Trojan.virtumonde ahhhh?
-
help me get rid of this damn thing i ran "VirtumundoBeGone" and heres the log....... please help [02/02/2009, 22:28:58] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\am2\Desktop\VirtumundoBeGone.ex… ) [02/02/2009, 22:29:04] - Detected System Information: [02/02/2009, 22:29:04] - Windows Version: 5.1.2600, Service Pack 3 [02/02/2009, 22:29:04] - Current Username: am2 (Admin) [02/02/2009, 22:29:04] - Windows is in NORMAL mode. [02/02/2009, 22:29:04] - Searching for Browser Helper Objects: [02/02/2009, 22:29:04] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (&Yahoo! Toolbar Helper) [02/02/2009, 22:29:04] - BHO 2: {2ff16aec-d79a-4b28-87cc-46c6d6a069a7} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\ugrulhah [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\ugrulhah, continuing. [02/02/2009, 22:29:04] - BHO 3: {61d6a8fe-ca49-4873-8983-597439a52052} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\gavklt [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\gavklt, continuing. [02/02/2009, 22:29:04] - BHO 4: {6D2852E3-7394-4EF8-8C9D-DF727091134C} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\jkkKebBs [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\jkkKebBs, continuing. [02/02/2009, 22:29:04] - BHO 5: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\khfFVMEV [02/02/2009, 22:29:04] - Found: HKLM\...\Winlogon\Notify\khfFVMEV - This is probably Virtumundo. [02/02/2009, 22:29:04] - Assigning {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} MSEvents Object [02/02/2009, 22:29:04] - BHO list has been changed! Starting over... [02/02/2009, 22:29:04] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (&Yahoo! Toolbar Helper) [02/02/2009, 22:29:04] - BHO 2: {2ff16aec-d79a-4b28-87cc-46c6d6a069a7} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\ugrulhah [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\ugrulhah, continuing. [02/02/2009, 22:29:04] - BHO 3: {61d6a8fe-ca49-4873-8983-597439a52052} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\gavklt [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\gavklt, continuing. [02/02/2009, 22:29:04] - BHO 4: {6D2852E3-7394-4EF8-8C9D-DF727091134C} () [02/02/2009, 22:29:04] - WARNING: BHO has no default name. Checking for Winlogon reference. [02/02/2009, 22:29:04] - Checking for HKLM\...\Winlogon\Notify\jkkKebBs [02/02/2009, 22:29:04] - Key not found: HKLM\...\Winlogon\Notify\jkkKebBs, continuing. [02/02/2009, 22:29:04] - BHO 5: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (MSEvents Object) [02/02/2009, 22:29:04] - ALERT: Found MSEvents Object! [02/02/2009, 22:29:04] - BHO 6: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class) [02/02/2009, 22:29:04] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO) [02/02/2009, 22:29:04] - Finished Searching Browser Helper Objects [02/02/2009, 22:29:04] - *** Detected MSEvents Object [02/02/2009, 22:29:04] - Trying to remove MSEvents Object... [02/02/2009, 22:29:05] - Terminating Process: IEXPLORE.EXE [02/02/2009, 22:29:05] - Terminating Process: RUNDLL32.EXE [02/02/2009, 22:29:06] - Disabling Automatic Shell Restart [02/02/2009, 22:29:06] - Terminating Process: EXPLORER.EXE [02/02/2009, 22:29:06] - Suspending the NT Session Manager System Service [02/02/2009, 22:29:06] - Terminating Windows NT Logon/Logoff Manager [02/02/2009, 22:29:07] - Re-enabling Automatic Shell Restart [02/02/2009, 22:29:07] - File to disable: C:\WINDOWS\system32\khfFVMEV.dll [02/02/2009, 22:29:07] - Renaming C:\WINDOWS\system32\khfFVMEV.dll -> C:\WINDOWS\system32\khfFVMEV.dll.vir [02/02/2009, 22:29:08] - File successfully renamed! [02/02/2009, 22:29:08] - Removing HKLM\...\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFB… [02/02/2009, 22:29:09] - Removing HKCR\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77… [02/02/2009, 22:29:09] - Adding Kill Bit for ActiveX for GUID: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} [02/02/2009, 22:29:09] - Deleting ATLEvents/MSEvents Registry entries [02/02/2009, 22:29:09] - Removing HKLM\...\Winlogon\Notify\khfFVMEV [02/02/2009, 22:29:09] - Searching for Browser Helper Objects: [02/02/2009, 22:29:09] - BHO 1: {02478D38-C3F9-4EFB-9B51-769
-
Answer:
dont worry! go and download trial version of kaspersky internet security! uninstall ur antivirus and install this than scan! or go to http://www.ewido.net/en/onlinescan/ accept activex control, scan ur pc, at the and remove it!
ekrok731... at Yahoo! Answers Visit the source
Other answers
you can down load AVG at www.cnet.com
squeezzer
Related Q & A:
- How do I remove Trojan TJ/BZ?Best solution by Yahoo! Answers
- How do you get rid of and MSN link sending virus/trojan?Best solution by Yahoo! Answers
Just Added Q & A:
- How many active mobile subscribers are there in China?Best solution by Quora
- How to find the right vacation?Best solution by bookit.com
- How To Make Your Own Primer?Best solution by thekrazycouponlady.com
- How do you get the domain & range?Best solution by ChaCha
- How do you open pop up blockers?Best solution by Yahoo! Answers
For every problem there is a solution! Proved by Solucija.
-
Got an issue and looking for advice?
-
Ask Solucija to search every corner of the Web for help.
-
Get workable solutions and helpful tips in a moment.
Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.