009 - 08:58 PM
Here's the log
Malwarebytes' Anti-Malware 1.41
Database version: 3101
Windows 5.1.2600 Service Pack 2
11/8/2009 3:43:21 PM
mbam-log-2009-11-08 (15-43-21).txt
Scan type: Quick Scan
Objects scanned: 142316
Time elapsed: 11 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 3
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\ShopGuide (Adware.Rewardnet) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\shpsv (Adware.Rewardnet) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\temp\3367958559.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\3160614809.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\181611020.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\2997487612.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\3001394762.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\3060314584.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\3824709410.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\4206984966.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
#14
Posted 08 November 2009 - 09:00 PM
#15
Posted 09 November 2009 - 03:08 AM

Help
This topic is locked

Back to top










