Spybot found Virtumondo on my PC. I ried to remove it with VundoFix then
TrojanVundoRemovalTool, then Virtuojmondo be gone and finally I run ComboFix. Not sure whether I succeded. Can someone have look at the following logs please?..
Cheers
yAro
VundoFix
VundoFix V7.0.6
Scan started at 13:17:46 06/08/2008
Listing files found while scanning…
C:\Windows\system32\cbXnkLff.dll
C:\Windows\system32\dlnpbwcq.dll
C:\Windows\system32\evzbny.dll
C:\Windows\system32\ffLknXbc.ini
C:\Windows\system32\ffLknXbc.ini2
C:\Windows\system32\hbrmutjf.dll
C:\Windows\system32\iifefDUN.dll
C:\Windows\system32\jxrnzm.dll
C:\Windows\system32\jyqfefsm.dll
C:\Windows\system32\kyvjwkvm.dll
C:\Windows\system32\mbtkynqm.dll
C:\Windows\system32\msfefqyj.tmp
C:\Windows\system32\mvkwjvyk.ini
C:\Windows\system32\mvkwjvyk.ini2
C:\Windows\system32\mvkwjvyk.tmp
C:\Windows\system32\swfrtldt.dll
C:\Windows\system32\xcloee.dll
C:\Windows\system32\xgfwekbd.dll
C:\Windows\system32\xxyxYrQj.dll
C:\Windows\system32\ydidfcwd.dll
Beginning removal…
Attempting to delete C:\Windows\system32\cbXnkLff.dll
C:\Windows\system32\cbXnkLff.dll Has been deleted!
Attempting to delete C:\Windows\system32\dlnpbwcq.dll
C:\Windows\system32\dlnpbwcq.dll Has been deleted!
Attempting to delete C:\Windows\system32\evzbny.dll
C:\Windows\system32\evzbny.dll Has been deleted!
Attempting to delete C:\Windows\system32\ffLknXbc.ini
C:\Windows\system32\ffLknXbc.ini Has been deleted!
Attempting to delete C:\Windows\system32\ffLknXbc.ini2
C:\Windows\system32\ffLknXbc.ini2 Has been deleted!
Attempting to delete C:\Windows\system32\hbrmutjf.dll
C:\Windows\system32\hbrmutjf.dll Has been deleted!
Attempting to delete C:\Windows\system32\iifefDUN.dll
C:\Windows\system32\iifefDUN.dll Could not be deleted.
Attempting to delete C:\Windows\system32\jxrnzm.dll
C:\Windows\system32\jxrnzm.dll Has been deleted!
Attempting to delete C:\Windows\system32\jyqfefsm.dll
C:\Windows\system32\jyqfefsm.dll Has been deleted!
Attempting to delete C:\Windows\system32\kyvjwkvm.dll
C:\Windows\system32\kyvjwkvm.dll Has been deleted!
Attempting to delete C:\Windows\system32\mbtkynqm.dll
C:\Windows\system32\mbtkynqm.dll Has been deleted!
Attempting to delete C:\Windows\system32\msfefqyj.tmp
C:\Windows\system32\msfefqyj.tmp Has been deleted!
Attempting to delete C:\Windows\system32\mvkwjvyk.ini
C:\Windows\system32\mvkwjvyk.ini Has been deleted!
Attempting to delete C:\Windows\system32\mvkwjvyk.ini2
C:\Windows\system32\mvkwjvyk.ini2 Has been deleted!
Attempting to delete C:\Windows\system32\mvkwjvyk.tmp
C:\Windows\system32\mvkwjvyk.tmp Has been deleted!
Attempting to delete C:\Windows\system32\swfrtldt.dll
C:\Windows\system32\swfrtldt.dll Has been deleted!
Attempting to delete C:\Windows\system32\xcloee.dll
C:\Windows\system32\xcloee.dll Has been deleted!
Attempting to delete C:\Windows\system32\xgfwekbd.dll
C:\Windows\system32\xgfwekbd.dll Has been deleted!
Attempting to delete C:\Windows\system32\xxyxYrQj.dll
C:\Windows\system32\xxyxYrQj.dll Has been deleted!
Attempting to delete C:\Windows\system32\ydidfcwd.dll
C:\Windows\system32\ydidfcwd.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V7.0.6
Scan started at 14:06:00 06/08/2008
Listing files found while scanning…
No infected files were found.
VirtumondoBeGone
[08/06/2008, 14:03:58] - VirtumundoBeGone v1.5 ( “E:\Vundo Warmachine\VirtumundoBeGone.exe” )
[08/06/2008, 14:04:07] - Detected System Information:
[08/06/2008, 14:04:07] - Windows Version: 5.1.2600, Service Pack 2
[08/06/2008, 14:04:07] - Current Username: Administrator (Admin)
[08/06/2008, 14:04:07] - Windows is in SAFE mode with Networking.
[08/06/2008, 14:04:07] - Searching for Browser Helper Objects:
[08/06/2008, 14:04:07] - BHO 1: AutorunsDisabled ()
[08/06/2008, 14:04:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:07] - No filename found. Continuing.
[08/06/2008, 14:04:07] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[08/06/2008, 14:04:07] - BHO 3: {62326729-D3FE-44FF-AE33-9C0C34382844} ()
[08/06/2008, 14:04:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:07] - Checking for HKLM.…\Winlogon\Notify\cbXnkLff
[08/06/2008, 14:04:07] - Key not found: HKLM.…\Winlogon\Notify\cbXnkLff, continuing.
[08/06/2008, 14:04:07] - BHO 4: {BB81FE02-F70B-46C2-82C3-DE5C6652E677} ()
[08/06/2008, 14:04:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:07] - Checking for HKLM.…\Winlogon\Notify\iifefDUN
[08/06/2008, 14:04:07] - Found: HKLM.…\Winlogon\Notify\iifefDUN - This is probably Virtumundo.
[08/06/2008, 14:04:07] - Assigning {BB81FE02-F70B-46C2-82C3-DE5C6652E677} MSEvents Object
[08/06/2008, 14:04:07] - BHO list has been changed! Starting over…
[08/06/2008, 14:04:07] - BHO 1: AutorunsDisabled ()
[08/06/2008, 14:04:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:07] - No filename found. Continuing.
[08/06/2008, 14:04:07] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[08/06/2008, 14:04:07] - BHO 3: {62326729-D3FE-44FF-AE33-9C0C34382844} ()
[08/06/2008, 14:04:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:07] - Checking for HKLM.…\Winlogon\Notify\cbXnkLff
[08/06/2008, 14:04:07] - Key not found: HKLM.…\Winlogon\Notify\cbXnkLff, continuing.
[08/06/2008, 14:04:07] - BHO 4: {BB81FE02-F70B-46C2-82C3-DE5C6652E677} (MSEvents Object)
[08/06/2008, 14:04:07] - ALERT: Found MSEvents Object!
[08/06/2008, 14:04:07] - Finished Searching Browser Helper Objects
[08/06/2008, 14:04:07] - *** Detected MSEvents Object
[08/06/2008, 14:04:07] - Trying to remove MSEvents Object…
[08/06/2008, 14:04:08] - Terminating Process: IEXPLORE.EXE
[08/06/2008, 14:04:08] - Terminating Process: RUNDLL32.EXE
[08/06/2008, 14:04:08] - Disabling Automatic Shell Restart
[08/06/2008, 14:04:08] - Terminating Process: EXPLORER.EXE
[08/06/2008, 14:04:09] - Suspending the NT Session Manager System Service
[08/06/2008, 14:04:09] - Terminating Windows NT Logon/Logoff Manager
[08/06/2008, 14:04:09] - Re-enabling Automatic Shell Restart
[08/06/2008, 14:04:09] - File to disable: C:\WINDOWS\system32\iifefDUN.dll
[08/06/2008, 14:04:09] - Renaming C:\WINDOWS\system32\iifefDUN.dll → C:\WINDOWS\system32\iifefDUN.dll.vir
[08/06/2008, 14:04:09] - File successfully renamed!
[08/06/2008, 14:04:09] - Removing HKLM.…\Browser Helper Objects{BB81FE02-F70B-46C2-82C3-DE5C6652E677}
[08/06/2008, 14:04:09] - Removing HKCR\CLSID{BB81FE02-F70B-46C2-82C3-DE5C6652E677}
[08/06/2008, 14:04:09] - Adding Kill Bit for ActiveX for GUID: {BB81FE02-F70B-46C2-82C3-DE5C6652E677}
[08/06/2008, 14:04:09] - Deleting ATLEvents/MSEvents Registry entries
[08/06/2008, 14:04:09] - Removing HKLM.…\Winlogon\Notify\iifefDUN
[08/06/2008, 14:04:09] - Searching for Browser Helper Objects:
[08/06/2008, 14:04:09] - BHO 1: AutorunsDisabled ()
[08/06/2008, 14:04:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:09] - No filename found. Continuing.
[08/06/2008, 14:04:09] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[08/06/2008, 14:04:09] - BHO 3: {62326729-D3FE-44FF-AE33-9C0C34382844} ()
[08/06/2008, 14:04:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:04:09] - Checking for HKLM.…\Winlogon\Notify\cbXnkLff
[08/06/2008, 14:04:09] - Key not found: HKLM.…\Winlogon\Notify\cbXnkLff, continuing.
[08/06/2008, 14:04:09] - Finished Searching Browser Helper Objects
[08/06/2008, 14:04:09] - Finishing up…
[08/06/2008, 14:04:09] - A restart is needed.
[08/06/2008, 14:04:14] - Attempting to Restart via STOP error (Blue Screen!)
[08/06/2008, 14:15:36] - VirtumundoBeGone v1.5 ( “E:\Vundo Warmachine\VirtumundoBeGone.exe” )
[08/06/2008, 14:15:42] - Detected System Information:
[08/06/2008, 14:15:42] - Windows Version: 5.1.2600, Service Pack 2
[08/06/2008, 14:15:42] - Current Username: Administrator (Admin)
[08/06/2008, 14:15:42] - Windows is in NORMAL mode.
[08/06/2008, 14:15:42] - Searching for Browser Helper Objects:
[08/06/2008, 14:15:42] - BHO 1: AutorunsDisabled ()
[08/06/2008, 14:15:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:15:42] - No filename found. Continuing.
[08/06/2008, 14:15:42] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[08/06/2008, 14:15:42] - BHO 3: {62326729-D3FE-44FF-AE33-9C0C34382844} ()
[08/06/2008, 14:15:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[08/06/2008, 14:15:42] - Checking for HKLM.…\Winlogon\Notify\cbXnkLff
[08/06/2008, 14:15:42] - Key not found: HKLM.…\Winlogon\Notify\cbXnkLff, continuing.
[08/06/2008, 14:15:42] - Finished Searching Browser Helper Objects
[08/06/2008, 14:15:42] - Finishing up…
[08/06/2008, 14:15:42] - Nothing found! Exiting…