Re: HIJACKTHIS log
23 Nov 2008 07:46PM
Malwarebytes' Anti-Malware 1.30
Database version: 1419
Windows 5.1.2600 Service Pack 3
11/23/2008 7:19:41 PM
mbam-log-2008-11-23 (19-19-35).txt
Scan type: Full Scan (C:\|)
Objects scanned: 146002
Time elapsed: 1 hour(s), 9 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 7
Registry Values Infected: 8
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\nokanoza.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\fotoguli.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kurivepa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tedakobe.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\hozuyofu.dll (Trojan.Vundo) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c324efde-be94-4be3-96de-78ffb62c3697} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c324efde-be94-4be3-96de-78ffb62c3697} (Trojan.BHO.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c324efde-be94-4be3-96de-78ffb62c3697} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\towezefiza (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm4bc6e754 (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb964 (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd8109 (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga3313 (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc9487 (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\tedakobe.dll -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\tedakobe.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\tedakobe.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\hozuyofu.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\hozuyofu.dll -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\nokanoza.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\azonakon.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\kurivepa.dll (Trojan.BHO.H) -> No action taken.
C:\WINDOWS\system32\fotoguli.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tedakobe.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\hozuyofu.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\jutivubi.dll_old (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\gsmith\Local Settings\Temporary Internet Files\Content.IE5\5P0Y00LN\style[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\gsmith\Local Settings\Temporary Internet Files\Content.IE5\R2JCGX50\style[1] (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pavereye.dll (Trojan.Vundo) -> No action taken.