Ok so earlier I was looking for a song for my friend to download. I found a page that had a download link and it seemed legit. I then linked it to her through Windows Messenger and she downloaded and ended up getting a virus. I didn't even click the download link but I ended up getting lots of popups and immediately closed my browser and did a quick scan with Malwarebyte's Anti-Malware. The scan found Trojan.Vundo.H in various places and Trojan.Downloader. They were both either deleted or quarantined and I restarted my computer.
After that, I did a full scan with Malwarebyte's to make sure and nothing was found. Then when I tried playing music or videos on either iTunes, WMP, or online, the audio and video would lag, like it would be choppy for a few seconds at a time. Could this be related to the viruses? I'd really appreciate some help.
EDIT: I also want to add that after I restarted my computer, each time, after the Windows logo showed up with the load bar I would get a black screen for about 30 seconds then the cursor would show up and a few seconds later it would continue like normal. This has happened before after I had a technician remove the previous Trojan.Zlob virus.
Here's a log of Malwarebyte's when the viruses were found:
Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 2
12/16/2008 9:01:31 PM
mbam-log-2008-12-16 (21-01-30).txt
Scan type: Quick Scan
Objects scanned: 55737
Time elapsed: 7 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 14
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\ssqQgHyW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qvknjwuw.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pkafnv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnnKBUK.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\hgGxWppp.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnnkbuk (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqqghyw -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqqghyw -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\pkafnv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ssqQgHyW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\WyHgQqss.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WyHgQqss.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qvknjwuw.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnnKBUK.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\hgGxWppp.dll (Trojan.Vundo) -> Delete on reboot.
Last edited by daftcow on 17th December 2008, 7:43 am; edited 3 times in total
After that, I did a full scan with Malwarebyte's to make sure and nothing was found. Then when I tried playing music or videos on either iTunes, WMP, or online, the audio and video would lag, like it would be choppy for a few seconds at a time. Could this be related to the viruses? I'd really appreciate some help.
EDIT: I also want to add that after I restarted my computer, each time, after the Windows logo showed up with the load bar I would get a black screen for about 30 seconds then the cursor would show up and a few seconds later it would continue like normal. This has happened before after I had a technician remove the previous Trojan.Zlob virus.
Here's a log of Malwarebyte's when the viruses were found:
Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 2
12/16/2008 9:01:31 PM
mbam-log-2008-12-16 (21-01-30).txt
Scan type: Quick Scan
Objects scanned: 55737
Time elapsed: 7 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 14
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\ssqQgHyW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qvknjwuw.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pkafnv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnnKBUK.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\hgGxWppp.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df1c09da-a493-46cd-8ad4-e0f1452f1e25} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d8e34e31-3b39-462d-bc9b-0a71dbba0f52} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnnkbuk (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqqghyw -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\ssqqghyw -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\pkafnv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ssqQgHyW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\WyHgQqss.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WyHgQqss.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qvknjwuw.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnnKBUK.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\hgGxWppp.dll (Trojan.Vundo) -> Delete on reboot.
Last edited by daftcow on 17th December 2008, 7:43 am; edited 3 times in total