Start a Conversation

Unsolved

This post is more than 5 years old

1252

March 21st, 2009 11:00

UNABLE TO LOCATE FILES I.D. BY TREND MICRO PC-CILLIN

Trend Micro PC-Cillin I.D. the following filesand the last 3 as containing a possible Vundo-9 trojan. However when I started our system in Safe Mode, I was unable to find the files in order to delete them.

C: \ Documents and Settings \ Jon Christopher Hall \ Local Settings \ Temporary Intenet Files \ content.IE5 \ CONB412C \ load[1].exe

C: \ Documents and Settings \ Jon Christopher Hall \ Local Settings \ Temporary Intenet Files \ content.IE5 \ LQYCO5YR \ jKxnOcZ[1].exe

C: \ WINDOWS \system32 \ tadepabe.dll

C: \ WINDOWS \system32 \ icgwqy.dll

C: \ WINDOWS \system32 \ vupuroke.dll

I would appreciate any suggestions.

 

 

3 Apprentice

 • 

20.5K Posts

March 21st, 2009 17:00

Welcome :emotion-1:

If it's Vundo, there are usually more files and associated Registry entries.

Try running Malwarebytes' Anti-Malware.
Please download to your desktop Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates,
  • manually download them from here
    and just double-click on mbam-rules.exe to install.
    Alternatively, you can update through MBAM's interface from a clean computer,
    copy the definitions (rules.ref) located in
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
    Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
  • Once the program has loaded, select "Perform Quick Scan"; then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checkedPhotobucket
    Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • If you are still having problems and/or would like a follow-up check to be sure the infection as well as vulnerabilities are gone, copy and paste the entire report into a New Message on the Malware Removal forum. Also include a fresh HijackThis log. Instructions for downloading HijackThis are at the top of that forum.

     

    1. Just click the Start A New Thread button (upper right) in the Malware Removal forum HERE
    to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.

    2. In the discussion window that opens, simply Right-Click and select Paste.

    Extra Notes:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

     

    * If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to your CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

     

    -- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes.

    **If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from http://www.malwarebytes.org/mbam-clean.exe

     

4 Posts

March 22nd, 2009 15:00

I had previously installed MBAM and have used it frequently for several months. I updated it today and ran the quick scan but it failed to find anything. Trend Micro PC -Cillin can find the files but is unable to remove or quarantine them. In the past I have restarted in Safe Mode found the files with the trojan and deleted them but I'm unable to find these particular files.

No Events found!

Top