The virus that won't just die...
Based on other threads on the same subject, I ran MBAM before I decided to post. Running ESET scan right now, and HijackThis.
This is the log from MBAM, I am not too clear as to what to do to get rid of this, but it seems to have worked for the other posters.
Thank you kindly in advance for your time going over my log in your spare time, much appreciated; this virus is driving us nuts.
-------------------------------
Malwarebytes' Anti-Malware 1.32
Database version: 1647
Windows 5.1.2600 Service Pack 3
1/13/2009 5:52:39 AM
mbam-log-2009-01-13 (05-52-32).txt
Scan type: Full Scan (C:\|D:\|F:\|)
Objects scanned: 94772
Time elapsed: 22 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 4
Registry Keys Infected: 22
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 22
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\urqRLbbB.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vxeccn.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\apmnbhll.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\lqtnsg.dll (Trojan.Vundo.H) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{848aa774-66ae-4841-b7ff-c72b1a349b75} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{848aa774-66ae-4841-b7ff-c72b1a349b75} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e12c56b2-6fcb-4f0f-bc99-11acdd585226} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{e12c56b2-6fcb-4f0f-bc99-11acdd585226} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e12c56b2-6fcb-4f0f-bc99-11acdd585226} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{848aa774-66ae-4841-b7ff-c72b1a349b75} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{cd24eb02-9831-4838-99d0-726d411b1328} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f20da564-9254-49fe-a678-cc3cef172252} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\2dda3201767c34b46a72671d26d39178 (Rogue.AntiSpywareBot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\2dda3201767c34b46a72671d26d39178 (Rogue.AntiSpywareBot) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb3678 (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd6585 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\documents and settings\all users\start menu\programs\antispywarebot\ (Rogue.AntiSpywareBot) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\urqrlbbb -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\urqrlbbb -> No action taken.
Folders Infected:
C:\Documents and Settings\Jas\Application Data\AntispywareBot (Rogue.AntiSpywareBot) -> No action taken.
Files Infected:
C:\WINDOWS\system32\lqtnsg.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\urqRLbbB.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\BbbLRqru.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\BbbLRqru.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ejtdhrpc.dll_old (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\cprhdtje.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\guxxheid.dll_old (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\diehxxug.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vxeccn.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\apmnbhll.dll (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Application Data\CyberDefender\cdmyidd.dll (Trojan.BHO) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Temp\seneka373d.tmp (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Temporary Internet Files\Content.IE5\E58G5ICN\index[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Temporary Internet Files\Content.IE5\E58G5ICN\index[2] (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Temporary Internet Files\Content.IE5\WE5O6IVB\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Jas\Local Settings\Temporary Internet Files\Content.IE5\WE5O6IVB\upd105320[3] (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\rcsjcdhr.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ysqxkv.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\odmljwxm.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\drivers\seneka.sys (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\drivers\senekatucbadlt.sys (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\senekagdvnjddw.dll (Trojan.Agent) -> No action taken.