gr8northwoods
2006-08-09, 06:49
Please help, it won't go away...
First let me say I am using Symantec Internet Security 2006 :(
This only seems to happen when IEXPLORE.EXE is running
I have spent 3 days scanning with Norton consuming 96% of my resources and my laptop is as useless as a paperweight. (if anyone has any good suggestions as an alternative to this absurd and ridiculous bloatware, please tell me!)
It continually reports Dialer.Generic and then it offers to Quarantine or Remove a file called (variably **):
C:\Documents and Settings\pops\Local Settings\Temporary InternetFiles\Content.IE5\**insert_random_folder_name**\srv***[1].exe
(ie: srvmxv[1].exe
this is immediately followed with a message from Norton saying:
Norton has detected a virus on your computer.
Object Name: C:WINDOWS\TEMP\win***.tmp
(insert random hex for *** ie: win11D.tmp)
Virus Name: Trojan Horse
Action Taken: Unable to repair this file
Action Taken: Access to this file was denied
it takes 8 to clicks to get rid of this message and then I get a box with:
Manual Repair: Risks -
Name - Trojan Horse
Risk - High
Details - Virus
Action - (Remove or Quarantine)
(NEITHER WORK)
then ...nothing... except after a reboot, same darn thing!
From reading here I found there may be problems with:
ddayy.dll
(as well as
yyadd.tmp
yyadd.ini
yyadd.ini2)
and I get
win64.tmp.exe
popping up in the C:\WINDOWS\Temp folder
and random win**.tmp files report a trojan to Norton
so I went to VirusTotal and got this:
------------------------------------------------------
Complete scanning result of "ddayy.dll", received in VirusTotal at 08.08.2006, 23:20:11 (CET).
Antivirus Version Update Result
AntiVir 6.35.1.0 08.08.2006 no virus found
Authentium 4.93.8 08.08.2006 no virus found
Avast 4.7.844.0 08.08.2006 no virus found
AVG 386 08.08.2006 no virus found
BitDefender 7.2 08.08.2006 no virus found
CAT-QuickHeal 8.00 08.08.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 no virus found
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2329 08.08.2006 Win32/Vundo
Ewido 4.0 08.08.2006 no virus found
Fortinet 2.77.0.0 08.08.2006 suspicious
F-Prot 3.16f 08.08.2006 no virus found
F-Prot4 4.2.1.29 08.08.2006 no virus found
Ikarus 0.2.65.0 08.08.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 not-a-virus:AdWare.Win32.Virtumonde.da
McAfee 4824 08.08.2006 Vundo
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1697 08.08.2006 no virus found
Norman 5.90.23 08.08.2006 no virus found
Panda 9.0.0.4 08.08.2006 Suspicious file
Sophos 4.08.0 08.08.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.08.2006 no virus found
VBA32 3.11.0 08.08.2006 no virus found
VirusBuster 4.3.7:9 08.08.2006 no virus found
Aditional Information
File size: 573492 bytes
MD5: 4bde22ffa058d3e130880b7d46998735
SHA1: 57c3ed465e617fee52dd30f471a7342c3ccff6ae
packers: embedded
---------------------------------------------------------
From this info I ran Atribune's VundoFix.exe 5.1.0.7 with no results.
---------------------------------------------------------
Then Symantecs FixVundo with this log:
Symantec Trojan.Vundo Removal Tool 1.5.0
The process "IEXPLORE.EXE" might be affected by the threat. It cannot be terminated.
The process "IEXPLORE.EXE" might be affected by the threat. It has been terminated.
C:\Program Files\Folder Lock\Encrypted\n¦+¦-n: (not scanned)
C:\System Volume Information: (not scanned)
Trojan.Vundo has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 205522
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral threads terminated: 0
The number of registry entries fixed: 0
but it was a lie as the same thing popped up again :(
---------------------------------------------------------
Then I ran VirtumundoBeGone.exe with no luck:
[08/08/2006, 23:02:28] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:02:30] - Detected System Information:
[08/08/2006, 23:02:30] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:02:30] - Current Username: pops (Admin)
[08/08/2006, 23:02:30] - Windows is in NORMAL mode.
[08/08/2006, 23:02:30] - Searching for Browser Helper Objects:
[08/08/2006, 23:02:30] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:30] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:30] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:30] - BHO 4: {61DB1DD7-0130-4B74-810E-BB6040C59EE5} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\ddayy
[08/08/2006, 23:02:30] - Found: HKLM\...\Winlogon\Notify\ddayy - This is probably Virtumundo.
[08/08/2006, 23:02:30] - Assigning {61DB1DD7-0130-4B74-810E-BB6040C59EE5} MSEvents Object
[08/08/2006, 23:02:30] - BHO list has been changed! Starting over...
[08/08/2006, 23:02:30] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:30] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:31] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:31] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:31] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:31] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:31] - BHO 4: {61DB1DD7-0130-4B74-810E-BB6040C59EE5} (MSEvents Object)
[08/08/2006, 23:02:31] - ALERT: Found MSEvents Object!
[08/08/2006, 23:02:31] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:02:31] - BHO 6: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:02:31] - BHO 7: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:02:31] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:02:31] - BHO 9: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:02:31] - Finished Searching Browser Helper Objects
[08/08/2006, 23:02:31] - *** Detected MSEvents Object
[08/08/2006, 23:02:31] - Trying to remove MSEvents Object...
[08/08/2006, 23:02:32] - Terminating Process: IEXPLORE.EXE
[08/08/2006, 23:02:32] - Terminating Process: RUNDLL32.EXE
[08/08/2006, 23:02:32] - Disabling Automatic Shell Restart
[08/08/2006, 23:02:32] - Terminating Process: EXPLORER.EXE
[08/08/2006, 23:02:33] - Suspending the NT Session Manager System Service
[08/08/2006, 23:02:33] - Terminating Windows NT Logon/Logoff Manager
[08/08/2006, 23:02:34] - Re-enabling Automatic Shell Restart
[08/08/2006, 23:02:34] - File to disable: C:\WINDOWS\system32\ddayy.dll
[08/08/2006, 23:02:34] - Removing HKLM\...\Browser Helper Objects\{61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Removing HKCR\CLSID\{61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Adding Kill Bit for ActiveX for GUID: {61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Deleting ATLEvents/MSEvents Registry entries
[08/08/2006, 23:02:34] - Removing HKLM\...\Winlogon\Notify\ddayy
[08/08/2006, 23:02:34] - Searching for Browser Helper Objects:
[08/08/2006, 23:02:34] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:34] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:34] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:34] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:34] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:34] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:34] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:02:35] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:02:35] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:02:35] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:02:35] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:02:35] - Finished Searching Browser Helper Objects
[08/08/2006, 23:02:35] - Finishing up...
[08/08/2006, 23:02:35] - A restart is needed.
[08/08/2006, 23:04:20] - Attempting to Restart via STOP error (Blue Screen!)
[08/08/2006, 23:11:32] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:11:34] - Detected System Information:
[08/08/2006, 23:11:34] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:11:34] - Current Username: pops (Admin)
[08/08/2006, 23:11:34] - Windows is in NORMAL mode.
[08/08/2006, 23:11:34] - Searching for Browser Helper Objects:
[08/08/2006, 23:11:34] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:11:34] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:11:34] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:11:34] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:11:34] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:11:34] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:11:34] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:11:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:11:34] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:11:34] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:11:34] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:11:34] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:11:34] - Finished Searching Browser Helper Objects
[08/08/2006, 23:11:34] - Finishing up...
[08/08/2006, 23:11:34] - Nothing found! Exiting...
[08/08/2006, 23:12:51] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:12:52] - Detected System Information:
[08/08/2006, 23:12:52] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:12:52] - Current Username: pops (Admin)
[08/08/2006, 23:12:52] - Windows is in NORMAL mode.
[08/08/2006, 23:12:52] - Searching for Browser Helper Objects:
[08/08/2006, 23:12:52] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:12:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:12:52] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:12:52] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:12:52] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:12:52] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:12:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:12:52] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:12:52] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:12:52] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:12:52] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:12:52] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:12:53] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:12:53] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:12:53] - Finished Searching Browser Helper Objects
[08/08/2006, 23:12:53] - Finishing up...
[08/08/2006, 23:12:53] - Nothing found! Exiting...
[08/08/2006, 23:27:05] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:27:08] - Detected System Information:
[08/08/2006, 23:27:08] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:27:08] - Current Username: pops (Admin)
[08/08/2006, 23:27:08] - Windows is in NORMAL mode.
[08/08/2006, 23:27:08] - Searching for Browser Helper Objects:
[08/08/2006, 23:27:08] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:27:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:27:08] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:27:08] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:27:08] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:27:08] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:27:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:27:08] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:27:08] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:27:08] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:27:08] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:27:08] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:27:08] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:27:08] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:27:08] - Finished Searching Browser Helper Objects
[08/08/2006, 23:27:08] - Finishing up...
[08/08/2006, 23:27:08] - Nothing found! Exiting.
------------------------------------------------------------------------
The darn thing still pops up in Norton!
------------------------------------------------------------------------
continued below.....
First let me say I am using Symantec Internet Security 2006 :(
This only seems to happen when IEXPLORE.EXE is running
I have spent 3 days scanning with Norton consuming 96% of my resources and my laptop is as useless as a paperweight. (if anyone has any good suggestions as an alternative to this absurd and ridiculous bloatware, please tell me!)
It continually reports Dialer.Generic and then it offers to Quarantine or Remove a file called (variably **):
C:\Documents and Settings\pops\Local Settings\Temporary InternetFiles\Content.IE5\**insert_random_folder_name**\srv***[1].exe
(ie: srvmxv[1].exe
this is immediately followed with a message from Norton saying:
Norton has detected a virus on your computer.
Object Name: C:WINDOWS\TEMP\win***.tmp
(insert random hex for *** ie: win11D.tmp)
Virus Name: Trojan Horse
Action Taken: Unable to repair this file
Action Taken: Access to this file was denied
it takes 8 to clicks to get rid of this message and then I get a box with:
Manual Repair: Risks -
Name - Trojan Horse
Risk - High
Details - Virus
Action - (Remove or Quarantine)
(NEITHER WORK)
then ...nothing... except after a reboot, same darn thing!
From reading here I found there may be problems with:
ddayy.dll
(as well as
yyadd.tmp
yyadd.ini
yyadd.ini2)
and I get
win64.tmp.exe
popping up in the C:\WINDOWS\Temp folder
and random win**.tmp files report a trojan to Norton
so I went to VirusTotal and got this:
------------------------------------------------------
Complete scanning result of "ddayy.dll", received in VirusTotal at 08.08.2006, 23:20:11 (CET).
Antivirus Version Update Result
AntiVir 6.35.1.0 08.08.2006 no virus found
Authentium 4.93.8 08.08.2006 no virus found
Avast 4.7.844.0 08.08.2006 no virus found
AVG 386 08.08.2006 no virus found
BitDefender 7.2 08.08.2006 no virus found
CAT-QuickHeal 8.00 08.08.2006 no virus found
ClamAV devel-20060426 08.08.2006 no virus found
DrWeb 4.33 08.08.2006 no virus found
eTrust-InoculateIT 23.72.89 08.08.2006 no virus found
eTrust-Vet 12.6.2329 08.08.2006 Win32/Vundo
Ewido 4.0 08.08.2006 no virus found
Fortinet 2.77.0.0 08.08.2006 suspicious
F-Prot 3.16f 08.08.2006 no virus found
F-Prot4 4.2.1.29 08.08.2006 no virus found
Ikarus 0.2.65.0 08.08.2006 no virus found
Kaspersky 4.0.2.24 08.08.2006 not-a-virus:AdWare.Win32.Virtumonde.da
McAfee 4824 08.08.2006 Vundo
Microsoft 1.1508 08.04.2006 no virus found
NOD32v2 1.1697 08.08.2006 no virus found
Norman 5.90.23 08.08.2006 no virus found
Panda 9.0.0.4 08.08.2006 Suspicious file
Sophos 4.08.0 08.08.2006 no virus found
Symantec 8.0 08.08.2006 no virus found
TheHacker 5.9.8.187 08.07.2006 no virus found
UNA 1.83 08.08.2006 no virus found
VBA32 3.11.0 08.08.2006 no virus found
VirusBuster 4.3.7:9 08.08.2006 no virus found
Aditional Information
File size: 573492 bytes
MD5: 4bde22ffa058d3e130880b7d46998735
SHA1: 57c3ed465e617fee52dd30f471a7342c3ccff6ae
packers: embedded
---------------------------------------------------------
From this info I ran Atribune's VundoFix.exe 5.1.0.7 with no results.
---------------------------------------------------------
Then Symantecs FixVundo with this log:
Symantec Trojan.Vundo Removal Tool 1.5.0
The process "IEXPLORE.EXE" might be affected by the threat. It cannot be terminated.
The process "IEXPLORE.EXE" might be affected by the threat. It has been terminated.
C:\Program Files\Folder Lock\Encrypted\n¦+¦-n: (not scanned)
C:\System Volume Information: (not scanned)
Trojan.Vundo has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 205522
The number of deleted files: 0
The number of viral processes terminated: 1
The number of viral threads terminated: 0
The number of registry entries fixed: 0
but it was a lie as the same thing popped up again :(
---------------------------------------------------------
Then I ran VirtumundoBeGone.exe with no luck:
[08/08/2006, 23:02:28] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:02:30] - Detected System Information:
[08/08/2006, 23:02:30] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:02:30] - Current Username: pops (Admin)
[08/08/2006, 23:02:30] - Windows is in NORMAL mode.
[08/08/2006, 23:02:30] - Searching for Browser Helper Objects:
[08/08/2006, 23:02:30] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:30] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:30] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:30] - BHO 4: {61DB1DD7-0130-4B74-810E-BB6040C59EE5} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\ddayy
[08/08/2006, 23:02:30] - Found: HKLM\...\Winlogon\Notify\ddayy - This is probably Virtumundo.
[08/08/2006, 23:02:30] - Assigning {61DB1DD7-0130-4B74-810E-BB6040C59EE5} MSEvents Object
[08/08/2006, 23:02:30] - BHO list has been changed! Starting over...
[08/08/2006, 23:02:30] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:30] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:30] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:30] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:31] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:31] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:31] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:31] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:31] - BHO 4: {61DB1DD7-0130-4B74-810E-BB6040C59EE5} (MSEvents Object)
[08/08/2006, 23:02:31] - ALERT: Found MSEvents Object!
[08/08/2006, 23:02:31] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:02:31] - BHO 6: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:02:31] - BHO 7: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:02:31] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:02:31] - BHO 9: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:02:31] - Finished Searching Browser Helper Objects
[08/08/2006, 23:02:31] - *** Detected MSEvents Object
[08/08/2006, 23:02:31] - Trying to remove MSEvents Object...
[08/08/2006, 23:02:32] - Terminating Process: IEXPLORE.EXE
[08/08/2006, 23:02:32] - Terminating Process: RUNDLL32.EXE
[08/08/2006, 23:02:32] - Disabling Automatic Shell Restart
[08/08/2006, 23:02:32] - Terminating Process: EXPLORER.EXE
[08/08/2006, 23:02:33] - Suspending the NT Session Manager System Service
[08/08/2006, 23:02:33] - Terminating Windows NT Logon/Logoff Manager
[08/08/2006, 23:02:34] - Re-enabling Automatic Shell Restart
[08/08/2006, 23:02:34] - File to disable: C:\WINDOWS\system32\ddayy.dll
[08/08/2006, 23:02:34] - Removing HKLM\...\Browser Helper Objects\{61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Removing HKCR\CLSID\{61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Adding Kill Bit for ActiveX for GUID: {61DB1DD7-0130-4B74-810E-BB6040C59EE5}
[08/08/2006, 23:02:34] - Deleting ATLEvents/MSEvents Registry entries
[08/08/2006, 23:02:34] - Removing HKLM\...\Winlogon\Notify\ddayy
[08/08/2006, 23:02:34] - Searching for Browser Helper Objects:
[08/08/2006, 23:02:34] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:02:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:34] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:02:34] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:02:34] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:02:34] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:02:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:02:34] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:02:34] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:02:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:02:35] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:02:35] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:02:35] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:02:35] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:02:35] - Finished Searching Browser Helper Objects
[08/08/2006, 23:02:35] - Finishing up...
[08/08/2006, 23:02:35] - A restart is needed.
[08/08/2006, 23:04:20] - Attempting to Restart via STOP error (Blue Screen!)
[08/08/2006, 23:11:32] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:11:34] - Detected System Information:
[08/08/2006, 23:11:34] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:11:34] - Current Username: pops (Admin)
[08/08/2006, 23:11:34] - Windows is in NORMAL mode.
[08/08/2006, 23:11:34] - Searching for Browser Helper Objects:
[08/08/2006, 23:11:34] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:11:34] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:11:34] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:11:34] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:11:34] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:11:34] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:11:34] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:11:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:11:34] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:11:34] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:11:34] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:11:34] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:11:34] - Finished Searching Browser Helper Objects
[08/08/2006, 23:11:34] - Finishing up...
[08/08/2006, 23:11:34] - Nothing found! Exiting...
[08/08/2006, 23:12:51] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:12:52] - Detected System Information:
[08/08/2006, 23:12:52] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:12:52] - Current Username: pops (Admin)
[08/08/2006, 23:12:52] - Windows is in NORMAL mode.
[08/08/2006, 23:12:52] - Searching for Browser Helper Objects:
[08/08/2006, 23:12:52] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:12:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:12:52] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:12:52] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:12:52] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:12:52] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:12:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:12:52] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:12:52] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:12:52] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:12:52] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:12:52] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:12:53] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:12:53] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:12:53] - Finished Searching Browser Helper Objects
[08/08/2006, 23:12:53] - Finishing up...
[08/08/2006, 23:12:53] - Nothing found! Exiting...
[08/08/2006, 23:27:05] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\pops\Desktop\VirtumundoBeGone.exe" )
[08/08/2006, 23:27:08] - Detected System Information:
[08/08/2006, 23:27:08] - Windows Version: 5.1.2600, Service Pack 2
[08/08/2006, 23:27:08] - Current Username: pops (Admin)
[08/08/2006, 23:27:08] - Windows is in NORMAL mode.
[08/08/2006, 23:27:08] - Searching for Browser Helper Objects:
[08/08/2006, 23:27:08] - BHO 1: {02DCA195-602B-4B1F-83FF-381B7E804BDB} ()
[08/08/2006, 23:27:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:27:08] - Checking for HKLM\...\Winlogon\Notify\HDBHO
[08/08/2006, 23:27:08] - Key not found: HKLM\...\Winlogon\Notify\HDBHO, continuing.
[08/08/2006, 23:27:08] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[08/08/2006, 23:27:08] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[08/08/2006, 23:27:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/08/2006, 23:27:08] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[08/08/2006, 23:27:08] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[08/08/2006, 23:27:08] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[08/08/2006, 23:27:08] - BHO 5: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[08/08/2006, 23:27:08] - BHO 6: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[08/08/2006, 23:27:08] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[08/08/2006, 23:27:08] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[08/08/2006, 23:27:08] - Finished Searching Browser Helper Objects
[08/08/2006, 23:27:08] - Finishing up...
[08/08/2006, 23:27:08] - Nothing found! Exiting.
------------------------------------------------------------------------
The darn thing still pops up in Norton!
------------------------------------------------------------------------
continued below.....