Vundo!grb trojan and agent.HRO issues

Status
Not open for further replies.
I am getting messages from McAfee OAS that it has detected and attempted to remove instances of Vundo!grb Trojan malware (It finds the files C:\windows\system32\oyirukaf.ini and C:\windows\system32\uyabesub.ini as the problematic files).

My symptoms are very similar to another user (SoraNagagino21) who reported it a couple of dayas back, e.g. pop up ads in Internet Explorer, and pop ups stating that i need updates and fixes from random companies, new browser windows popping up to result in "cannot find server" page.

I also ran StopZilla scan and it found 8 instances of agent.HRO infection in the registry keys and removed it. But the infections were found again after I rebooted the machine after the removal.

I am currently following the steps in "8-step Viruses/Spyware/Malware Preliminary Removal Instructions" and will attach the 3 logs to this post when the scanning is completed. I would appreciate if the experts can take a look at the logs and help me out in getting rid of this stubborn malware.

Thanks,
Neil
 
Sorry about the delay in posting the logs, Bobbye. Here are the 3 log files. Please suggest what should be my next step. Thank you very much for your help!
 
Here are the logs. Somehow it did not attach during the last attempt.
 

Attachments

  • mbam-log-2009-03-25 (10-56-01).txt
    5.9 KB · Views: 11
  • hijackthis.txt
    15.9 KB · Views: 7
  • SUPERAntiSpyware Scan Log-03-25-2009.txt
    4.7 KB · Views: 6
Neil, you are heavily infected. You have way too much loading at Startup and too many different connections. I am going to refer your logs to someone who is better able to handle them. Be patient while I ask.
 
Neil,

What exactly is the laptop used for, is it a work laptop? and do you know all the Host file entires?

I don't want to fix anything that will permanently wreck it on you.

Did you also put the restrictions on Internet Explorer?
 
Kritius,

Sorry about the delayed response. I was in the middle of a move and did not see my messages until now.

Yes, it is a work laptop and the hosts file entries as shown in hijackthis log are all legitimate and added by me.

I did not put any restrictions on Internet Explorer and the browser could not open the home page during this infection. So could it be a case of the malware trying to hijack my browser's home page?

Thanks for all your help, Kritius and Bobbye!

-Neil
 
Status
Not open for further replies.
Back