Elizabeth52
2007-03-03, 05:35
I have been plagued with constant popups, winsoftwareantiviruspro2006 or game sites. I have used a number of different spyware removers but none seems work.
My Spybot has been running all day and each time it come up with a new set of problems,
Cassava, ReliableStats, Smitfraud. Other programs have detected and supposedly removed, Worm.Krepper.c, Logger.VBStat.h, Trojan.BHO.g and Downloader.Swizzer.ag.
The notepad files are as follows:
VirtumundoBeGone
[03/02/2007, 20:11:09] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Sandy\Desktop\VirtumundoBeGone.exe" )
[03/02/2007, 20:11:13] - Detected System Information:
[03/02/2007, 20:11:13] - Windows Version: 5.1.2600, Service Pack 2
[03/02/2007, 20:11:13] - Current Username: Sandy (Admin)
[03/02/2007, 20:11:13] - Windows is in NORMAL mode.
[03/02/2007, 20:11:13] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\awttqnn
[03/02/2007, 20:11:13] - Found: HKLM\...\Winlogon\Notify\awttqnn - This is probably Virtumundo.
[03/02/2007, 20:11:13] - Assigning {768318D5-06A3-4987-81FC-8ECA2E068210} MSEvents Object
[03/02/2007, 20:11:13] - BHO list has been changed! Starting over...
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:13] - BHO 4: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:13] - BHO 5: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\geedd
[03/02/2007, 20:11:13] - Found: HKLM\...\Winlogon\Notify\geedd - This is probably Virtumundo.
[03/02/2007, 20:11:13] - Assigning {BBCE6944-2736-40E4-AE88-E092C9F2A83A} MSEvents Object
[03/02/2007, 20:11:13] - BHO list has been changed! Starting over...
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:13] - BHO 4: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:13] - BHO 5: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 6: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:13] - BHO 7: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:13] - BHO 8: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:13] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:13] - *** Detected MSEvents Object
[03/02/2007, 20:11:13] - Trying to remove MSEvents Object...
[03/02/2007, 20:11:14] - Terminating Process: IEXPLORE.EXE
[03/02/2007, 20:11:15] - Terminating Process: RUNDLL32.EXE
[03/02/2007, 20:11:15] - Disabling Automatic Shell Restart
[03/02/2007, 20:11:15] - Terminating Process: EXPLORER.EXE
[03/02/2007, 20:11:16] - Suspending the NT Session Manager System Service
[03/02/2007, 20:11:16] - Terminating Windows NT Logon/Logoff Manager
[03/02/2007, 20:11:16] - Re-enabling Automatic Shell Restart
[03/02/2007, 20:11:16] - File to disable: C:\WINDOWS\system32\awttqnn.dll
[03/02/2007, 20:11:16] - Renaming C:\WINDOWS\system32\awttqnn.dll -> C:\WINDOWS\system32\awttqnn.dll.vir
[03/02/2007, 20:11:16] - File successfully renamed!
[03/02/2007, 20:11:16] - Removing HKLM\...\Browser Helper Objects\{768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Removing HKCR\CLSID\{768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Adding Kill Bit for ActiveX for GUID: {768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Deleting ATLEvents/MSEvents Registry entries
[03/02/2007, 20:11:16] - Removing HKLM\...\Winlogon\Notify\awttqnn
[03/02/2007, 20:11:16] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:16] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:16] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:16] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:16] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:16] - BHO 4: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} (MSEvents Object)
[03/02/2007, 20:11:16] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:16] - BHO 5: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:16] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:17] - BHO 6: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:17] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:17] - BHO 7: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:17] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:17] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:17] - *** Detected MSEvents Object
[03/02/2007, 20:11:17] - Trying to remove MSEvents Object...
[03/02/2007, 20:11:18] - Terminating Process: IEXPLORE.EXE
[03/02/2007, 20:11:18] - Terminating Process: RUNDLL32.EXE
[03/02/2007, 20:11:18] - Disabling Automatic Shell Restart
[03/02/2007, 20:11:18] - Terminating Process: EXPLORER.EXE
[03/02/2007, 20:11:18] - Suspending the NT Session Manager System Service
[03/02/2007, 20:11:18] - Terminating Windows NT Logon/Logoff Manager
[03/02/2007, 20:11:18] - Re-enabling Automatic Shell Restart
[03/02/2007, 20:11:18] - File to disable: C:\WINDOWS\system32\geedd.dll
[03/02/2007, 20:11:18] - Renaming C:\WINDOWS\system32\geedd.dll -> C:\WINDOWS\system32\geedd.dll.vir
[03/02/2007, 20:11:18] - File successfully renamed!
[03/02/2007, 20:11:18] - Removing HKLM\...\Browser Helper Objects\{BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Removing HKCR\CLSID\{BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Adding Kill Bit for ActiveX for GUID: {BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Deleting ATLEvents/MSEvents Registry entries
[03/02/2007, 20:11:18] - Removing HKLM\...\Winlogon\Notify\geedd
[03/02/2007, 20:11:18] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:18] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:18] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:18] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:18] - BHO 4: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:18] - BHO 5: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:18] - BHO 6: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:18] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:18] - Finishing up...
[03/02/2007, 20:11:18] - A restart is needed.
[03/02/2007, 20:11:23] - Attempting to Restart via STOP error (Blue Screen!)
[03/02/2007, 20:14:35] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Sandy\Desktop\VirtumundoBeGone.exe" )
[03/02/2007, 20:14:42] - Detected System Information:
[03/02/2007, 20:14:42] - Windows Version: 5.1.2600, Service Pack 2
[03/02/2007, 20:14:42] - Current Username: Sandy (Admin)
[03/02/2007, 20:14:42] - Windows is in NORMAL mode.
[03/02/2007, 20:14:42] - Searching for Browser Helper Objects:
[03/02/2007, 20:14:42] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:14:42] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:14:42] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:14:42] - BHO 4: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:14:42] - BHO 5: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:14:42] - BHO 6: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:14:42] - Finished Searching Browser Helper Objects
[03/02/2007, 20:14:42] - Finishing up...
[03/02/2007, 20:14:42] - Nothing found! Exiting...
Active Scan
Incident Status Location
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\All Users\Application Data\SecTaskMan\gputldxh.dll.q_804D015_q
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Sandy\Cookies\sandy@mediaplex[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\Extracted Zip\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\Extracted Zip\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\jtuhqejt.exe.bad
Adware:Adware/PurityScan Not disinfected C:\VundoFix Backups\ubkeuhbf.dll.bad
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\antqgfjy.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\bfwvolom.dll
Adware:Adware/WinAntivirus2006 Not disinfected C:\WINDOWS\system32\ijvjavam.dll
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\vbcyyvcg.exe
Virus:Trj/Zapchast.Z Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[Pixelbt32.exe]
Virus:Trj/Pakes.V Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[xpq.exe]
Adware:Adware/IST.ISTBar Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[xpq.exe][mgrsts.exe]
See next post for the rest.
My Spybot has been running all day and each time it come up with a new set of problems,
Cassava, ReliableStats, Smitfraud. Other programs have detected and supposedly removed, Worm.Krepper.c, Logger.VBStat.h, Trojan.BHO.g and Downloader.Swizzer.ag.
The notepad files are as follows:
VirtumundoBeGone
[03/02/2007, 20:11:09] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Sandy\Desktop\VirtumundoBeGone.exe" )
[03/02/2007, 20:11:13] - Detected System Information:
[03/02/2007, 20:11:13] - Windows Version: 5.1.2600, Service Pack 2
[03/02/2007, 20:11:13] - Current Username: Sandy (Admin)
[03/02/2007, 20:11:13] - Windows is in NORMAL mode.
[03/02/2007, 20:11:13] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\awttqnn
[03/02/2007, 20:11:13] - Found: HKLM\...\Winlogon\Notify\awttqnn - This is probably Virtumundo.
[03/02/2007, 20:11:13] - Assigning {768318D5-06A3-4987-81FC-8ECA2E068210} MSEvents Object
[03/02/2007, 20:11:13] - BHO list has been changed! Starting over...
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:13] - BHO 4: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:13] - BHO 5: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\geedd
[03/02/2007, 20:11:13] - Found: HKLM\...\Winlogon\Notify\geedd - This is probably Virtumundo.
[03/02/2007, 20:11:13] - Assigning {BBCE6944-2736-40E4-AE88-E092C9F2A83A} MSEvents Object
[03/02/2007, 20:11:13] - BHO list has been changed! Starting over...
[03/02/2007, 20:11:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:13] - BHO 2: {768318D5-06A3-4987-81FC-8ECA2E068210} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:13] - BHO 4: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:13] - BHO 5: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} (MSEvents Object)
[03/02/2007, 20:11:13] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:13] - BHO 6: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:13] - BHO 7: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:13] - BHO 8: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:13] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:13] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:13] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:13] - *** Detected MSEvents Object
[03/02/2007, 20:11:13] - Trying to remove MSEvents Object...
[03/02/2007, 20:11:14] - Terminating Process: IEXPLORE.EXE
[03/02/2007, 20:11:15] - Terminating Process: RUNDLL32.EXE
[03/02/2007, 20:11:15] - Disabling Automatic Shell Restart
[03/02/2007, 20:11:15] - Terminating Process: EXPLORER.EXE
[03/02/2007, 20:11:16] - Suspending the NT Session Manager System Service
[03/02/2007, 20:11:16] - Terminating Windows NT Logon/Logoff Manager
[03/02/2007, 20:11:16] - Re-enabling Automatic Shell Restart
[03/02/2007, 20:11:16] - File to disable: C:\WINDOWS\system32\awttqnn.dll
[03/02/2007, 20:11:16] - Renaming C:\WINDOWS\system32\awttqnn.dll -> C:\WINDOWS\system32\awttqnn.dll.vir
[03/02/2007, 20:11:16] - File successfully renamed!
[03/02/2007, 20:11:16] - Removing HKLM\...\Browser Helper Objects\{768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Removing HKCR\CLSID\{768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Adding Kill Bit for ActiveX for GUID: {768318D5-06A3-4987-81FC-8ECA2E068210}
[03/02/2007, 20:11:16] - Deleting ATLEvents/MSEvents Registry entries
[03/02/2007, 20:11:16] - Removing HKLM\...\Winlogon\Notify\awttqnn
[03/02/2007, 20:11:16] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:16] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:16] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:16] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:16] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:16] - BHO 4: {BBCE6944-2736-40E4-AE88-E092C9F2A83A} (MSEvents Object)
[03/02/2007, 20:11:16] - ALERT: Found MSEvents Object!
[03/02/2007, 20:11:16] - BHO 5: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:16] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:17] - BHO 6: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:17] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:17] - BHO 7: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:17] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:17] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:17] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:17] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:17] - *** Detected MSEvents Object
[03/02/2007, 20:11:17] - Trying to remove MSEvents Object...
[03/02/2007, 20:11:18] - Terminating Process: IEXPLORE.EXE
[03/02/2007, 20:11:18] - Terminating Process: RUNDLL32.EXE
[03/02/2007, 20:11:18] - Disabling Automatic Shell Restart
[03/02/2007, 20:11:18] - Terminating Process: EXPLORER.EXE
[03/02/2007, 20:11:18] - Suspending the NT Session Manager System Service
[03/02/2007, 20:11:18] - Terminating Windows NT Logon/Logoff Manager
[03/02/2007, 20:11:18] - Re-enabling Automatic Shell Restart
[03/02/2007, 20:11:18] - File to disable: C:\WINDOWS\system32\geedd.dll
[03/02/2007, 20:11:18] - Renaming C:\WINDOWS\system32\geedd.dll -> C:\WINDOWS\system32\geedd.dll.vir
[03/02/2007, 20:11:18] - File successfully renamed!
[03/02/2007, 20:11:18] - Removing HKLM\...\Browser Helper Objects\{BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Removing HKCR\CLSID\{BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Adding Kill Bit for ActiveX for GUID: {BBCE6944-2736-40E4-AE88-E092C9F2A83A}
[03/02/2007, 20:11:18] - Deleting ATLEvents/MSEvents Registry entries
[03/02/2007, 20:11:18] - Removing HKLM\...\Winlogon\Notify\geedd
[03/02/2007, 20:11:18] - Searching for Browser Helper Objects:
[03/02/2007, 20:11:18] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:11:18] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:11:18] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:11:18] - BHO 4: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:11:18] - BHO 5: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:11:18] - BHO 6: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:11:18] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:11:18] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:11:18] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:11:18] - Finished Searching Browser Helper Objects
[03/02/2007, 20:11:18] - Finishing up...
[03/02/2007, 20:11:18] - A restart is needed.
[03/02/2007, 20:11:23] - Attempting to Restart via STOP error (Blue Screen!)
[03/02/2007, 20:14:35] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Sandy\Desktop\VirtumundoBeGone.exe" )
[03/02/2007, 20:14:42] - Detected System Information:
[03/02/2007, 20:14:42] - Windows Version: 5.1.2600, Service Pack 2
[03/02/2007, 20:14:42] - Current Username: Sandy (Admin)
[03/02/2007, 20:14:42] - Windows is in NORMAL mode.
[03/02/2007, 20:14:42] - Searching for Browser Helper Objects:
[03/02/2007, 20:14:42] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/02/2007, 20:14:42] - BHO 2: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/02/2007, 20:14:42] - BHO 3: {AB4B3E48-FBCD-47A2-85C6-AE5EFEFAD2E5} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\pmnli
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\pmnli, continuing.
[03/02/2007, 20:14:42] - BHO 4: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\fppmxheu
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\fppmxheu, continuing.
[03/02/2007, 20:14:42] - BHO 5: {DA69062A-E444-4F03-9668-14FE0CCB85C1} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\ddcyx
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\ddcyx, continuing.
[03/02/2007, 20:14:42] - BHO 6: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[03/02/2007, 20:14:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/02/2007, 20:14:42] - Checking for HKLM\...\Winlogon\Notify\etccpbfh
[03/02/2007, 20:14:42] - Key not found: HKLM\...\Winlogon\Notify\etccpbfh, continuing.
[03/02/2007, 20:14:42] - Finished Searching Browser Helper Objects
[03/02/2007, 20:14:42] - Finishing up...
[03/02/2007, 20:14:42] - Nothing found! Exiting...
Active Scan
Incident Status Location
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\All Users\Application Data\SecTaskMan\gputldxh.dll.q_804D015_q
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Sandy\Cookies\sandy@mediaplex[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\Extracted Zip\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\Extracted Zip\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sandy\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\jtuhqejt.exe.bad
Adware:Adware/PurityScan Not disinfected C:\VundoFix Backups\ubkeuhbf.dll.bad
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\antqgfjy.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\bfwvolom.dll
Adware:Adware/WinAntivirus2006 Not disinfected C:\WINDOWS\system32\ijvjavam.dll
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\vbcyyvcg.exe
Virus:Trj/Zapchast.Z Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[Pixelbt32.exe]
Virus:Trj/Pakes.V Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[xpq.exe]
Adware:Adware/IST.ISTBar Not disinfected J:\My Documents\Sams Downloads\DivXPlayerPro64-Setup.0xe[xpq.exe][mgrsts.exe]
See next post for the rest.