View Single Post
Old 02-28-2007, 11:24 PM   #23 (permalink)
Pancake
Security Team (ret.)
 
Pancake's Avatar
 
Join Date: Nov 2003
Location: Victoria.Australia
Posts: 7,404
OS: XP Pro SP3


And still more to clear out....


Download VirtumundoBegone and save it to your desktop. When you have done this doubleclick on VirtumundoBeGone.exe and follow the instructions. When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply. Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.





Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O2 - BHO: (no name) - {067BE456-B710-4015-84FF-E09B52ACE092} - C:\WINDOWS\System32\pmkjj.dll (file missing)
O2 - BHO: (no name) - {37EB498E-7800-A96A-AED9-045FF6ECB283} - C:\WINDOWS\System32\ceamvdb.dll (file missing)
O2 - BHO: (no name) - {8C5AFBC1-5D1E-4A8A-ABB5-90BE5DC3E248} - C:\WINDOWS\System32\vtstr.dll
O2 - BHO: (no name) - {911427C3-6065-497F-9C72-B2562DA349C6} - C:\WINDOWS\System32\vtstq.dll (file missing)
O2 - BHO: 0 - {A87A5C44-882B-42BC-27A5-06511D2BA675} - C:\Program Files\Common Files\sagu292.dll (file missing)
O2 - BHO: (no name) - {C3581462-AD4C-43AF-A8A7-AFEFEBA11B44} - C:\WINDOWS\system32\byxwttt.dll
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\System32\xbiehfer.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\kxrwuojr.dll",setvm
O20 - Winlogon Notify: byxyvwv - byxyvwv.dll (file missing)
O20 - Winlogon Notify: szr_dll - C:\WINDOWS\szr_dll.dll
O20 - Winlogon Notify: vtstq - C:\WINDOWS\System32\vtstq.dll (file missing)
O20 - Winlogon Notify: vtstr - C:\WINDOWS\System32\vtstr.dll


Reboot and run Hijack This again and post a new Hijack This log and VBG.TXT (if any viruses are detected and removed, reboot first).
__________________
Eddy
Pancake is offline