This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

POPUPS from H@#$

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, all. I've been getting some wicked popups starting with sysprotect and winantivirus. Then, recently, I've getting some from worlddatinghere.com; these are not tolerable on this family computer and are bordering on pornographic. I've tried the Vundo fix but maybe I'm not doing something right (although we I first scan with the Vundo fix, it seemed to get some nasties, but they're back!)

Here's my Hijack this logfile:

Logfile of HijackThis v1.99.1
Scan saved at 10:43:14 PM, on 9/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\CallWave\IAM.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\YTBSDK.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\AdobeAcrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF699015-3DFD-4B6C-90A4-DDAAB0B88BA3}: NameServer = 66.81.1.251 66.81.1.252
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
Hi davy123,

I'm Gary R. I'll be glad to help you with your computer problems.
Please be patient, I know that you want your problems solved quickly, and I will work hard to help you.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.

Looks like you have one of the newer Vundo varients that hides itself from HijackThis.

Go to your HijackThis folder, and right click on HijackThis.exe select rename, and rename it Remove.exe

Now double click Remove.exe to launch HJT, and run a scan.

Post the new scan back here please.
Just the exe file. The version of Vundo you've got hides objects from HijackThis.exe, but the renamed exe usually sees the hidden objects.
OK…here's the new scan after changing it to "Remove.exe":


Logfile of HijackThis v1.99.1
Scan saved at 12:54:13 PM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\YTBSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\HijackThis\Remove.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
O2 - BHO: (no name) - {18219A52-3802-4149-9BCB-FE02FBF3EF0D} - C:\VundoFix Backups\geeda.dll
O2 - BHO: (no name) - {228C3D06-11A8-4787-A5F3-5505780201C9} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\AdobeAcrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF699015-3DFD-4B6C-90A4-DDAAB0B88BA3}: NameServer = 66.81.1.251 66.81.1.252
O20 - Winlogon Notify: geeda - C:\VundoFix Backups\geeda.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
Hi davy123,

Download combofix.exe and save it to your desktop. (Must be in this location).

go to start –> run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /v geeda

When finished, it will produce a log. Post the log in your next reply please.

Note: Don't mouseclick combofix's window whilst it's running. That may cause it to stall.

In your next post, please include
  • new hijackthis log
  • combofix log
*use separate posts to ensure the logs don't get cut off!
OK…I'll do two seperate posts as per your request…THANKS!! Here is the new hijackthis file (done after I ran the combofix scan which will be on the next post):

Logfile of HijackThis v1.99.1
Scan saved at 5:36:34 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\YTBSDK.exe
C:\HijackThis\Remove.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
O2 - BHO: (no name) - {228C3D06-11A8-4787-A5F3-5505780201C9} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5DC1F340-8274-4351-B979-05BF57599648} - C:\VundoFix Backups\geeda.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\AdobeAcrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF699015-3DFD-4B6C-90A4-DDAAB0B88BA3}: NameServer = 66.81.1.251 66.81.1.252
O20 - Winlogon Notify: geeda - C:\VundoFix Backups\geeda.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
OK…now the combofix file: Dave - 06-09-09 17:31:07.37 ComboFix 06.09.07 - Running from: C:\Documents and Settings\[removed]\desktop Microsoft Windows XP [Version 5.1.2600] ((((((((((((((((((((((((((((((( Files Created from 2006-08-09 to 2006-09-09 )))))))))))))))))))))))))))))))))) 2006-09-09 12:59 106,516 –a—— C:\WINDOWS\system32\fsaispga.dll 2006-09-08 17:24 106,516 –a—— C:\WINDOWS\system32\hctssxex.dll 2006-09-07 17:35 106,516 –a—— C:\WINDOWS\system32\ucmywhel.dll 2006-09-03 17:20 180,224 –a-s—- C:\WINDOWS\system32\archlib.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-09-09 17:22 ——– d——– C:\Program Files\CallWave 2006-09-07 12:01 ——– d——– C:\Program Files\Java 2006-09-07 11:13 ——– d——– C:\Program Files\Common Files\Java 2006-09-07 11:13 ——– d——– C:\Program Files\Common Files 2006-09-07 11:11 ——– d——– C:\Program Files\LimeWire 2006-09-07 08:17 ——– d——– C:\Program Files\WDM 2006-09-07 07:09 ——– d——– C:\Program Files\Hijackthis folder 2006-09-04 21:20 ——– d——– C:\Program Files\Yahoo! 2006-09-04 21:20 ——– d——– C:\Program Files\Common Files\Scanner 2006-09-03 17:28 ——– d——– C:\Documents and Settings\Dave\Application Data\Tenebril 2006-09-01 21:44 ——– d——– C:\Program Files\dBpowerAMP 2006-08-26 15:39 ——– d——– C:\Program Files\Online Services 2006-08-24 20:17 ——– d——– C:\Program Files\Windows NT 2006-08-24 19:42 ——– d——– C:\Program Files\Norton Utilities 2006-08-23 13:24 ——– d—s—- C:\Documents and Settings\Dave\Application Data\Microsoft 2006-08-21 09:46 777472 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-08-21 09:46 27904 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-08-21 07:41 21290704 –a—— C:\Program Files\AdbeRdr708_en_US.exe 2006-08-21 07:41 1525 –a—— C:\Documents and Settings\Dave\Application Data\AdobeDLM.log 2006-08-21 07:41 0 –a—— C:\Documents and Settings\Dave\Application Data\dm.ini 2006-08-20 21:22 ——– d——– C:\Program Files\Common Files\Adobe 2006-08-20 21:13 ——– d——– C:\Program Files\AdobeAcrobat 7.0 2006-08-20 21:09 ——– d——– C:\Program Files\Adobe 2006-08-12 22:01 ——– d——– C:\Documents and Settings\Dave\Application Data\AdobeUM 2006-08-08 20:58 ——– d——– C:\Program Files\Internet Explorer 2006-07-27 06:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-07-23 21:09 ——– d——– C:\Program Files\Lavasoft 2006-07-23 21:09 ——– d——– C:\Documents and Settings\Dave\Application Data\Lavasoft 2006-07-23 11:38 ——– d——– C:\Documents and Settings\Dave\Application Data\Macromedia 2006-07-21 01:24 72704 –a—— C:\WINDOWS\system32\hlink.dll 2006-07-20 12:24 14872 –a—— C:\WINDOWS\system32\SBBD.exe 2006-07-12 20:58 ——– d——– C:\Documents and Settings\Dave\Application Data\Adobe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "H2O"="C:\\Program Files\\SyncroSoft\\Pos\\H2O\\cledx.exe" "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PhotoShow Deluxe Media Manager"="C:\\PROGRA~1\\Ahead\\Ahead\\data\\Xtras\\mssysmgr.exe" "Creative Detector"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R" "updateMgr"="\"C:\\Program Files\\AdobeAcrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3c,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,b5,00,00,00,80,00,00,00,76,00,\ 00,00,01,00,00,00 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\ADOBEA~1.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office\\OSA9.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Program Neighborhood Agent.lnk] "path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Program Neighborhood Agent.lnk" "backup"="C:\\WINDOWS\\pss\\Program Neighborhood Agent.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Citrix\\ICACLI~1\\pnagent.exe " "item"="Program Neighborhood Agent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk] "path"="C:\\Documents and Settings\\Dave\\Start Menu\\Programs\\Startup\\Greetings Workshop Reminders.lnk" "backup"="C:\\WINDOWS\\pss\\Greetings Workshop Reminders.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\GREETI~1\\GWREMIND.EXE " "item"="Greetings Workshop Reminders" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\avast!] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ashDisp" "hkey"="HKLM" "command"="C:\\PROGRA~1\\Avast4\\ashDisp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HPDJ Taskbar Utility] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="hpztsb04" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\KernelFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -k" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -k" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SoundMan] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SOUNDMAN" "hkey"="HKLM" "command"="SOUNDMAN.EXE" "inimapping"="0" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geeda Completion time: Sat 09/09/2006 17:32:00.64 ComboFix.txt
Hi Davy,

Run a scan with HJT and check the following items.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O2 - BHO: (no name) - {228C3D06-11A8-4787-A5F3-5505780201C9} - (no file)
O2 - BHO: (no name) - {5DC1F340-8274-4351-B979-05BF57599648} - C:\VundoFix Backups\geeda.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O20 - Winlogon Notify: geeda - C:\VundoFix Backups\geeda.dll


Close all open windows then click Fix Checked to remove them.

Make sure that you can see hidden files and folders.
  • Click Start.
  • Click My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Click Yes to confirm.
  • Uncheck the Hide file extensions for known file types.
  • Click OK.
Search for Hidden Files
By default, the Search companion does not search for hidden files. Because of this, you may be unable to find files, even though they exist on the drive.

To search for hidden or system files in Windows XP:
  • Click Start.
  • Click Search.
  • Click All files and folders.
  • Click More advanced options.
  • Click to select the Search hidden files and folders check box.
Now delete the following folder.

C:\VundoFix Backups

I'd like you to check a file(s) for Viruses.
  • Go to VirusTotal or Jotti's, and scan the following file(s).

C:\WINDOWS\system32\fsaispga.dll
C:\WINDOWS\system32\hctssxex.dll
C:\WINDOWS\system32\ucmywhel.dll

  • Click on the Browse button at the top of the screen.
  • Browse to the first file on the list.
  • Click OK.
  • Click Send, and the file will upload to VirusTotal / Jotti, where it will be scanned by several anti-virus programmes.
  • After a while, a window will open, with details of what the scans found.
  • Note details of any viruses found.
  • Repeat for all files on the list, and post me the details please.
If the above scanner sites are oversubscribed, try Virus.org.

Download ATF Cleaner by Atribune and save it to your Desktop.
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post please, along with a new HJT log and the results from Virus Total.
One last Question: There is evidence in the Combofix log that you have Tenebril Keycorder installed on your computer, this is a Keylogging program, did you install this yourself?
OK… I finished up to the point where you ask me to delete the C:\VundoFix Backups folder…. was able to delete all the 4 files in that folder EXCEPT the geeda.dll file… windows keeps telling me that "another person or program is using that file. Please close and try again". Well… no other running applications are presently listed as running… not sure how to proceed!! THANKS, davy
OK looks like we need a bit of help getting rid of geeda.dll

Download Pocket Killbox and install it to your Desktop. Do not run it yet.
  • First copy the filepaths in the box below to your clipboard, by highlighting them and pressing Ctrl+C.

C:\VundoFix Backups\geeda.dll

  • Open Killbox and check a mark in the "RadioBox" which says Delete On Reboot
  • Click File > Paste from Clipboard.
  • Check Unregister dll before Deleting.
  • Click on the Red button with a Cross, and answer Yes when prompted to Backup and Delete the pasted files.
  • Answer Yes when prompted to Reboot now.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, download and run missingfilesetup.exe. Then try Killbox again.

Now carry on with the rest of the things listed in my last post please.
Hi. I tried the killbox directions, but got the following error message and would not reboot: PendingFileRenameOperations Registry Data has been removed by External Process!
OK, just carry on with the rest of the instructions for the present, and send me the logs I requested, we'll get back to the geeda.dll file.

Sorry about the time diffence (I live in the UK), seems to mean we only get 1 post in per night (your last post was at 01:38 am my time so I've only picked it up this morning).

Stick with it, we will get rid of this thing.
Actually, I did all that… I'll send the logs…. I'm ready to re-format, as this is crazy! Thanks for all help thus far. Geeda just doesn't want to go away! Anyway, here's the log files from Kaspersky (I did one on geeda.dll for fun). I won't add Virus.org as they found none… however, I ran all the files with Kaspersky and here goes: STATUS: FINISHED Complete scanning result of "ucmywhel.dll", received in VirusTotal at 09.11.2006, 00:51:42 (CET). Antivirus Version Update Result AntiVir 7.1.1.16 09.09.2006 no virus found Authentium 4.93.8 09.10.2006 no virus found Avast 4.7.844.0 09.08.2006 Win32:Trojano-1165 AVG 386 09.08.2006 no virus found BitDefender 7.2 09.10.2006 no virus found CAT-QuickHeal 8.00 09.09.2006 no virus found ClamAV devel-20060426 09.10.2006 no virus found DrWeb 4.33 09.10.2006 no virus found eTrust-InoculateIT 23.72.121 09.10.2006 no virus found eTrust-Vet 30.3.3070 09.09.2006 no virus found Ewido 4.0 09.10.2006 no virus found Fortinet 2.77.0.0 09.10.2006 no virus found F-Prot 3.16f 09.10.2006 no virus found F-Prot4 4.2.1.29 09.10.2006 no virus found Ikarus 0.2.65.0 09.08.2006 no virus found Kaspersky 4.0.2.24 09.11.2006 no virus found McAfee 4848 09.08.2006 no virus found Microsoft 1.1560 09.10.2006 no virus found NOD32v2 1.1747 09.10.2006 no virus found Norman 5.90.23 09.08.2006 no virus found Panda 9.0.0.4 09.10.2006 Application/WinAntivirus Sophos 4.09.0 09.10.2006 no virus found Symantec 8.0 09.10.2006 no virus found TheHacker 5.9.8.208 09.08.2006 no virus found UNA 1.83 09.08.2006 no virus found VBA32 3.11.1 09.10.2006 no virus found VirusBuster 4.3.7:9 09.10.2006 no virus found Aditional Information File size: 106516 bytes MD5: 50ea36ef009aed62d7b167219468f805 SHA1: f881ad829ce4069416caa97aebab15857f324f25 STATUS: FINISHED Complete scanning result of "hctssxex.dll", received in VirusTotal at 09.11.2006, 01:09:10 (CET). Antivirus Version Update Result AntiVir 7.1.1.16 09.09.2006 no virus found Authentium 4.93.8 09.10.2006 no virus found Avast 4.7.844.0 09.08.2006 Win32:Trojano-1165 AVG 386 09.08.2006 no virus found BitDefender 7.2 09.10.2006 no virus found CAT-QuickHeal 8.00 09.09.2006 no virus found ClamAV devel-20060426 09.10.2006 no virus found DrWeb 4.33 09.10.2006 no virus found eTrust-InoculateIT 23.72.121 09.10.2006 no virus found eTrust-Vet 30.3.3070 09.09.2006 no virus found Ewido 4.0 09.10.2006 no virus found Fortinet 2.77.0.0 09.10.2006 no virus found F-Prot 3.16f 09.10.2006 no virus found F-Prot4 4.2.1.29 09.10.2006 no virus found Ikarus 0.2.65.0 09.08.2006 no virus found Kaspersky 4.0.2.24 09.11.2006 no virus found McAfee 4848 09.08.2006 no virus found Microsoft 1.1560 09.10.2006 no virus found NOD32v2 1.1747 09.10.2006 no virus found Norman 5.90.23 09.08.2006 no virus found Panda 9.0.0.4 09.10.2006 Application/WinAntivirus Sophos 4.09.0 09.10.2006 no virus found Symantec 8.0 09.10.2006 no virus found TheHacker 5.9.8.208 09.08.2006 no virus found UNA 1.83 09.08.2006 no virus found VBA32 3.11.1 09.10.2006 no virus found VirusBuster 4.3.7:9 09.10.2006 no virus found Aditional Information File size: 106516 bytes MD5: 50ea36ef009aed62d7b167219468f805 SHA1: f881ad829ce4069416caa97aebab15857f324f25 STATUS: FINISHED Complete scanning result of "fsaispga.dll", received in VirusTotal at 09.11.2006, 01:26:45 (CET). Antivirus Version Update Result AntiVir 7.1.1.16 09.09.2006 no virus found Authentium 4.93.8 09.10.2006 no virus found Avast 4.7.844.0 09.08.2006 Win32:Trojano-1165 AVG 386 09.08.2006 no virus found BitDefender 7.2 09.11.2006 no virus found CAT-QuickHeal 8.00 09.09.2006 no virus found ClamAV devel-20060426 09.10.2006 no virus found DrWeb 4.33 09.10.2006 no virus found eTrust-InoculateIT 23.72.121 09.10.2006 no virus found eTrust-Vet 30.3.3070 09.09.2006 no virus found Ewido 4.0 09.10.2006 no virus found Fortinet 2.77.0.0 09.10.2006 no virus found F-Prot 3.16f 09.10.2006 no virus found F-Prot4 4.2.1.29 09.10.2006 no virus found Ikarus 0.2.65.0 09.08.2006 no virus found Kaspersky 4.0.2.24 09.11.2006 no virus found McAfee 4848 09.08.2006 no virus found Microsoft 1.1560 09.10.2006 no virus found NOD32v2 1.1747 09.10.2006 no virus found Norman 5.90.23 09.08.2006 no virus found Panda 9.0.0.4 09.10.2006 Application/WinAntivirus Sophos 4.09.0 09.10.2006 no virus found Symantec 8.0 09.10.2006 no virus found TheHacker 5.9.8.208 09.08.2006 no virus found UNA 1.83 09.08.2006 no virus found VBA32 3.11.1 09.10.2006 no virus found VirusBuster 4.3.7:9 09.10.2006 no virus found Aditional Information File size: 106516 bytes MD5: 50ea36ef009aed62d7b167219468f805 SHA1: f881ad829ce4069416caa97aebab15857f324f25 STATUS: FINISHED Complete scanning result of "geeda.dll", received in VirusTotal at 09.11.2006, 01:56:59 (CET). Antivirus Version Update Result AntiVir 7.1.1.16 09.09.2006 ADSPY/Virtumonde.CQ.5 Authentium 4.93.8 09.10.2006 no virus found Avast 4.7.844.0 09.08.2006 Win32:Trojan-gen. {Other} AVG 386 09.08.2006 Adware Generic.PDI BitDefender 7.2 09.11.2006 Adware.Virtumonde.BQ CAT-QuickHeal 8.00 09.09.2006 AdWare.Virtumonde.cq (Not a Virus) ClamAV devel-20060426 09.10.2006 Adware.Virtumonde-9 DrWeb n - no virus found eTrust-InoculateIT 23.72.121 09.10.2006 no virus found eTrust-Vet 30.3.3070 09.09.2006 Win32/Vundo Ewido 4.0 09.10.2006 Adware.Virtumonde Fortinet 2.77.0.0 09.10.2006 suspicious F-Prot 3.16f 09.10.2006 no virus found F-Prot4 4.2.1.29 09.10.2006 no virus found Ikarus 0.2.65.0 09.08.2006 no virus found Kaspersky 4.0.2.24 09.11.2006 not-a-virus:AdWare.Win32.Virtumonde.cq McAfee 4848 09.08.2006 Vundo Microsoft 1.1560 09.11.2006 no virus found NOD32v2 1.1747 09.10.2006 Win32/Adware.Virtumonde Norman 5.90.23 09.08.2006 W32/Virtumonde.KR Panda 9.0.0.4 09.10.2006 Spyware/Virtumonde Sophos 4.09.0 09.10.2006 no virus found Symantec 8.0 09.10.2006 no virus found TheHacker 5.9.8.208 09.08.2006 Adware/Virtumonde.cq UNA 1.83 09.08.2006 Adware.Virtumonde VBA32 3.11.1 09.10.2006 no virus found VirusBuster 4.3.7:9 09.10.2006 no virus found Aditional Information File size: 573492 bytes MD5: 4bcfd2d1a14337be36f2f9b182ade052 SHA1: ac96f88e484476714a9eaf3fd342f3802186f8d6 packers: embedded
Hi Davy,

You haven't sent me the Kaspersky online scan log. However you can run another scan once we've made another stab at geeda.dll

You didn't tell me, did you install Tenebril Keycorder?

Download Avenger, and unzip it to your desktop or somewhere you can find it. (Do not run it yet).

Note: This programme is for use on Windows XP 32 bit systems only, and must be run from an account with Administor priviledges.
  • Open a Notepad file by clicking Start > Run and typing Notepad.exe in the box, click OK.
  • Click Format, and ensure Word Wrap is unchecked.
  • Copy and Paste the text in the box below into Notepad.
  • Now save the file as RemoveFiles.txt in a location where you can find it.
Files to delete:
C:\VundoFix Backups\geeda.dll
C:\WINDOWS\system32\fsaispga.dll
C:\WINDOWS\system32\hctssxex.dll
C:\WINDOWS\system32\ucmywhel.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Start Avenger by double clicking on Avenger.exe.
  • Check Load script from file:
  • Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
  • Double click it to enter it into Avenger.
  • Click the green traffic light symbol.
  • You will be asked if you want to execute the script, answer Yes.
  • At this point you may get prompts from your protection systems, allow them please.
  • Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
  • Answer Yes, and allow your computer to re-boot.
  • Upon re-boot a command window will briefly appear on screen (this is normal).
  • A Notepad text file will be created C:\avenger.txt.
  • Copy and Paste it into your next post please.
Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post, along with the C:\avenger.txt and a new HJT log please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI