This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Annoying popups

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Almost everytime i open my browser, I get a popup from some ad site. I have used a lot of programs such as spybot search and destroy to scan my computer, but i haven't used them to remove anything because they have to be registered to remove anything.

Here is my log from HijackThis - I need to know what needs to be fixed
Thanks :)


Logfile of HijackThis v1.99.1
Scan saved at 4:25:28 PM, on 9/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\downloads\hijackthis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.com/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DosSpecFolder Object - {3E1BEA96-02D9-4992-B508-9B51819D9D86} - C:\WINDOWS\System32\gebcc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\system32\qpvrvqln.dll
O2 - BHO: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll
O3 - Toolbar: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [NetZero_uoltray] \\Family\NetZero\exec.exe regrun
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NETGEAR WG311v3 Wireless Assistant.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143167639890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143167997796
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: gebcc - C:\WINDOWS\System32\gebcc.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
The Gumby :D

Welcome to Tom Coyote, you have a few issues going on that we need to fix, the most important right now is Vundo.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



Open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost


O2 - BHO: DosSpecFolder Object - {3E1BEA96-02D9-4992-B508-9B51819D9D86} - C:\WINDOWS\System32\gebcc.dll
O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\system32\qpvrvqln.dll



If you know these sites and set these yourself then leave them, otherwise fix them
O15 - Trusted IP range: http://59.148.220.121 <–Internet Service Provider in Hong Kong
O15 - Trusted IP range: http://62.4.84.53 <– Cyber Technology in Belgium
O15 - Trusted IP range: http://82.98.235.58 <– Cyber Technology in Belgium

O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab

O20 - Winlogon Notify: gebcc - C:\WINDOWS\System32\gebcc.dll



I need to see the log from Vundofix and a new HJT log please.

Ken :D
Here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:02:16 PM, on 9/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.com/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll
O3 - Toolbar: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [NetZero_uoltray] \\Family\NetZero\exec.exe regrun
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NETGEAR WG311v3 Wireless Assistant.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143167639890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143167997796
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe


And here is the VundoFix log:


VundoFix V6.1.5

Checking Java version…

Java version is 1.5.0.8

Scan started at 8:43:47 PM 9/19/2006

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\gebcc.dll
C:\WINDOWS\SYSTEM32\ccbeg.ini
C:\WINDOWS\SYSTEM32\ccbeg.bak1
C:\WINDOWS\SYSTEM32\ccbeg.bak2
C:\WINDOWS\SYSTEM32\ccbeg.ini2
C:\WINDOWS\SYSTEM32\ccbeg.tmp
C:\WINDOWS\SYSTEM32\geeby.dll
C:\WINDOWS\SYSTEM32\hsievynw.exe
C:\WINDOWS\SYSTEM32\ixafsmqi.exe
C:\WINDOWS\SYSTEM32\lskxrnte.exe
C:\WINDOWS\SYSTEM32\rvnkeqpd.exe
C:\WINDOWS\SYSTEM32\ursaxtbr.exe
C:\WINDOWS\SYSTEM32\wouttycc.exe
C:\WINDOWS\system32\Drivers\DP.sys

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\gebcc.dll
C:\WINDOWS\SYSTEM32\gebcc.dll Could not be deleted.

Attempting to delete C:\WINDOWS\SYSTEM32\ccbeg.ini
C:\WINDOWS\SYSTEM32\ccbeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ccbeg.bak1
C:\WINDOWS\SYSTEM32\ccbeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ccbeg.bak2
C:\WINDOWS\SYSTEM32\ccbeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ccbeg.ini2
C:\WINDOWS\SYSTEM32\ccbeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ccbeg.tmp
C:\WINDOWS\SYSTEM32\ccbeg.tmp Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\geeby.dll
C:\WINDOWS\SYSTEM32\geeby.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hsievynw.exe
C:\WINDOWS\SYSTEM32\hsievynw.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ixafsmqi.exe
C:\WINDOWS\SYSTEM32\ixafsmqi.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lskxrnte.exe
C:\WINDOWS\SYSTEM32\lskxrnte.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rvnkeqpd.exe
C:\WINDOWS\SYSTEM32\rvnkeqpd.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ursaxtbr.exe
C:\WINDOWS\SYSTEM32\ursaxtbr.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\wouttycc.exe
C:\WINDOWS\SYSTEM32\wouttycc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\Drivers\DP.sys
C:\WINDOWS\system32\Drivers\DP.sys Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.1.5

Checking Java version…

Java version is 1.5.0.8

Scan started at 8:51:35 PM 9/19/2006

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\gebcc.dll

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\gebcc.dll
C:\WINDOWS\SYSTEM32\gebcc.dll Has been deleted!

Performing Repairs to the registry.
Done!


Thanks for your help :D
The Gumby :D

Vundo is gone :thumbup: The rest of your log looks fine. How are things running now??

To be on the safeside, run the free online virus scanner from Panda, it wont clean anything but I need to see the report.

Panda ActiveScan <<
Ken :D
Everything seems to be running better but some things showed up in the activescan. The popup ads are gone now :D Here is the log from the Activescan Incident Status Location Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.tickle.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.atdmt.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.2o7.net/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.advertising.com/] Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.maxserving.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.com.com/] Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.as-us.falkag.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.statcounter.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.z1.adserver.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.valueclick.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.valueclick.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.zedo.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[statse.webtrendslive.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[server.iad.liveperson.net/hc/90594700] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[server.iad.liveperson.net/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[server.iad.liveperson.net/hc/90594700] Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.clickbank.net/] Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.hotlog.ru/] Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.bfast.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.hitbox.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.go.com/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.hitbox.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.go.com/] Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.targetnet.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.atwola.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.perf.overture.com/] Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Raymond\Application Data\Mozilla\Firefox\Profiles\p7nyupo9.default\cookies.txt[.xiti.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Raymond\Cookies\[removed][2].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Raymond\Cookies\raymond@apmebf[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Raymond\Cookies\[removed][1].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Raymond\Cookies\raymond@realmedia[1].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Raymond\Cookies\[removed][1].txt Spyware:Cookie/Overture Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc120.txt Spyware:Cookie/Overture Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc122.txt Spyware:Cookie/QuestionMarket Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc125.txt Spyware:Cookie/Statcounter Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc138.txt Spyware:Cookie/Reliablestats Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc139.txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc158.txt Spyware:Cookie/Zedo Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc161.txt Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc73.txt Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc80.txt Spyware:Cookie/PointRoll Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc83.txt Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\S-1-5-21-768132561-943134337-2526259468-1007\Dc85.txt Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\geeby.dll.bad Adware:Adware/SecurityError Not disinfected C:\VundoFix Backups\hsievynw.exe.bad Adware:Adware/SecurityError Not disinfected C:\VundoFix Backups\ixafsmqi.exe.bad Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\lskxrnte.exe.bad Adware:Adware/SecurityError Not disinfected C:\VundoFix Backups\rvnkeqpd.exe.bad Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\ursaxtbr.exe.bad Adware:Adware/SecurityError Not disinfected C:\VundoFix Backups\wouttycc.exe.bad Potentially unwanted tool:application/winfixer2005 Not disinfected C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N69M1503NetInstaller.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\blalevju.dll Adware:Adware/Popuper Not disinfected C:\WINDOWS\SYSTEM32\btmjudta.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\cqneewab.dll Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\eupxtyij.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\evkkofgc.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\fbsxrweo.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\fdedhfrb.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\flxfxxty.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\hkvtmetf.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\itnbgwfn.dll Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\jahjynhs.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\jkwjomuu.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\kcolgtsg.exe Adware:Adware/Popuper Not disinfected C:\WINDOWS\SYSTEM32\kojmhugp.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\kpimigxy.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\mejemwlh.dll Adware:Adware/Popuper Not disinfected C:\WINDOWS\SYSTEM32\mlutunxu.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\mumgkfog.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\mvrglmnp.dll Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\ndkaispj.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\peyunbnx.dll Adware:Adware/Popuper Not disinfected C:\WINDOWS\SYSTEM32\qsjvjimp.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\rexlgsud.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\sanlmabk.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\tyfecofv.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\uadfgftb.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\wgbmmbav.dll Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\wjwfpvef.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\SYSTEM32\wuhihnbj.exe Thanks
The Gumby :D


Download Pocket Killbox to your desktop, unzip it to a folder that you can find

C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N69M1503NetInstaller.exe
C:\WINDOWS\SYSTEM32\blalevju.dll
C:\WINDOWS\SYSTEM32\btmjudta.exe
C:\WINDOWS\SYSTEM32\cqneewab.dll
C:\WINDOWS\SYSTEM32\eupxtyij.exe
C:\WINDOWS\SYSTEM32\evkkofgc.dll
C:\WINDOWS\SYSTEM32\fbsxrweo.dll
C:\WINDOWS\SYSTEM32\fdedhfrb.dll
C:\WINDOWS\SYSTEM32\flxfxxty.dll
C:\WINDOWS\SYSTEM32\hkvtmetf.dll
C:\WINDOWS\SYSTEM32\itnbgwfn.dll
C:\WINDOWS\SYSTEM32\jahjynhs.exe
C:\WINDOWS\SYSTEM32\jkwjomuu.exe
C:\WINDOWS\SYSTEM32\kcolgtsg.exe
C:\WINDOWS\SYSTEM32\kojmhugp.exe
C:\WINDOWS\SYSTEM32\kpimigxy.exe
C:\WINDOWS\SYSTEM32\mejemwlh.dll
C:\WINDOWS\SYSTEM32\mlutunxu.exe
C:\WINDOWS\SYSTEM32\mumgkfog.exe
C:\WINDOWS\SYSTEM32\mvrglmnp.dll
C:\WINDOWS\SYSTEM32\ndkaispj.exe
C:\WINDOWS\SYSTEM32\peyunbnx.dll
C:\WINDOWS\SYSTEM32\qsjvjimp.exe
C:\WINDOWS\SYSTEM32\rexlgsud.exe
C:\WINDOWS\SYSTEM32\sanlmabk.dll
C:\WINDOWS\SYSTEM32\tyfecofv.dll
C:\WINDOWS\SYSTEM32\uadfgftb.dll
C:\WINDOWS\SYSTEM32\wgbmmbav.dll
C:\WINDOWS\SYSTEM32\wjwfpvef.exe
C:\WINDOWS\SYSTEM32\wuhihnbj.ex


Highlight all the files with the complete path inside the quote box and press Ctrl C on your keyboard.
  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes

The rest of what Panda found where cookies and the backuped files from the first fix.


Run Panda again and lets make sure these are gone, they are just leftover files, but we need to get rid of them.

Ken :D
Ok Everything looks like it's working fine now. Thanks for the help :D After I ran the Activescan again, the only things that showed up were the ones you said were the backups and the cookies. Thank you! -The Gumby
Glad things are better :thumbup:


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.

TonyKlein CastleCops
Grinler BleepingComputer
Geeks To Go


Thanks for using Tom Coyote Glad to be able to help you.

Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI