[11/26/2005, 11:07:35] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:07:35] - Found MSEvents Object!
[11/26/2005, 11:07:35] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:35] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:35] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:36] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:36] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:37] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:37] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:37] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:37] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:38] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:07:38] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:38] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:39] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:39] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:07:39] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:39] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:07:39] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:07:39] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:07:39] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:07:39] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:07:40] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:40] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:07:40] - Found MSEvents Object!
[11/26/2005, 11:07:40] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:40] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:40] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:40] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:40] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:41] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:41] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:41] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:41] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:41] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:07:41] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:41] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:43] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:43] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:07:43] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:43] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:07:43] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:07:43] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:07:43] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:07:43] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:07:43] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:07:43] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:07:43] - Found MSEvents Object!
[11/26/2005, 11:07:43] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:43] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:43] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:43] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:43] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:44] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:44] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:44] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:44] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:44] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:07:45] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:45] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:45] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:45] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:07:45] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:45] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:07:45] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:07:45] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:07:45] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:07:46] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:07:46] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:46] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:07:46] - Found MSEvents Object!
[11/26/2005, 11:07:46] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:46] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:46] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:46] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:46] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:47] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:47] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:47] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:47] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:48] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:07:49] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:49] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:49] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:49] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:07:49] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:49] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:07:49] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:07:49] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:07:49] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:07:49] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:07:49] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:07:49] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:07:49] - Found MSEvents Object!
[11/26/2005, 11:07:49] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:49] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:07:49] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:49] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:49] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:50] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:50] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:50] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:50] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:50] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:07:51] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:51] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:53] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:07:53] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:07:53] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:53] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:07:53] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:07:53] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:07:53] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:07:54] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:07:56] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:56] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:07:56] - Found MSEvents Object!
[11/26/2005, 11:07:56] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:56] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:07:56] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:07:56] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:07:56] - Disabling Automatic Shell Restart
[11/26/2005, 11:07:56] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:07:57] - Suspending the NT Session Manager System Service
[11/26/2005, 11:07:57] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:07:57] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:07:57] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:07:57] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:07:57] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:59] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:07:59] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:07:59] - BHO list has been changed! Starting over...
[11/26/2005, 11:07:59] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:07:59] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:07:59] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:07:59] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:07:59] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:07:59] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:07:59] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:07:59] - Found MSEvents Object!
[11/26/2005, 11:08:00] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:00] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:00] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:00] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:00] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:01] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:01] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:01] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:01] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:01] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:02] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:02] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:02] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:02] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:02] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:02] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:02] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:02] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:02] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:03] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:04] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:04] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:04] - Found MSEvents Object!
[11/26/2005, 11:08:04] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:04] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:04] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:04] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:04] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:05] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:05] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:05] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:05] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:06] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:06] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:06] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:06] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:06] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:06] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:06] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:06] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:06] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:06] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:06] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:06] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:06] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:06] - Found MSEvents Object!
[11/26/2005, 11:08:06] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:06] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:06] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:06] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:06] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:07] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:08] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:08] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:08] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:09] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:09] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:09] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:10] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:10] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:10] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:10] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:10] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:11] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:11] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:11] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:11] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:11] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:11] - Found MSEvents Object!
[11/26/2005, 11:08:11] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:11] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:11] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:11] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:11] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:12] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:13] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:13] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:13] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:14] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:14] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:14] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:14] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:14] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:15] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:15] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:15] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:15] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:15] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:15] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:15] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:15] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:15] - Found MSEvents Object!
[11/26/2005, 11:08:15] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:15] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:15] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:16] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:16] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:16] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:16] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:16] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:17] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:17] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:17] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:17] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:21] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:21] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:21] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:21] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:21] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:21] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:21] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:21] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:22] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:22] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:22] - Found MSEvents Object!
[11/26/2005, 11:08:22] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:22] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:22] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:22] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:22] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:22] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:22] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:22] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:22] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:23] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:23] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:23] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:24] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:24] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:24] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:24] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:24] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:24] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:25] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:25] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:25] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:25] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:25] - Found MSEvents Object!
[11/26/2005, 11:08:25] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:25] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:25] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:25] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:25] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:25] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:25] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:25] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:26] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:26] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:26] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:26] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:26] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:26] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:26] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:26] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:26] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:26] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:26] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:26] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:27] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:27] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:27] - Found MSEvents Object!
[11/26/2005, 11:08:27] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:27] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:27] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:27] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:27] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:28] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:28] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:28] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:28] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:29] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:29] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:29] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:30] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:30] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:30] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:30] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:30] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:30] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:30] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:30] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:30] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:30] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:30] - Found MSEvents Object!
[11/26/2005, 11:08:30] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:30] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:30] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:30] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:30] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:31] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:32] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:32] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:32] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:32] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:32] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:32] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:36] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:36] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:37] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:37] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:37] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:37] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:37] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:37] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:38] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:38] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:38] - Found MSEvents Object!
[11/26/2005, 11:08:38] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:38] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:38] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:38] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:38] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:38] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:38] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:39] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:39] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:39] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:39] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:39] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:39] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:39] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:39] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:39] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:39] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:39] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:39] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:39] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:39] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:39] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:39] - Found MSEvents Object!
[11/26/2005, 11:08:39] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:39] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:39] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:39] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:39] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:40] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:41] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:41] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:41] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:41] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:41] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:41] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:41] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:41] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:41] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:41] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:41] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:42] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:42] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:43] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:43] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:43] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:43] - Found MSEvents Object!
[11/26/2005, 11:08:43] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:43] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:43] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:43] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:43] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:43] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:44] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:44] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:44] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:44] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:44] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:44] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:44] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:44] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:44] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:44] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:44] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:44] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:44] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:44] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:44] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:44] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:44] - Found MSEvents Object!
[11/26/2005, 11:08:44] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:44] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:44] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:44] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:44] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:45] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:45] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:45] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:45] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:46] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:46] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:46] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:49] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:49] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:49] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:49] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:49] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:49] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:49] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:50] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:51] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:51] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:51] - Found MSEvents Object!
[11/26/2005, 11:08:51] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:51] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:51] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:51] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:51] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:52] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:52] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:52] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:52] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:52] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:08:52] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:52] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:54] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:08:54] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:08:54] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:54] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:08:54] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:08:54] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:08:54] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:08:54] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:08:54] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:08:54] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:08:54] - Found MSEvents Object!
[11/26/2005, 11:08:54] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:54] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:08:54] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:55] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:55] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:55] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:56] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:56] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:56] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:56] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:08:56] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:08:56] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:56] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:08:56] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:08:56] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:56] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:08:56] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:08:56] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:08:56] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:08:56] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:08:57] - BHO list has been changed! Starting over...
[11/26/2005, 11:08:57] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:08:57] - Found MSEvents Object!
[11/26/2005, 11:08:57] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:57] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:08:57] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:08:57] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:08:58] - Disabling Automatic Shell Restart
[11/26/2005, 11:08:58] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:08:58] - Suspending the NT Session Manager System Service
[11/26/2005, 11:08:59] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:08:59] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:08:59] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:01] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:01] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:01] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:01] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:01] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:01] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:01] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:01] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:01] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:01] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:01] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:01] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:09:01] - Found MSEvents Object!
[11/26/2005, 11:09:01] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:01] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:01] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:01] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:02] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:03] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:03] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:03] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:03] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:03] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:09:03] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:03] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:04] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:04] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:09:04] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:04] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:09:04] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:09:04] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:09:04] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:09:04] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:09:05] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:05] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:09:05] - Found MSEvents Object!
[11/26/2005, 11:09:05] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:05] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:05] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:05] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:05] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:06] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:06] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:06] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:06] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:06] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:06] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:06] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:07] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:07] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:07] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:07] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:07] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:07] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:07] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:07] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:07] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:07] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:09:07] - Found MSEvents Object!
[11/26/2005, 11:09:07] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:07] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:07] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:07] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:07] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:07] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:07] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:08] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:08] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:09] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:09:09] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:09] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:12] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:12] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:09:12] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:12] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:09:12] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:09:12] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:09:12] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:09:12] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:09:12] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:12] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:09:12] - Found MSEvents Object!
[11/26/2005, 11:09:12] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:12] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:12] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:13] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:13] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:14] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:14] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:14] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:15] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:15] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:15] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:15] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:15] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:15] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:15] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:15] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:15] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:15] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:15] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:15] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:15] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:15] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:09:15] - Found MSEvents Object!
[11/26/2005, 11:09:15] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:15] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:15] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:16] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:16] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:16] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:16] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:16] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:16] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:18] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:09:18] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:18] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:20] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:20] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:09:20] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:20] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:09:20] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:09:20] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:09:20] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:09:21] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:09:21] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:21] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:09:21] - Found MSEvents Object!
[11/26/2005, 11:09:21] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:21] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:21] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:21] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:21] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:22] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:22] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:22] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:22] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:22] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:22] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:22] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:22] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:22] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:22] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:22] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:22] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:22] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:22] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:22] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:22] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:22] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:09:22] - Found MSEvents Object!
[11/26/2005, 11:09:22] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:22] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:22] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:22] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:22] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:23] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:23] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:24] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:24] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:24] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:09:24] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:24] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:26] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:26] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:09:26] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:26] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:09:26] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:09:26] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:09:26] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:09:26] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:09:26] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:26] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:09:26] - Found MSEvents Object!
[11/26/2005, 11:09:26] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:26] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:26] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:27] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:27] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:27] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:27] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:27] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:27] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:27] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:27] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:27] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:28] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:28] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:29] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:29] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:29] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:29] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:29] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:29] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:29] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:29] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:09:29] - Found MSEvents Object!
[11/26/2005, 11:09:29] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:29] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:09:29] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:29] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:29] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:29] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:29] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:29] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:30] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:30] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:09:31] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:31] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:33] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:09:33] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:09:33] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:34] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:09:34] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:09:34] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:09:34] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:09:35] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:09:36] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:36] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:09:36] - Found MSEvents Object!
[11/26/2005, 11:09:36] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:36] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:09:36] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:09:36] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:09:36] - Disabling Automatic Shell Restart
[11/26/2005, 11:09:36] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:09:36] - Suspending the NT Session Manager System Service
[11/26/2005, 11:09:36] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:09:36] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:09:36] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:09:36] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:09:36] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:37] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:09:37] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:09:37] - BHO list has been changed! Starting over...
[11/26/2005, 11:09:37] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:09:37] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:09:37] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:09:37] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:09:37] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:09:37] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:09:37] - 4: {