0

pls..help me..as soon as you read my post.thanks..

hello, pls someone lend me a hand.

My Nod32 kept on detecting a virus called
Object:
C:\Users\Karen\Appdata\Local\Temp\AgjjQXbc.ini
threat
Win32.virtumonde.NEO application
then after detecting all, it automatically reboot then again and again.
I also have the same problem as the first person who posted here. A RunDLL error appeared whenever I turn on my laptop. I'm really nervous and I don't know what to do. I search for it(the virtumonde) as what I read from posts but nothing come out. I think it all started when I downloaded a free kaspersky antivirus.

2
Contributors
8
Replies
9
Views
8 Years
Discussion Span
Last Post by crunchie
0

Hi to All,
This what happened...
The EsetNod32 Antivirus program did a normal scan and indicated that I had 4 infections. Esetnod32 said it was a Trojan Horse or something like that. The infections were removed and quarantine, but eventually my computer was having problems such as lots of popups saying Threat found called Win32/Adware.Virtumonde.NEO application. I noticed that it pop and after a while a warning appeared that my NEO laptop needed to be reboot.

Then when my computer booted up I got an error which said "Error Loading C:\WINDOWS\system32\khtGaxut.dll The specified module could not be found". I also noticed that the computer was still having the same problems.

And then I found this forum to help me. I read all of the forum and did what it said. I went through the search programs and hoping to delete the said “Virtumonde” but nothing was found.

I scan again my computer for viruses still nothing was found(i’ll post the log files at the end). I read the forums and downloaded the Hijackthis. I ran HiJackThis.exe and will post the log at the end.

I am trying to figure it out on my own but am having no success. Any body that can help would really be appreciated. I follow directions very well so just let me know what you think I should do. I read some forums about a tool called Rundll.error but I think I can’t get it.

Thanks for any and all assistance,
karen

EsetNod32 Antivirus 3.0.667.0
Virus signature database: 4019(20090418)
Log files
4/19/2009 7:07:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:12 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:07:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:06:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:24 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 7:05:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE
4/19/2009 6:58:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:12 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:58:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:57:04 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:56:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:36:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:36:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:09 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:35:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:12 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:34:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:33:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:16:12 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:16:11 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:16:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:16:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:16:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:04 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:15:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:49 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:42 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:41 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:39 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 6:14:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EX
4/19/2009 5:50:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.4/19/2009 5:49:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:49:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:44 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:26 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:24 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:19 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:48:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:46 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:34 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:26 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:24 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:14 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:11 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:02 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:27:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:51 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:49 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:39 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:36 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:26 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:14 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:11 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:09 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:26:06 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:56 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:46 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:44 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:22 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:06 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:05:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:59 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:54 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:53 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting (after the next restart) - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:43 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:34 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:21 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:09 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 5:04:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:58:04 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:58:04 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:59 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:54 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:49 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:47 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:46 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:08 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:57:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:58 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:54 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:51 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:38 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting (after the next restart) - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:33 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:29 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:28 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:23 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:19 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:13 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:09 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting (after the next restart) - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:56:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:55:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.4/19/2009 4:41:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:41:26 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:41:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:41:18 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:41:17 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:31 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:38:01 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:57 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:48 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:46 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting (after the next restart) - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:41 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:37 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:32 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:31 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:16 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:14 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting (after the next restart) - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:11 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:07 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:37:01 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Exp4/19/2009 4:05:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:11 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:05:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:04:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 4:03:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.4/19/2009 3:55:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:55:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:55:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:55:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:54:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:25 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:20 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:15 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:10 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:05 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:03 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini2 Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:53:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:52:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:52:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:52:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EX4/19/2009 3:45:00 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:59 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:55 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:52 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:50 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:46 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:45 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a file modified by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:40 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:35 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:34 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:30 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the application: C:\Windows\Explorer.EXE.
4/19/2009 3:44:27 PM Real-time file system protection file C:\Users\Karen\AppData\Local\Temp\AGjjQXbc.ini Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined Event occurred on a new file created by the applica

0

Hi and welcome to the Daniweb forums :).

==========

Is NOD32 legitimate, or is that a 'freebie' version too?

==

Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Download the update from here if you have problems.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

Make sure that you restart the computer.

Post new HJT log.

0

Thanks the popups were gone but still the Error Rundll appears on the startup. so..did i made a mistake? the esetnod32 antivirus program was given to me by a friend and said it was original.

Malwarebytes' Anti-Malware 1.36
Database version: 1954
Windows 6.0.6001 Service Pack 1

4/19/2009 11:44:19 PM
mbam-log-2009-04-19 (23-44-19).txt

Scan type: Full Scan (C:\|)
Objects scanned: 181540
Time elapsed: 2 hour(s), 20 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{420959a7-1b3f-49ee-848e-6de631a39223} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmds (Malware.Trace) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\086D9GDA\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\086D9GDA\kb456456[3] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7GP8P0W2\vsm_free_setup[1].exe (Rogue.VirusRemover) -> Quarantined and deleted successfully.
C:\Windows\t55ft2772f44.dat (Trojan.KoobFace) -> Quarantined and deleted successfully.
C:\Windows\t55ft2829f44.dat (Trojan.KoobFace) -> Quarantined and deleted successfully.
C:\Users\Karen\AppData\Local\Temp\cbXQjjGA.dll (Malware.Trace) -> Delete on reboot.

0


Post new HJT log.

I need this too.

If NOD32 was given to you by a friend, it could possibly be a pirate copy.

0

I just borrowed her installer "eset nod32 antivirus program".
here is the hijackthis log files, i still have the startup rundll error saying that error cannot find the module C:\windows\system32\khfGaxvt.dll. Also i scan my computer with the eset still no findings and i search for file but still I can't find the file. Thank you so much for your help. Let me know what to do next. I will try to be as quick as I can with action.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:46:23 PM, on 4/20/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\BisonCam\BisonHK.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Karen\AppData\Local\Yahoo!\Messenger for Vista\Yahoo.Messenger.YmApp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\Karen\Program Files\DNA\btdna.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe -chkautorun
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [BisonHK] C:\Windows\BisonCam\BisonHK.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\khfGaxvt.dll,#1
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo!MessengerForVista] "C:\Users\Karen\AppData\Local\Yahoo!\Messenger for Vista\Yahoo.Messenger.YmApp.exe" -startup
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Karen\Program Files\DNA\btdna.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 7766 bytes

0

Can you please do the following.

===============

Can you disable Windows Defender as it may interfere with the removal process. Please leave it disabled until your PC has been given the all clear.

  • Open Windows Defender
  • Click Tools
  • Click General Settings
  • Scroll down to Real Time Protection Options
  • Uncheck Turn on Real Time Protection (recommended)
  • After you uncheck this, click on the Save button
  • Close Windows Defender

===============

Scan with HijackThis and then place a check next to all the following, if present:


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\khfGaxvt.dll,#1

O13 - Gopher Prefix:

O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Reboot.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

0

The error rundll didn't appear when I restart my computer. I guess, you fixed it. thank you very much. I'm really grateful i found this site. by the way, here is the log files. Thank you! thank you!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:49 PM, on 4/20/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Hotkey_Driver\HotkeyDriver.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\BisonCam\BisonHK.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Karen\AppData\Local\Yahoo!\Messenger for Vista\Yahoo.Messenger.YmApp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\Karen\Program Files\DNA\btdna.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe -chkautorun
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [BisonHK] C:\Windows\BisonCam\BisonHK.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo!MessengerForVista] "C:\Users\Karen\AppData\Local\Yahoo!\Messenger for Vista\Yahoo.Messenger.YmApp.exe" -startup
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Karen\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 8019 bytes

0

Congratulations! Your log looks clean.

===============

Now that your PC is clean you need to follow these easy steps to keeping it this way:

Download CCleaner and install, then run it. It will clear out your temp folders.

  1. Uncheck "Cookies" under "Internet Explorer".
  2. Click on Run Cleaner in the lower right-hand corner. This can take quite a while to run.
  3. Close when finished.

====

An alternative to Ccleaner is ATF Cleaner.
Download ATF (Atribune Temp File) Cleaner by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

====

Use an alternative browser! Download FireFox and give it a run. It is far more secure than Internet Explorer. Or, you can get Opera, which in my opinion, is better still.

====

Use a firewall. It is an essential part of your computers security. There is a link to a good, free firewall in my signature.

====

Install and keep updated,
Spybot S&D.
Run it on a regular basis, following the maker's recommendations.

====

Install an anti-virus. There are some good, free AV's available today. Make sure that it is updated regularly and have it scan your system often.

====

Check for Windows Updates. Microsoft regularly post updates for your systems safe running. Make sure to take advantage of this. Reboot when installed and return to make sure there are no others.

=====

For XP users.
After something like this it is a good idea to Flush the Restore Points and start fresh.
To flush the XP system Restore Points.

Go to Start | Run and type msconfig and press enter.

When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings link on the left.

Check the box labelled 'Turn off System restore'.

Reboot. Go back in and Turn System Restore Back on. A new Restore Point will be created.

Note that all previous restore points will be lost.

===============

Please mark this thread as solved if all is well.

If you have any more problems, post back.

-

Happy surfing,

crunchie.

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.