3 Apprentice

 • 

15.6K Posts

December 31st, 2005 17:00

among other things, I see a WinFixer [trojan vundo/virtumundo]  problem... let's start with that:
 
download VirtumundoBeGone from:

http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

* Save it to your Desktop
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Follow the directions as indicated

please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.

just reboot if your system "jams"

*********************

It's now time to report back to us:

VirtumundoBeGone  generated a "log" file of its own, which it should have placed on your Desktop... please REPLY to this thread, and copy/paste the VirtumundoBeGone log back here, along with your latest HJT log.

 

12 Posts

December 31st, 2005 19:00

thank you very much, my computer seems to running ok now thank you.

12 Posts

December 31st, 2005 19:00

[12/31/2005, 12:57:26] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Owner.JORDAN.000\Desktop\VirtumundoBeGone.exe" )
[12/31/2005, 12:57:38] - Detected System Information:
[12/31/2005, 12:57:38] - Windows Version: 5.1.2600, Service Pack 2
[12/31/2005, 12:57:38] - Current Username: Owner (Admin)
[12/31/2005, 12:57:38] - Windows is in NORMAL mode.
[12/31/2005, 12:57:38] - Searching for Browser Helper Objects:
[12/31/2005, 12:57:38] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/31/2005, 12:57:38] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/31/2005, 12:57:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/31/2005, 12:57:38] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/31/2005, 12:57:38] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/31/2005, 12:57:38] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[12/31/2005, 12:57:38] - BHO 4: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
[12/31/2005, 12:57:38] - BHO 5: {B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
[12/31/2005, 12:57:38] - BHO 6: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class)
[12/31/2005, 12:57:38] - BHO 7: {CE70731D-F28D-4D81-9D61-C8EE60378401} (MSEvents Object)
[12/31/2005, 12:57:38] - ALERT: Found MSEvents Object!
[12/31/2005, 12:57:38] - Finished Searching Browser Helper Objects
[12/31/2005, 12:57:38] - *** Detected MSEvents Object
[12/31/2005, 12:57:38] - Trying to remove MSEvents Object...
[12/31/2005, 12:57:39] - Terminating Process: IEXPLORE.EXE
[12/31/2005, 12:57:41] - Terminating Process: RUNDLL32.EXE
[12/31/2005, 12:57:41] - Disabling Automatic Shell Restart
[12/31/2005, 12:57:42] - Terminating Process: EXPLORER.EXE
[12/31/2005, 12:57:44] - Suspending the NT Session Manager System Service
[12/31/2005, 12:57:44] - Terminating Windows NT Logon/Logoff Manager
[12/31/2005, 12:57:45] - Re-enabling Automatic Shell Restart
[12/31/2005, 12:57:45] - File to disable: C:\WINDOWS\system32\pmkjh.dll
[12/31/2005, 12:57:45] - Renaming C:\WINDOWS\system32\pmkjh.dll -> C:\WINDOWS\system32\pmkjh.dll.vir
[12/31/2005, 12:57:47] - File successfully renamed!
[12/31/2005, 12:57:47] - Removing HKLM\...\Browser Helper Objects\{CE70731D-F28D-4D81-9D61-C8EE60378401}
[12/31/2005, 12:57:48] - Removing HKCR\CLSID\{CE70731D-F28D-4D81-9D61-C8EE60378401}
[12/31/2005, 12:57:49] - Adding Kill Bit for ActiveX for GUID: {CE70731D-F28D-4D81-9D61-C8EE60378401}
[12/31/2005, 12:57:50] - Deleting ATLEvents/MSEvents Registry entries
[12/31/2005, 12:57:50] - Removing HKLM\...\Winlogon\Notify\pmkjh
[12/31/2005, 12:57:51] - Searching for Browser Helper Objects:
[12/31/2005, 12:57:51] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/31/2005, 12:57:51] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/31/2005, 12:57:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/31/2005, 12:57:51] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/31/2005, 12:57:51] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/31/2005, 12:57:51] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[12/31/2005, 12:57:51] - BHO 4: {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
[12/31/2005, 12:57:51] - BHO 5: {B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
[12/31/2005, 12:57:51] - BHO 6: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class)
[12/31/2005, 12:57:52] - Finished Searching Browser Helper Objects
[12/31/2005, 12:57:52] - Finishing up...
[12/31/2005, 12:57:52] - A restart is needed.
[12/31/2005, 12:57:52] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[12/31/2005, 12:58:03] - Attempting to Restart via STOP error (Blue Screen!)

3 Apprentice

 • 

15.6K Posts

December 31st, 2005 19:00

based on the VBG log, it looks like VirtumundoBeGone successfully deactivated the bad WinFixer/vundo file. Have you noticed any difference, in terms of WinFixer popups, warning messages about trojan vundo/virtumundo, and/or overall system speed/performance?
 
are you experiencing any other problems???   if you'd like further analysis (most likely by someone else), you should post an updated/revised HJT log, REPLYing to this thread.
No Events found!

Top