Vundo Highjackthis Traces
This page is dedicated to finding vundo and virtumonde traces that are found in the highjackthis page. Please add any traces you find. This will help thousands of people remove the virtumonde virus.
traces we know of already:
O2-BHO:(noname)-{EFCB1D95-FFF6-47BB-B6C9-61A523F04322} C:\WINDOWS\system32\vturr.dll
awtqn.dll
awtsr.dll
jkhfe.dll
vzbb.dll
O20 – Winlogon Notify: vturr – C:\WINDOWS\system32\vturr.dll
May 31st, 2008 at 6:32 am
Registry Key for Vitumonde
hklm\software\microsoft\removerp\
Windows file for Virtumonde
Winlogon.exe
C:\windows\system32\_c00C9FCE.data
June 20th, 2008 at 9:29 am
Hi!
Alsou found this one:
hggyawmm.dll attached to winlogon.exe
i guess it it changing from time to time.
July 8th, 2008 at 5:21 am
C:\WINDOWS\system32\wvUoOHxu.dll and
C:\WINDOWS\system32\ljJAPIbb.dll
July 8th, 2008 at 6:35 am
uhjqfcqr.dll
any file that has a .dll,b
mljyatld.dll
Smitfraud trace we found that is common
wgalogan in the C:\Windows\ folder