I have a Windows 2003 server box that recently became very infected with several malwares. This box serves primarly as a terminal server so there are always any number of people connected to the server doing work and browsing the internet which is probally how the box got infected. I do my best to keep the box safe but this got through. The worst of the infection was something called Spyware Guard 2008 which Malwarebytes was able to get rid of after I removed a rootkit infection.
Now my problem is an infection called "Trojan.Vundo.H" which both Malwarebytes and SpyBot Search and Destroy is able to detect and remove but each time I reboot the trojan is reinstalled. No matter how many times I run Spybot or Malwarebytes it keeps finding the same trojan, removes it, and needs to reboot to remove the rest of the trojan but every time I reboot the trojan is reinstalled. Below is my malwarebytes log. I will post the Panda Active Log and HiJack This Log as soon as they are complete.
Thank you so much for your help!
---------------------- Malwarebytes Log --------------------------
Malwarebytes' Anti-Malware 1.31
Database version: 1491
Windows 5.2.3790
12/11/2008 5:35:10 PM
mbam-log-2008-12-11 (17-35-10).txt
Scan type: Quick Scan
Objects scanned: 339212
Time elapsed: 31 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 6
Registry Keys Infected: 14
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 24
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\awtrPjJC.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\efcCvVmM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\vdljmyni.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\hgGyyyxW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tsjnbptv.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ixvknf.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4481fe0e-3b2b-470e-8b81-ffa4b0094f13} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4481fe0e-3b2b-470e-8b81-ffa4b0094f13} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hggyyyxw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bff9a884-e9d1-47bd-a309-3f9881ada053} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bff9a884-e9d1-47bd-a309-3f9881ada053} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\381b2adb (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\awtrpjjc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\awtrpjjc -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\awtrPjJC.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\CJjPrtwa.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGyyyxW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ixvknf.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\efcCvVmM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\MmVvCcfe.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MmVvCcfe.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vdljmyni.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\inymjldv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tsjnbptv.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\kmrhbieu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rjpjqrwd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wccsoido.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ytzhlx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kendra.Doss.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\CZFVJO5Z\kb600179[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kendra.Doss.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\DO7PTTQ8\CA3E29ZF (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kendra.Doss.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\MZWJLS2O\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kendra.Doss.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\TEHC32J2\CAEJCLMJ (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gary.Doss\Local Settings\Temporary Internet Files\Content.IE5\2T867SZZ\CATKML97 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Evan.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\058SBX8J\CAC905KB (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Evan.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\10KW6YYF\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Evan.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\5C0H0C45\CAPSSBDX (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Evan.MATRIX\Local Settings\Temporary Internet Files\Content.IE5\5RT2EXKL\CA94MLX7 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator.ARCHITECT\Local Settings\Temporary Internet Files\Content.IE5\OXIFSHA7\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.