[11/26/2005, 11:27:04] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:04] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:04] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:04] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:04] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:04] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:04] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:04] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:04] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:04] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:04] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:04] - Found MSEvents Object!
[11/26/2005, 11:27:04] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:04] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:04] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:04] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:04] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:05] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:06] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:06] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:06] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:06] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:07] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:07] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:07] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:07] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:07] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:07] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:07] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:07] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:07] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:07] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:08] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:08] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:08] - Found MSEvents Object!
[11/26/2005, 11:27:08] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:08] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:08] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:10] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:10] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:11] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:11] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:11] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:11] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:11] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:11] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:11] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:11] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:11] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:11] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:11] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:11] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:11] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:11] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:11] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:11] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:11] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:11] - Found MSEvents Object!
[11/26/2005, 11:27:11] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:11] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:11] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:11] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:11] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:13] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:13] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:13] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:13] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:14] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:14] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:14] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:16] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:16] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:16] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:16] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:16] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:16] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:16] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:17] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:17] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:17] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:17] - Found MSEvents Object!
[11/26/2005, 11:27:17] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:17] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:17] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:18] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:18] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:19] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:19] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:19] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:20] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:20] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:20] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:20] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:21] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:21] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:21] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:21] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:21] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:21] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:21] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:21] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:21] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:21] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:21] - Found MSEvents Object!
[11/26/2005, 11:27:21] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:21] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:22] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:22] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:22] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:22] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:23] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:23] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:23] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:23] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:23] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:23] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:24] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:24] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:24] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:24] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:24] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:24] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:24] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:25] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:28] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:28] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:28] - Found MSEvents Object!
[11/26/2005, 11:27:28] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:28] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:28] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:28] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:28] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:28] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:28] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:28] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:28] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:29] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:29] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:29] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:30] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:30] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:31] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:31] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:31] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:31] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:31] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:31] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:31] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:31] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:31] - Found MSEvents Object!
[11/26/2005, 11:27:31] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:31] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:31] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:31] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:31] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:32] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:32] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:32] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:32] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:33] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:33] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:33] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:35] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:35] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:35] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:35] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:35] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:35] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:35] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:36] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:36] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:36] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:36] - Found MSEvents Object!
[11/26/2005, 11:27:36] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:36] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:36] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:36] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:36] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:37] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:37] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:37] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:37] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:37] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:37] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:37] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:38] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:38] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:39] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:39] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:39] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:39] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:39] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:39] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:39] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:39] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:39] - Found MSEvents Object!
[11/26/2005, 11:27:39] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:39] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:39] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:40] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:40] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:41] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:41] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:41] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:41] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:41] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:41] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:41] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:44] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:44] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:44] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:44] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:44] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:44] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:44] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:45] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:46] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:46] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:46] - Found MSEvents Object!
[11/26/2005, 11:27:46] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:46] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:46] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:46] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:46] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:47] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:47] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:47] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:47] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:47] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:47] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:47] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:47] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:47] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:47] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:47] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:47] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:47] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:47] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:47] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:47] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:47] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:47] - Found MSEvents Object!
[11/26/2005, 11:27:47] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:47] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:47] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:47] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:47] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:48] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:49] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:49] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:49] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:49] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:49] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:49] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:50] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:50] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:50] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:50] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:50] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:50] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:50] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:50] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:51] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:51] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:51] - Found MSEvents Object!
[11/26/2005, 11:27:51] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:51] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:51] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:51] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:52] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:53] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:53] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:53] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:53] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:53] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:27:53] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:53] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:55] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:27:55] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:27:55] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:55] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:27:55] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:27:55] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:27:55] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:27:55] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:27:55] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:27:55] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:27:55] - Found MSEvents Object!
[11/26/2005, 11:27:55] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:55] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:27:55] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:55] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:27:55] - Disabling Automatic Shell Restart
[11/26/2005, 11:27:55] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:27:55] - Suspending the NT Session Manager System Service
[11/26/2005, 11:27:56] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:27:56] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:27:56] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:27:56] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:27:56] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:57] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:27:57] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:27:57] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:57] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:27:57] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:27:57] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:27:57] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:27:58] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:27:59] - BHO list has been changed! Starting over...
[11/26/2005, 11:27:59] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:27:59] - Found MSEvents Object!
[11/26/2005, 11:27:59] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:59] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:27:59] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:27:59] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:00] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:00] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:00] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:00] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:00] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:00] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:00] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:00] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:00] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:00] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:00] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:00] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:00] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:00] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:00] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:00] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:00] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:01] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:01] - Found MSEvents Object!
[11/26/2005, 11:28:01] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:01] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:01] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:01] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:01] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:02] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:02] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:02] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:02] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:03] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:03] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:03] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:03] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:03] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:03] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:03] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:03] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:03] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:03] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:03] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:04] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:04] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:04] - Found MSEvents Object!
[11/26/2005, 11:28:04] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:04] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:04] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:04] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:04] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:05] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:05] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:05] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:05] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:05] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:05] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:05] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:07] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:07] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:08] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:08] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:08] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:08] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:08] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:08] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:08] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:09] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:09] - Found MSEvents Object!
[11/26/2005, 11:28:09] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:09] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:09] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:09] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:09] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:10] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:10] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:10] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:11] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:11] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:12] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:12] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:13] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:13] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:13] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:13] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:13] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:13] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:13] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:14] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:14] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:14] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:14] - Found MSEvents Object!
[11/26/2005, 11:28:14] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:14] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:14] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:14] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:14] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:14] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:15] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:15] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:15] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:15] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:15] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:15] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:17] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:17] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:17] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:17] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:17] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:17] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:17] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:17] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:17] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:17] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:17] - Found MSEvents Object!
[11/26/2005, 11:28:17] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:17] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:17] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:18] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:18] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:18] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:19] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:19] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:19] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:19] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:19] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:19] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:21] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:21] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:22] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:22] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:22] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:22] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:22] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:22] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:23] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:23] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:23] - Found MSEvents Object!
[11/26/2005, 11:28:23] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:23] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:23] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:24] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:24] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:24] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:24] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:24] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:24] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:25] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:25] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:25] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:26] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:26] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:27] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:27] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:27] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:27] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:27] - Couldn't find ddayy in Winlogon Notify. Ignoring {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}.
[11/26/2005, 11:28:27] - 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:27] - 3: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:27] - WARNING: 3: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:27] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:27] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:27] - 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:27] - 5: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:27] - Found MSEvents Object!
[11/26/2005, 11:28:27] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:27] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:27] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:27] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:27] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:27] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:27] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:27] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:27] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:28] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:28] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:28] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:32] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:32] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:32] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:32] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:32] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:32] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:32] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:32] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:33] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:33] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:33] - Found MSEvents Object!
[11/26/2005, 11:28:33] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:33] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:33] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:33] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:33] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:33] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:33] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:33] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:33] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:34] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:34] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:34] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:34] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:34] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:34] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:34] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:34] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:34] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:34] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:34] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:34] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:34] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:34] - Found MSEvents Object!
[11/26/2005, 11:28:34] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:34] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:34] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:34] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:34] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:35] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:35] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:35] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:35] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:36] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:36] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:36] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:36] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:36] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:36] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:36] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:36] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:36] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:36] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:37] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:38] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:38] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:38] - Found MSEvents Object!
[11/26/2005, 11:28:38] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:38] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:38] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:38] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:38] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:38] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:38] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:38] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:38] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:39] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:39] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:39] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:40] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:40] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:41] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:41] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:41] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:41] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:41] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:41] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:41] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:41] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:41] - Found MSEvents Object!
[11/26/2005, 11:28:41] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:41] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:41] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:41] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:41] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:41] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:41] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:41] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:42] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:42] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:42] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:42] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:42] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:42] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:42] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:42] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:42] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:42] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:42] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:42] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:44] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:44] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:44] - Found MSEvents Object!
[11/26/2005, 11:28:44] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:44] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:44] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:44] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:44] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:44] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:44] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:44] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:45] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:45] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:46] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:46] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:46] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:46] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:46] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:46] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:46] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:46] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:46] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:46] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:46] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:46] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:46] - Found MSEvents Object!
[11/26/2005, 11:28:46] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:46] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:46] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:46] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:46] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:46] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:46] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:46] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:47] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:47] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:48] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:48] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:48] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:48] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:48] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:48] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:48] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:48] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:48] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:49] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:50] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:50] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:50] - Found MSEvents Object!
[11/26/2005, 11:28:50] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:50] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:50] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:50] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:50] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:50] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:50] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:50] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:51] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:51] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:28:51] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:51] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:52] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:28:52] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:28:52] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:52] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:28:52] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:28:52] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:28:52] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:28:52] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:28:52] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:28:52] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:28:52] - Found MSEvents Object!
[11/26/2005, 11:28:52] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:52] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:28:52] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:53] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:53] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:54] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:54] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:54] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:54] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:28:55] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:28:56] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:28:56] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:58] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:28:58] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:28:58] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:58] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:28:58] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:28:58] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:28:58] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:28:58] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:28:59] - BHO list has been changed! Starting over...
[11/26/2005, 11:28:59] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:28:59] - Found MSEvents Object!
[11/26/2005, 11:28:59] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:59] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:28:59] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:28:59] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:28:59] - Disabling Automatic Shell Restart
[11/26/2005, 11:28:59] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:28:59] - Suspending the NT Session Manager System Service
[11/26/2005, 11:28:59] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:28:59] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:29:00] - Renaming C:\WINDOWS\system32\ddayy.dll -> C:\WINDOWS\system32\ddayy.dll.vir
[11/26/2005, 11:29:00] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:29:00] - Removing Registry references to {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:29:00] - Adding Internet Explorer Protection (Kill ActiveX) for {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
[11/26/2005, 11:29:00] - Removing Winlogon Notify Entry: ddayy
[11/26/2005, 11:29:00] - BHO list has been changed! Starting over...
[11/26/2005, 11:29:00] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/26/2005, 11:29:00] - 2: {53707962-6F74-2D53-2644-206D7942484F} -
[11/26/2005, 11:29:00] - WARNING: 2: {53707962-6F74-2D53-2644-206D7942484F} - BHO Name is blank.
[11/26/2005, 11:29:00] - Checking for WinLogon Notify reference. (File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
[11/26/2005, 11:29:00] - Couldn't find SDHelper in Winlogon Notify. Ignoring {53707962-6F74-2D53-2644-206D7942484F}.
[11/26/2005, 11:29:00] - 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper
[11/26/2005, 11:29:00] - 4: {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - MSEvents Object
[11/26/2005, 11:29:00] - Found MSEvents Object!
[11/26/2005, 11:29:00] - File location: C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:29:00] - Attempting to kill C:\WINDOWS\system32\jkhfe.dll
[11/26/2005, 11:29:00] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:29:01] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:29:01] - Disabling Automatic Shell Restart
[11/26/2005, 11:29:02] - Terminating Process: EXPLORER.EXE
[11/26/2005, 11:29:02] - Suspending the NT Session Manager System Service
[11/26/2005, 11:29:02] - Terminating Windows NT Logon/Logoff Manager
[11/26/2005, 11:29:02] - Re-enabling Automatic Shell Restart
[11/26/2005, 11:29:02] - Renaming C:\WINDOWS\system32\jkhfe.dll -> C:\WINDOWS\system32\jkhfe.dll.vir
[11/26/2005, 11:29:03] - File rename was unsucessful. Rename operation sent to SMSS for next reboot.
[11/26/2005, 11:29:03] - Removing Registry references to {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:29:05] - Adding Internet Explorer Protection (Kill ActiveX) for {FC148228-87E1-4D00-AC06-58DCAA52A4D1}
[11/26/2005, 11:29:05] - Removing Winlogon Notify Entry: jkhfe
[11/26/2005, 11:29:06] - BHO list has been changed! Starting over...
[11/26/2005, 11:29:06] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -
[11/26/2005, 11:29:06] - WARNING: 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - BHO Name is blank.
[11/26/2005, 11:29:06] - Checking for WinLogon Notify reference. (File: C:\WINDOWS\system32\ddayy.dll)
[11/26/2005, 11:29:06] - Found a reference to C:\WINDOWS\system32\ddayy.dll in Winlogon Notify! This is most likely Virtumundo!
[11/26/2005, 11:29:06] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
[11/26/2005, 11:29:07] - BHO list has been changed! Starting over...
[11/26/2005, 11:29:07] - 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - MSEvents Object
[11/26/2005, 11:29:07] - Found MSEvents Object!
[11/26/2005, 11:29:07] - File location: C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:29:07] - Attempting to kill C:\WINDOWS\system32\ddayy.dll
[11/26/2005, 11:29:07] - Terminating Process: RUNDLL32.EXE
[11/26/2005, 11:29:07] - Terminating Process: IEXPLORE.EXE
[11/26/2005, 11:29:07] - Disabling Automatic Shell Restart
[11/26/2005, 11:29:07] - Terminating Pro