I have done the following:
- Downloaded Kaspersky Anti Virus (Trial edition), I have ran through and done a system scan... it found a few trojans that were due to my younger brother downloading music files from Limewire
- Downloaded "Virtumondobegone", ran through this and I shall copy the log below
- Downloaded "Vundo Fix", ran through this earlier with no luck
- Updated Java
I have also scanned the PC with the following programs
- Spybot S&D
- Ad-awareSE
- AVG
The problem is still here I have gone into the registry myself a few times and manually removed some of the registry keys and values which are just rebuilt as soon as I restart the pc/internet.
The symptoms are as follows...
- Annoying pop-ups every now and again
- Windows Updates are turned off
- Cookies are set to the lowest settings
- Browser helper objects are also added
I did try and also update the windows (using windowsupdate.com) but due to my updates being turned off the website can't connect to them!
Please Help me!!!
Here is the log from VirtumondoBeGone
[06/30/2008, 13:49:43] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ash\Desktop\VirtumundoBeGone.exe" )
[06/30/2008, 13:49:51] - Detected System Information:
[06/30/2008, 13:49:51] - Windows Version: 5.1.2600, Service Pack 2
[06/30/2008, 13:49:51] - Current Username: Ash (Admin)
[06/30/2008, 13:49:51] - Windows is in NORMAL mode.
[06/30/2008, 13:49:51] - Searching for Browser Helper Objects:
[06/30/2008, 13:49:51] - BHO 1: {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
[06/30/2008, 13:49:51] - BHO 2: {4c2a6f8a-bc55-4d24-bf7d-467e66f09bd8} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\acdubu
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\acdubu, continuing.
[06/30/2008, 13:49:51] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[06/30/2008, 13:49:51] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/30/2008, 13:49:51] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/30/2008, 13:49:51] - BHO 6: {9358CB63-6746-4EF2-BDA5-1165FC152D1D} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\urqOecCS
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\urqOecCS, continuing.
[06/30/2008, 13:49:51] - BHO 7: {944FA61B-91B2-4A08-A465-F248B1781E2B} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\hgGWPJBs
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\hgGWPJBs, continuing.
[06/30/2008, 13:49:51] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/30/2008, 13:49:51] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/30/2008, 13:49:51] - BHO 10: {BAFFE38C-C38F-421D-A619-854106535705} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\geBrqrrQ
[06/30/2008, 13:49:51] - Found: HKLM\...\Winlogon\Notify\geBrqrrQ - This is probably Virtumundo.
[06/30/2008, 13:49:51] - Assigning {BAFFE38C-C38F-421D-A619-854106535705} MSEvents Object
[06/30/2008, 13:49:51] - BHO list has been changed! Starting over...
[06/30/2008, 13:49:51] - BHO 1: {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
[06/30/2008, 13:49:51] - BHO 2: {4c2a6f8a-bc55-4d24-bf7d-467e66f09bd8} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\acdubu
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\acdubu, continuing.
[06/30/2008, 13:49:51] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[06/30/2008, 13:49:51] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/30/2008, 13:49:51] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/30/2008, 13:49:51] - BHO 6: {9358CB63-6746-4EF2-BDA5-1165FC152D1D} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\urqOecCS
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\urqOecCS, continuing.
[06/30/2008, 13:49:51] - BHO 7: {944FA61B-91B2-4A08-A465-F248B1781E2B} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\hgGWPJBs
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\hgGWPJBs, continuing.
[06/30/2008, 13:49:51] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/30/2008, 13:49:51] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/30/2008, 13:49:51] - BHO 10: {BAFFE38C-C38F-421D-A619-854106535705} (MSEvents Object)
[06/30/2008, 13:49:51] - ALERT: Found MSEvents Object!
[06/30/2008, 13:49:51] - BHO 11: {C4DBDFC8-DCE8-403E-A2BA-21FBB5A033C9} ()
[06/30/2008, 13:49:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:51] - Checking for HKLM\...\Winlogon\Notify\yayxwTJB
[06/30/2008, 13:49:51] - Key not found: HKLM\...\Winlogon\Notify\yayxwTJB, continuing.
[06/30/2008, 13:49:51] - Finished Searching Browser Helper Objects
[06/30/2008, 13:49:51] - *** Detected MSEvents Object
[06/30/2008, 13:49:51] - Trying to remove MSEvents Object...
[06/30/2008, 13:49:52] - Terminating Process: IEXPLORE.EXE
[06/30/2008, 13:49:52] - Terminating Process: RUNDLL32.EXE
[06/30/2008, 13:49:53] - Disabling Automatic Shell Restart
[06/30/2008, 13:49:53] - Terminating Process: EXPLORER.EXE
[06/30/2008, 13:49:53] - Suspending the NT Session Manager System Service
[06/30/2008, 13:49:53] - Terminating Windows NT Logon/Logoff Manager
[06/30/2008, 13:49:53] - Re-enabling Automatic Shell Restart
[06/30/2008, 13:49:53] - File to disable: C:\WINDOWS\system32\geBrqrrQ.dll
[06/30/2008, 13:49:53] - Renaming C:\WINDOWS\system32\geBrqrrQ.dll -> C:\WINDOWS\system32\geBrqrrQ.dll.vir
[06/30/2008, 13:49:53] - File successfully renamed!
[06/30/2008, 13:49:53] - Removing HKLM\...\Browser Helper Objects\{BAFFE38C-C38F-421D-A619-854106535705}
[06/30/2008, 13:49:53] - Removing HKCR\CLSID\{BAFFE38C-C38F-421D-A619-854106535705}
[06/30/2008, 13:49:53] - Adding Kill Bit for ActiveX for GUID: {BAFFE38C-C38F-421D-A619-854106535705}
[06/30/2008, 13:49:53] - Deleting ATLEvents/MSEvents Registry entries
[06/30/2008, 13:49:53] - Removing HKLM\...\Winlogon\Notify\geBrqrrQ
[06/30/2008, 13:49:53] - Searching for Browser Helper Objects:
[06/30/2008, 13:49:53] - BHO 1: {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
[06/30/2008, 13:49:53] - BHO 2: {4c2a6f8a-bc55-4d24-bf7d-467e66f09bd8} ()
[06/30/2008, 13:49:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:53] - Checking for HKLM\...\Winlogon\Notify\acdubu
[06/30/2008, 13:49:53] - Key not found: HKLM\...\Winlogon\Notify\acdubu, continuing.
[06/30/2008, 13:49:53] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[06/30/2008, 13:49:53] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/30/2008, 13:49:53] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/30/2008, 13:49:53] - BHO 6: {9358CB63-6746-4EF2-BDA5-1165FC152D1D} ()
[06/30/2008, 13:49:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:53] - Checking for HKLM\...\Winlogon\Notify\urqOecCS
[06/30/2008, 13:49:53] - Key not found: HKLM\...\Winlogon\Notify\urqOecCS, continuing.
[06/30/2008, 13:49:53] - BHO 7: {944FA61B-91B2-4A08-A465-F248B1781E2B} ()
[06/30/2008, 13:49:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:53] - Checking for HKLM\...\Winlogon\Notify\hgGWPJBs
[06/30/2008, 13:49:53] - Key not found: HKLM\...\Winlogon\Notify\hgGWPJBs, continuing.
[06/30/2008, 13:49:53] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/30/2008, 13:49:53] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/30/2008, 13:49:53] - BHO 10: {C4DBDFC8-DCE8-403E-A2BA-21FBB5A033C9} ()
[06/30/2008, 13:49:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 13:49:53] - Checking for HKLM\...\Winlogon\Notify\yayxwTJB
[06/30/2008, 13:49:53] - Key not found: HKLM\...\Winlogon\Notify\yayxwTJB, continuing.
[06/30/2008, 13:49:53] - Finished Searching Browser Helper Objects
[06/30/2008, 13:49:53] - Finishing up...
[06/30/2008, 13:49:53] - A restart is needed.
[06/30/2008, 13:49:53] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[06/30/2008, 13:50:11] - Attempting to Restart via STOP error (Blue Screen!)
[06/30/2008, 19:44:59] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ash\Desktop\VirtumundoBeGone.exe" )
[06/30/2008, 19:45:02] - Detected System Information:
[06/30/2008, 19:45:02] - Windows Version: 5.1.2600, Service Pack 2
[06/30/2008, 19:45:02] - Current Username: Ash (Admin)
[06/30/2008, 19:45:02] - Windows is in NORMAL mode.
[06/30/2008, 19:45:03] - Searching for Browser Helper Objects:
[06/30/2008, 19:45:03] - BHO 1: {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
[06/30/2008, 19:45:03] - BHO 2: {4c2a6f8a-bc55-4d24-bf7d-467e66f09bd8} ()
[06/30/2008, 19:45:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 19:45:03] - Checking for HKLM\...\Winlogon\Notify\acdubu
[06/30/2008, 19:45:03] - Key not found: HKLM\...\Winlogon\Notify\acdubu, continuing.
[06/30/2008, 19:45:03] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[06/30/2008, 19:45:03] - BHO 4: {5B00702D-9C04-4DCC-8825-87FA2905F1E6} ()
[06/30/2008, 19:45:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 19:45:03] - Checking for HKLM\...\Winlogon\Notify\urqOecCS
[06/30/2008, 19:45:03] - Key not found: HKLM\...\Winlogon\Notify\urqOecCS, continuing.
[06/30/2008, 19:45:03] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/30/2008, 19:45:03] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/30/2008, 19:45:03] - BHO 7: {9358CB63-6746-4EF2-BDA5-1165FC152D1D} ()
[06/30/2008, 19:45:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 19:45:03] - No filename found. Continuing.
[06/30/2008, 19:45:03] - BHO 8: {944FA61B-91B2-4A08-A465-F248B1781E2B} ()
[06/30/2008, 19:45:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 19:45:03] - Checking for HKLM\...\Winlogon\Notify\hgGWPJBs
[06/30/2008, 19:45:03] - Key not found: HKLM\...\Winlogon\Notify\hgGWPJBs, continuing.
[06/30/2008, 19:45:03] - BHO 9: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/30/2008, 19:45:03] - BHO 10: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/30/2008, 19:45:03] - BHO 11: {C4DBDFC8-DCE8-403E-A2BA-21FBB5A033C9} ()
[06/30/2008, 19:45:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/30/2008, 19:45:03] - Checking for HKLM\...\Winlogon\Notify\yayxwTJB
[06/30/2008, 19:45:03] - Key not found: HKLM\...\Winlogon\Notify\yayxwTJB, continuing.
[06/30/2008, 19:45:03] - Finished Searching Browser Helper Objects
[06/30/2008, 19:45:03] - Finishing up...
[06/30/2008, 19:45:03] - Nothing found! Exiting...
Thanks for your time - it's very much appreciated
Edited by greyknight17, 17 July 2008 - 09:42 AM.