Need Help. Trojan Vundo And Memcheck.exe Error

By default, this memcheck.exe error is: C:\Windows\System32\ (Windows XP, Vista, 7,8) If you use a 64-bit version of Windows, you should also place Memcheck.exe in C:\Windows\SysWOW64\ Make sure overwrite any existing At the end of the scan, you can review your PC's Hardware, Security and Stability in comparison with a worldwide average. do i need to rum malwarebytes' again? it fixes it and removes it.

C:\WINDOWS\services.exe84 (Heuristics.Reserved.Word.Exploit) -> No action taken. No you won't get into trouble.Norton warns you about wanting connection to proxim.ircgalaxy.pl block the darn thing.Lets see if this takes out vundo.1. C:\Documents and Settings\Devin\Local Settings\Temporary Internet Files\Content.IE5\R96MMDRL\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully. Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2009-07-13 25600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="-" [X] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512] "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768] "ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2009-07-12 25600] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-06-06 185896]

Dude I Never received the MemCheck.exe error until I downloaded and installed Rogers new security software that comes with their service. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - Machine restarts but VundoFix doesnt make to delete the infected file. Many P2P networks are riddled with malware, and it's often some of the most recent and therefore sometimes the most difficult to remove.If you chose to optionally uninstall Limewire, go to

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: - Click on Yes, to continue scanning for malware. Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia

Performing Repairs to the registry. C:\Documents and Settings\All Users\Start Menu\Programs\Antispyware\Antispyware.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully.

Widgets.lnk = E:\Widgets\YahooWidgets.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra Attached Files ComboFix.txt (23.3 KB, 1 views)

i hope it will be useful to you. Attempting to delete C:\Windows\system32\pbrrloru.dll C:\Windows\system32\pbrrloru.dll Could not be deleted. MBAM won't work, and I've tried all the different solutions from the topic that is often refferred to when someone has this problem. VundoFix V7.0.6 Scan started at 11:17:11 PM 7/12/2009 Listing files found while scanning....

C:\Windows\system32\pbrrloru.dll Beginning removal... This software is produced by Acer (www.acer.com) or, as the case may be, Avanquest North America (www.avanquest.com). C:\WINDOWS\SYSTEM32\irdugo.dll (Trojan.Vundo) -> Delete on reboot.

scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2985862323-1253851296-254320386-1006\Software\SecuROM\License information*] "datasecu"=hex:7b,51,6f,97,5a,13,79,92,2e,fb,31,fc,6f,9e,81,e5,d7,66,b1,06,8e, 57,b0,3e,dd,c6,2f,2f,08,94,68,dd,f3,96,95,15,0b,7a,cd,83,22,a7,22,e6,e4,ca,\ "rkeysecu"=hex:54,2e,7f,23,dd,68,8d,01,71,68,9d,e4,cc,86,f1,18 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,4f,e4,22,01,5e, 8a,09,22,c8,28,51,af,b0,29,a3,98,01,96,8c,ba,2b,73,a0,3f,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b9,70,46,4b,44, 29,96,ed,71,3b,04,66,8b,46,0d,96,98,ac,d5,06,fa,b5,bb,b0,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ijjistarter2.exe (Trojan.Agent) -> Quarantined and deleted successfully.

The HijackThis log is below: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:07:48 AM, on 7/13/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16850) Boot mode: Uninstalling this variant: If you experience any issues with installation of MemCheck.exe, you may also want to do the following: go to the software publisher, www.acer.com, [1][2] for advice uninstall the But i can access it in other OS that is Vista Home Basic.