Good afternoon,
None of the internet searches I have done are showing up anything on the below. I should let you know my occupation is in the computer arena. I am an Middleware Administrator and have installed IBM MQ software & MSMQ on windows boxes, so I do have some comfort level playing around on the operating system.
Thursday night, April 24th, our McAfee popped up that it had found a Trojan named Vundo, byRKkhFV.dll that it could not clean. I checked clean, delete, and quarantine and none of the actions were successful. If I say cancel, the McAfee box pops right back up.
In MSCONFIG the following are showing in my startup now. I have disabled them but that is not working.
rundll.exe "c:\windows\system32\caslrqyd.dll",b
rundll.exe "c:\windows\system32\fvhgciyp.dll",s
In Windows Defender Software running tab the following shows up. When I disable this or try to remove it, it keeps coming right back. There is a line:
Microsoft run dll as an app with "c:\windows\system32\fvhgciyp.dll"
Windows Defender pops up that it has detected changes in the run key, I say deny, it says deny successful and then the pop up that it has detected changes comes up again.
I ran McAfee in regular startup, and it says 0 files found, even though that Trojan found popup appears. Then I rebooted in diagnostic mode, unhooking the internet cable, and ran McAfee. It is still finding anything.
An Error Repair Tool installed itself on the computer. I have supposedly successfully removed that program from add remove programs.
In HKLM\software\microsoft\windows\currentVersion\run is the following keys. In diagnostic mode these keys are now under MSConfig startupreg.
BM73c6c058 - command = rundll.exe "c:\windows\system32\fvhgciyp.dll",s
70f5e3c4 - command = rundll.exe "c:\windows\system32\caslrqyd.dll",b
In Windows\System32\ the following files were created on Thursday 4/24,
pmnmjgeb.dll ***
ytulhjjx.dll
hodgekbh.ini ***
clkcnt.tmp
xdyxmaqy.dll
begjmnmp.ini
begjmnmp.ini2
Files created in System 32 on 4/25
caslrqyd.dll
fvhgciyp.dll
mrch.tmp
The ones with the *** after them are files that are in use even in diagnostic mode. It does not let me rename them to with a bad_ in front.
So,
? Should I leave the ones I renamed to bad_* alone and restart or rename them back to normal and do something else.
? Should I delete the BM73c6d058 & 70f5e3c4 keys in MSConfig/startupreg?
My computer is still disconnected from the internet and it diagnostic mode. I am on another one, a laptop in the same room. Sorry if this is a long thread entry. Just wanted you to have all details that I see.
Thanks for your assistance!!!!


Reply With Quote
