Just want to start off by saying this is an excellent site and I found a lot of good info. With that said... I have Ad-Aware and it picked up a Virtumonde. It's not taking care of it. I did a search and download Malwarebytes. It picked this up this is my log file. I haven't taken action yet because I wanted tohear what you guys had to say. Should I delete the Virus's? I don't want to mess up my whole computer.
Malwarebytes' Anti-Malware 1.31
Database version: 1590
Windows 5.1.2600 Service Pack 3
1/1/2009 5:23:14 PM
mbam-log-2009-01-01 (17-23-06).txt
Scan type: Quick Scan
Objects scanned: 58969
Time elapsed: 5 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 4
Registry Keys Infected: 18
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 26
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\geBqQIXo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pbstdsfg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMgdeEV.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jqjhfc.dll (Trojan.Vundo.H) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomgdeev (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\90bd56ce (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\gebqqixo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebqqixo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: digeste.dll -> No action taken.
Folders Infected:
C:\Program Files\iCheck (Trojan.Agent) -> No action taken.
C:\Program Files\GetModule (Trojan.Agent) -> No action taken.
Files Infected:
C:\WINDOWS\system32\geBqQIXo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oXIQqBeg.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oXIQqBeg.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMgdeEV.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\jqjhfc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pbstdsfg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gfsdtsbp.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\waxwcivg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gvicwxaw.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\buqltr.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\digeste.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\nbjgqjjx.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vqddnh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ceycck.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\dbktnl.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\njcxxmom.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wpv481229907443.cpx (Adware.Agent) -> No action taken.
C:\WINDOWS\system32\ixtiqqoa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jekmdsnb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\fnhihxhi.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kunrsqug.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\atmqfl.dll (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temp\KB02.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\Q6X8YL6C\upd105320[1] (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\ZDM1AZU3\index[1] (Trojan.Vundo.H) -> No action taken.
C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> No action taken.
Malwarebytes' Anti-Malware 1.31
Database version: 1590
Windows 5.1.2600 Service Pack 3
1/1/2009 5:23:14 PM
mbam-log-2009-01-01 (17-23-06).txt
Scan type: Quick Scan
Objects scanned: 58969
Time elapsed: 5 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 4
Registry Keys Infected: 18
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 26
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\geBqQIXo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pbstdsfg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMgdeEV.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jqjhfc.dll (Trojan.Vundo.H) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomgdeev (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c610147b-319a-48ad-af9c-9b6757db067c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{558301a0-2fe5-4b0b-9cfc-6404794ddd1a} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\90bd56ce (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\gebqqixo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebqqixo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: digeste.dll -> No action taken.
Folders Infected:
C:\Program Files\iCheck (Trojan.Agent) -> No action taken.
C:\Program Files\GetModule (Trojan.Agent) -> No action taken.
Files Infected:
C:\WINDOWS\system32\geBqQIXo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oXIQqBeg.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oXIQqBeg.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMgdeEV.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\jqjhfc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\pbstdsfg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gfsdtsbp.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\waxwcivg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gvicwxaw.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\buqltr.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\digeste.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\nbjgqjjx.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vqddnh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ceycck.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\dbktnl.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\njcxxmom.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wpv481229907443.cpx (Adware.Agent) -> No action taken.
C:\WINDOWS\system32\ixtiqqoa.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\jekmdsnb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\fnhihxhi.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\kunrsqug.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\atmqfl.dll (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temp\KB02.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\Q6X8YL6C\upd105320[1] (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\ZDM1AZU3\index[1] (Trojan.Vundo.H) -> No action taken.
C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> No action taken.