The tool ends an important Windows Process that was protecting the file and NT Security STOPS the system as soon as it detects this is happening.

Show information about your own IP Address Who sent you an Email? it should look like this VundoFix V2.15 by Atri By pressing enter you agree that you are using this at your own risk

I never received the "blue screen of death" when I finished. Please wait... Attempting to delete C:\WINDOWS\system32\klnmp.ini2 C:\WINDOWS\system32\klnmp.ini2 Has been deleted! Working...

Checking for Winlogon reference. [01/22/2006, 21:19:30] - Checking for HKLM\...\Winlogon\Notify\SDHelper [01/22/2006, 21:19:30] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing. [01/22/2006, 21:19:30] - BHO 3: {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} (MSEvents Object) [01/22/2006, 21:19:30] - ALERT: Found

Fix these with HJT – mark them, close IE, click fix checked O17 - HKLM\System\CCS\Services\Tcpip\..\{29E10E32-8356-40E8-B74E-3AAB95C85E89}: NameServer =, O17 - HKLM\System\CCS\Services\Tcpip\..\{E558851E-F71B-4EF1-B556-E23A0AEF3388}: NameServer =

Done! -------------------------------------------------------------------------------------------------------- Now the HighJack This file after running Vundo and Fixwareout: -------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 10:44:49 PM, on 1/18/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Thanks everyone.... -------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 8:52:50 PM, on 1/22/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new Hijack This log. ================================== If you get an Autoexec nt error do the following XP Fix - http://www.visualtour.com/downloads/ You can do this by restarting your computer and continually tapping the F8 key until a menu appears.

At this point please type the following file path (make sure to enter it exactly as below!): C:\WINDOWS\system32\pmnlk.dll Press Enter, Next you will see: Please type in the second filepath as

According to Alexa Traffic Rank toptvbytes.com is ranked number 12,871,699 in the world and 2.0E-6% of global Internet users visit it.

Rename the infected files with a .Vir extension (this is disable them from being run) Remove the Browser Helper Object registry key Adds a registry value to block file from running

Here's the reports from the Virtumondo and the HJT: [01/22/2006, 21:18:46] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Owner\Desktop\VirtumundoBeGone.exe" ) [01/22/2006, 21:19:30] - Detected System Information: [01/22/2006, 21:19:30] - Windows Version: 5.1.2600, At this point please type the following file path (make sure to enter it exactly as below!): C:\WINDOWS\system32\klnmp.*

Estimated site value is $38.81.

Please allow up to 5 seconds… DDoS protection by Cloudflare Ray ID: 33c2c9eaa73d20de Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & I ran the Undobegone, but I did not run the Spysweeper because my AVG scan took so long, I'll do that this evening.