![]() ![]() |
25.07.2008 23:36
Post
#1
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
Hello
Am facing a problem in the removal of this tojan Trojan.Win32.Monderc.gen ..KIS 2009 is keep informing me that it is detected but can not remove it. The machine is using windows xp SP3. I also noticed that the system becomes slow and keep hanging and the windows explorer keep crashing from time to time and the windows update id disappled. Please help me to remove this trojan. |
|
|
|
25.07.2008 23:46
Post
#2
|
|
![]() Kaspersky Fan III ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 2200 Joined: 2.01.2007 From: Novi Sad, Serbia |
Please post an AVZ log: http://forum.kaspersky.com/index.php?showtopic=69276
|
|
|
|
26.07.2008 00:04
Post
#3
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
|
|
|
|
26.07.2008 00:09
Post
#4
|
|
![]() Are You Kidding? ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 56933 Joined: 28.01.2006 From: Timisoara, Romania |
Run this script (instructions in the same topic):
CODE begin SetAVZGuardStatus(True); SearchRootkit(true, true); DelBHO('{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}'); DelBHO('{954C573F-8E6E-4A8C-A8E7-1C6229A81286}'); DelBHO('{03E3D45B-681C-481C-B6A3-0D08B12C4AB9}'); QuarantineFile('wvUmmjGv.dll',''); QuarantineFile('C:\WINDOWS\system32\wvUmmjGv.dll',''); QuarantineFile('C:\WINDOWS\system32\bnyewsxo.dll',''); QuarantineFile('C:\WINDOWS\system32\iiffFYrO.dll',''); QuarantineFile('C:\WINDOWS\system32\dpfnkmun.dll',''); DeleteFile('C:\WINDOWS\system32\dpfnkmun.dll'); DeleteFile('C:\WINDOWS\system32\iiffFYrO.dll'); DeleteFile('C:\WINDOWS\system32\bnyewsxo.dll'); DeleteFile('C:\WINDOWS\system32\wvUmmjGv.dll'); DeleteFile('wvUmmjGv.dll'); BC_ImportDeletedList; ExecuteSysClean; BC_Activate; RebootWindows(true); end. then make a combofix log: Download it here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe Now, please make sure no other programs are running, close all other windows and pause Kaspersky (if still active) until after the scanning and removal process has taken place. Now, please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal. You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed. Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post |
|
|
|
26.07.2008 00:42
Post
#5
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
AZV script excuted and attached is the CompoFix reprot.
Attached File(s)
|
|
|
|
26.07.2008 00:50
Post
#6
|
|
![]() Are You Kidding? ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 56933 Joined: 28.01.2006 From: Timisoara, Romania |
CODE begin QuarantineFile('C:\WINDOWS\system32\dpfnkmun.bak',''); QuarantineFile('C:\WINDOWS\BMd7a990fb.xml',''); QuarantineFile('C:\WINDOWS\system32\iiffFYrO.bak',''); DeleteFile('C:\WINDOWS\system32\dpfnkmun.bak'); DeleteFile('C:\WINDOWS\BMd7a990fb.xml'); DeleteFile('C:\WINDOWS\system32\iiffFYrO.bak'); end. execute this one. then zip and send me the contents of c:\qoobox\quarantine and C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\AVZ_Quarantine over PM |
|
|
|
26.07.2008 21:34
Post
#7
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
Thanks Lucian Bara for all the help
I got the files you reguested...they are large. How can i upload them to you? |
|
|
|
26.07.2008 21:39
Post
#8
|
|
![]() Advanced Member IV ![]() ![]() ![]() ![]() ![]() ![]() Group: Gold beta testers Posts: 750 Joined: 12.02.2007 From: Estonia |
www.rapidshare.com
Send link to Lucian. |
|
|
|
27.07.2008 22:10
Post
#9
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
The scan with Malwarebytes' Anti-Malware is done and attached the log file
Done the rempval and now am doing anoter scan with Malwarebytes' Anti-Malware.
Attached File(s)
|
|
|
|
27.07.2008 22:11
Post
#10
|
|
![]() Are You Kidding? ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 56933 Joined: 28.01.2006 From: Timisoara, Romania |
looks ok, delete this C:\WINDOWS\BMd7a990fb.txt
|
|
|
|
27.07.2008 22:48
Post
#11
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
Couldn't find this file C:\WINDOWS\BMd7a990fb.txt
It seems it's deleted already |
|
|
|
27.07.2008 22:50
Post
#12
|
|
![]() Are You Kidding? ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 56933 Joined: 28.01.2006 From: Timisoara, Romania |
ok then. any more problems?
|
|
|
|
27.07.2008 23:08
Post
#13
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 25.07.2008 |
Now every thing seems to be ok
Thanks for all the help and support. |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 20.05.2013 21:10 |