Here's my question, I ran a scan and the software showed 24 detections, the log file showed 27 detections and in quarantine there is only 17 detections. Quarantine shows 7 files, five registry keys, and five registry values. the log which i'm posting adds 5 memory modules and 5 registry data items? Why are the totals as to what was deteted and quarantined so different?
By the way malwarebytes got everything, I ran another hijack log and was clean, also ran a superantispyware scan. I'm very happy about malwarebytes ticked off about spy sweeper. Thanks alot.
Malwarebytes' Anti-Malware 1.30
Database version: 1455
Windows 5.1.2600 Service Pack 2
12/3/2008 7:30:09 PM
mbam-log-2008-12-03 (19-30-09).txt
Scan type: Full Scan (C:\|)
Objects scanned: 139913
Time elapsed: 34 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 5
Registry Values Infected: 5
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\miziwiva.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\nunayeta.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\disovibu.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\gafuyowo.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\puyipufo.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1f0b2395-f536-4091-ad70-6d4ff4085b69} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1f0b2395-f536-4091-ad70-6d4ff4085b69} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1f0b2395-f536-4091-ad70-6d4ff4085b69} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d4dc18b5 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rekumoboto (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmd7ef2b29 (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\gafuyowo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\gafuyowo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\puyipufo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\puyipufo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\puyipufo.dll -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\miziwiva.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\aviwizim.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\disovibu.dll (Trojan.BHO.H) -> Delete on reboot.
C:\WINDOWS\system32\nunayeta.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\gafuyowo.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\puyipufo.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2XCDIHAD\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
PEACE
Sign In
Create Account

Back to top










